Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

151–160 of 610 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#151
post #5

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue. It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many…

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

We have a word for attack with no intent. It's accident.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#153
post #65

Earlier quoted context omitted.

You really wanna start asking questions, how do we know it isn't North Korea or Anthropic via a VPN claiming to be oai?

I mean the HF attack seemed to be traced back directly to OpenAI. Any of the others I'm not sure.

This attack predates OpenAI and the German wiki attack (which OpenAI confirmed was theirs) and shares agent naming conventions. So seems unlikely that someone went back in time to frame OpenAI before the HF stuff was even known publicly.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#154

Imagine if all this training and "agent gym" and creativity of the agents being forced to make number go up was pointed at one task instead: "please help describe and implement a controlled experiment to equally distribute wealth and stability of health for 1 million people, adjusting to scale up to the greatest amount possible." I'd love to wake up one day and read, "OpenAI found responsible for the emptying of the…

Every mass genocide in the history of humanity has followed logic like yours. People don't kill millions of humans because they want to do harm-- they do so because they think they are doing the ultimate good a good so great that is justifies the loss of life.

If AI ever does cause serious direct harm to humanity it will be because of logic like this.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#155

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

They can still be held civilly liable for negligence, though.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#156
post #149
post #145

Earlier quoted context omitted.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

If any remediation was required, that's damage. This looks a lot smaller than the HuggingFace hack but it still required some cleanup.

Remediation mostly involved repairing pre-exising holes in the fences that the dog crawled through.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#157
post #145

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

That's not really true. Unauthorized access to a system is a crime regardless if there was damage.

https://www.law.cornell.edu/uscode/text/18/1030

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#158
post #144

Earlier quoted context omitted.

One of the main purposes of LLMs is to launder responsibility/culpability for (possibly nefarious) actions in the eyes of the public. The average person has no idea how LLMs actually work and think it’s plausible that an “agent” could go rogue without any human instruction. Terms like agent, thinking, reasoning, etc reinforce the misconception that the LLM has a mind of its own.

> One of the main purposes of LLMs is to launder responsibility No it isn't.

Yes, it is, for the reasons I stated in my comment, and you only need look at any OAI/Anthropic press release to see evidence of this in the language they use.

The LLM now reasons better! Set the thinking level! It learns!

All of these phrases are designed to give the impression that the LLM is an autonomous entity, when it is no such thing.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#159

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

At some point that recklessness looks like intent
Post reply on HN