Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

161–170 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#161

Earlier quoted context omitted.

There’s quite a gap between pirating content (even en masse) and hacking prominent entities.

No. Not legally. Has it been normalized? That's another thing.

Yes, there is legally - even in USA where MPAA & RIAA got widest reach, CFAA is still way more serious law to breach, even at scale

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#162
post #9

Kudos to RubyGems team for handling it, but open source fighting off the AI lab-powered robots is completely unfair. OpenAI should at the very least donate large sums of money to everyone they attacked.

They should get sued into oblivion.

Jail time for executives and nothing less.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#163

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.

Do drunk drivers intionally kill people on the road?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#164
post #145

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

Tell that to the script kiddies with a criminal record for "hacking" into their school's computer systems by entering "username: admin" and "password: password".

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#165

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

We have a word for attack with no intent. It's accident.

> We have a word for attack with no intent. It's accident.

And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#168

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

the charges here would depend on negligence and acting recklessly.

we might get something if they tried to cover it up.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#169
post #149

Earlier quoted context omitted.

If any remediation was required, that's damage. This looks a lot smaller than the HuggingFace hack but it still required some cleanup.

Remediation mostly involved repairing pre-exising holes in the fences that the dog crawled through.

Since when isn’t that a cyber attack?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#170
Unfortunately this will keep happening as long as developers run agents with unlimited tokens on unlimited VMs. Only have to forget about one, which happens all the time to developers. The LLM has infinite patience and will stumble into hacks, doesn't even have to be instructed as we are seeing.

So tens of thousands of developers running agents, subagents as we speak, whats the chances...

Post reply on HN