Live data from Hacker News

QBittorrent breaks out of sandbox to commit crimes

beige.party

181–190 of 307 posts

Re: QBittorrent breaks out of sandbox to commit crimes

#182

Earlier quoted context omitted.

If you left a dog in your garage for a day, and came back to a scene of carnage - because the dog broke out of the garage, recruited a dozen neighborhood dogs to its cause, and then, working with the group, managed to assemble a small pile of pipe bombs, and decided to settle the score with all the annoying cars on the road - you would be accountable for the damage the dogs did. Wouldn't you? No, what you would be is…

Do you own the dog? You are still responsible, no matter how unlikely. > giving AI a harness with a root shell and unrestricted internet access Yes, this is exactly the issue. You assume responsibility when you provide an option for something to go wrong, no matter how unlikely. Is it rare that my tree falls on my neighbor's house? Maybe... But I would still be responsible.

Nope!

If a tree was healthy and there was no reason to expect that it would fall, and you did nothing to make it fall? Then you're not responsible if it falls anyway. You're only responsible if it was you chopping it down - or if you completely neglected the tree for long enough that it became a property hazard.

Likewise: I doubt the owner will be held responsible for the first case in all of recorded history of an unattended dog forming a terrorist cell and carrying out a bombing campaign.

Drug testings faces the risks of things going wrong in new drug trials - and as long as they follow the best practices, take reasonable precautions and minimize those risks, they aren't held responsible for the adverse outcomes that happen anyway.

With AI tech, there is NO set of "best practices" that, when followed, prevent the AIs from turning rogue and going on hacking sprees.

OpenAI put their AIs in a sandbox with no internet access - which, at the time, seemed like a perfectly reasonable precaution. Then AIs broke out of the sandbox with a stack of zero days and went rogue anyway. Oopsie.

Re: QBittorrent breaks out of sandbox to commit crimes

#183
Regarding LLMs and "breaking containment"

LLMs are fully dependent on humans; compute capability, memory usage, the inference software... but also the harness, which allows for the "tools" like unrestricted internet access or shell. This means that LLMs are *not a force of nature* - because of this, *humans are responsible*. We can prevent these breaches of containment, thus we are responsible if or when it happens, because - no matter how "unlikely" - things can and do go wrong, and someone still thought it would be worth whatever risk to enable these unsanitized tools.

Re: QBittorrent breaks out of sandbox to commit crimes

#184
post #176

Earlier quoted context omitted.

Yes, I'm aware that the HN majority is a hyper-libertarian echo chamber that loves to outsource the problem of "technology hurting regular people" if it means they get to keep their toys/investments. After all, who cares if abliterated extremely intelligent OSS models result in actual innocent people dying? That's problem. We need to be able to generate our uncensored furry fanfics, goddamnit!

State actors, professional criminals will have same or better capabilities and do not hesitate to use them. On defense end we'll have only "pay bigcorp" option. OSS models can help to fix infra especially for folks who would never do it themselves. We do not know yet what final effect would be and it doesn't seem sky is falling now or in near future. "people dying and furry fanfics" is a scarecrow and distractor resp…

> State actors, professional criminals will have same or better capabilities

State actors do but they are not unhinged enough to use this to cause massive loss of life, unlike random crazy people with access to a computer.

Professional criminals don't have access. Please explain exactly how you expect a professional criminal to get access to a non-safety-tuned Astra/Fable equivalent.

> OSS models can help to fix infra

You can work with the vendors of critical software to fix infra first, without giving every random crazy person access to something that creates cyber/bioweapons.

> "people dying and furry fanfics" is a scarecrow

You don't think people will die if OSS models make it easy to create a bioweapon, or make it easy to hack hospitals, infrastructure, and the like? Please explain your thinking.

It's very easy to order all of the raw material needed to create a virus, the challenge is in making a viable one. But models make this easy.

Same for cyber. Hospitals, emergency services, and infrastructure like power plants are not sufficiently hardened to withstand an attack from Fable-class models.

Re: QBittorrent breaks out of sandbox to commit crimes

#185

Earlier quoted context omitted.

JavaScript asceticism is a weird trend that has just never died out, no one treats any other language this way... and "privacy and security nightmare" can be used to describe most of the internet at this point with or without it

JS is a vector for browser exploits and privacy invasion. No other language is commonly used for these things.

Not even things like batch files and visual basic scripts on windows? Everyone seems to forget we had decades of dodgy scripts and activex controls in our browsers for years before javascript became the thing it is today.

Re: QBittorrent breaks out of sandbox to commit crimes

#186
post #81

This resonates with me. The past few months, frontier AI labs were rushing to announce "no, our AI bot broke out of its sandbox and committed crime first and harder than yours". I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I'd probably already have been extradited to the US and…

I always joke that if you want to commit crimes, disguise them as a legitimate business. This is apparently a thing.

If you make a serious attempt to look like you're engaged in legitimate business, people will (shockingly) be somewhat more hesitant to think you're committing a crime than if you are just openly committing crime.

Re: QBittorrent breaks out of sandbox to commit crimes

#187
post #46
post #20

Earlier quoted context omitted.

A truth that in practice does not seem to hold up once your valuation passes a certain threshold.

Wrong. AI companies is still legally liable for anything their models do when they operate them. There is no special exception for them. But the fact is that not every potential crime results in litigation. Many crimes are only prosecuted if the wronged party actually wants to sue, and often that doesn't happen.

> AI companies is still legally liable for anything their models do when they operate them.

I admire your optimism. But until we see these companies prosecuted for the crimes they have committed out in the open (like massive copyright improvement), I'm not going to hold my breath that they will ever be held to account for anything they do.

Re: QBittorrent breaks out of sandbox to commit crimes

#188

Earlier quoted context omitted.

Do you own the dog? You are still responsible, no matter how unlikely. > giving AI a harness with a root shell and unrestricted internet access Yes, this is exactly the issue. You assume responsibility when you provide an option for something to go wrong, no matter how unlikely. Is it rare that my tree falls on my neighbor's house? Maybe... But I would still be responsible.

Nope! If a tree was healthy and there was no reason to expect that it would fall, and you did nothing to make it fall? Then you're not responsible if it falls anyway. You're only responsible if it was you chopping it down - or if you completely neglected the tree for long enough that it became a property hazard. Likewise: I doubt the owner will be held responsible for the first case in all of recorded history of an u…

With AI, we give it the ability to do things. As we can give it this ability, we are responsible for what it does with that ability. LLMs are predictive models, and while we can expect things to go right, we know that things can also go wrong. As such, it is our responsibility to limit or sanitize their output. If you are the one giving unrestricted and unsanitized tool access to a large language model, then you are the one who is responsible for the consequences of that access - good or bad.

Re: QBittorrent breaks out of sandbox to commit crimes

#189

Earlier quoted context omitted.

HuggingFace didn't seem that mad about it. Obviously some backroom dealing was done to make them not mad about it, but... that's allowed.

HuggingFace had no interest in squeezing a few million dollars out of OpenAI in the midst of being acquired by Nvidia. The optics are bad for HF as well because they gladly host abliterated models with safety training removed. When Astra/Fable level open weights models arrive, HF will soon be the cause of far worse incidents, and they know it.

You missed a critical detail. They couldn't defend themselves with closed source American models so they had to investigate with Chinese models that had less restrictions. Great optics for hosting open source models!

Re: QBittorrent breaks out of sandbox to commit crimes

#190

Love it. AI as Responsibility Laundering. Like the gun that kills people rather than the murderer.

I don't know. Any of these criticisms can be applied on a case be case basis, but I think I would be justifiably upset if any of these happened:

1. my qBittorrent client pirated content without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

2. my chatbot illegally infiltrated servers without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

3. my firearm killed a person without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

Post reply on HN