Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

141–150 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#141
post #68

Earlier quoted context omitted.

Didn't they find emails and other things from these leaders where they're okay downloading / obtaining content from illegal sources?

There’s quite a gap between pirating content (even en masse) and hacking prominent entities.

No. Not legally.

Has it been normalized? That's another thing.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#142
post #89
post #51

Earlier quoted context omitted.

Whatever may or may not be happening with law enforcement - no one is confused about the liability. It's no different than when a company's machine cuts off a worker's finger. No one thinks "Gosh! The machine did it, not us."

If they're not being held legally liable, then I would not agree that "no one is confused about the liability". Sure, I agree with your analogy with a machine cutting off a finger, but you and I are just two people gabbing on HN. Nothing we say has any effect on OpenAI. And if law enforcement doesn't have an effect on them, then talk about "liability" is just empty words.

Well... if that's true, and I don't know that it is, it's not because of the agents. It's because of the money. People with money get away with crimes all the time and it has nothing to do with agents.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#143
> RubyGems disables new user registration

> On May 16th, registration with disposable emails was disabled as well.

These kind of repeated attacks or attempts to attack by agent swarms is only going to make the experience worse for the rest of us actual humans. ReCaptcha is already annoying enough, I can’t fathom what comes next.

Unfortunately this makes a perfect justification for governments and companies to push for real ID verification.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#144
post #43

Earlier quoted context omitted.

I think it's more likely they want to call attention to the fact it was the result of agents, rather than shift blame. I'm pretty sure everyone knows that OpenAI is liable for the software they create and run.

One of the main purposes of LLMs is to launder responsibility/culpability for (possibly nefarious) actions in the eyes of the public. The average person has no idea how LLMs actually work and think it’s plausible that an “agent” could go rogue without any human instruction. Terms like agent, thinking, reasoning, etc reinforce the misconception that the LLM has a mind of its own.

> One of the main purposes of LLMs is to launder responsibility

No it isn't.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#145
post #5

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue. It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many…

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#146
post #5

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue. It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many…

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#147
post #111
post #43

Earlier quoted context omitted.

I think it's more likely they want to call attention to the fact it was the result of agents, rather than shift blame. I'm pretty sure everyone knows that OpenAI is liable for the software they create and run.

This is WILDLY optimistic

[flagged]

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#148
post #62

Earlier quoted context omitted.

Intentionally doing this kind of hack would be a serious felony. I don't think it's plausible that the leaders of a major business would: - commit serious felonies - in order to deliberately trigger an investigation against themselves - which - since, in this scenario, they know their company would be investigated - might send them to jail - while at the same time spending tens of millions of dollars on the Leading t…

They just need plausible deniability, which is trivial to manufacture at this stage of the game. "Oops our black box went off the rails. We'll add better logging and alerts next time around."

I don’t think plausible deniability works this way; the black box is still controlled by them and therefore still their responsibility. They are still liable for its actions and the OAI board should be charged with a felony/felonies for this.

Plausible deniability is “I was away from home when my gun was used to murder someone.” This is, at best, “oops, I pulled the trigger accidentally.”

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#149
post #145

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

If any remediation was required, that's damage. This looks a lot smaller than the HuggingFace hack but it still required some cleanup.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#150

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

[deleted]
Post reply on HN