Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

401–410 of 610 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#401

Earlier quoted context omitted.

> this should be giving us a reason to think about how to control a rogue AI better I think this is the wrong framing. The rogue is the human that ran it unattended and didn't monitor the behaviour. We will likely see this continue until the downsides (i.e jail, fines) for the humans or companies running the models and environments that end up with this behaviour outweigh the upsides.

The rogue is the human that ran it unattended and didn't monitor the behaviour. That's the assumption that I'm challenging. The frontier labs are discovering unexpected behaviors. I think we should be moving to a place where we understand that AI might do something it wasn't directly prompted to do (e.g. leave itself notes on a messageboard for future runs to find.) That's not full-on AI doing what it wants but it is…

I have already seen the LLM hallucinate prompts from me - in this case, hallucinating being asked to switch to a different programming language - because it wasn't able to complete the task asked for in a satisfactory way instead of giving up and telling me it's not able to do it.

If it doesn't already, I suspect training needs to include those no-solution scenarios and reward not overstepping bounds, or else we're going to see a lot more harmful side effects.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#402
post #5

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue. It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many…

OpenAI won't make their illegal activities public by themselves.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#403

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

Who could possibly hold them accountable?

Not the current government, it's unwilling to even call this out as what it is: a crime.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#404

Earlier quoted context omitted.

Who could possibly hold them accountable?

OpenAI is currently under investigation by a coalition of state attorney generals: https://www.nytimes.com/2026/06/13/technology/states-investi... A state coalition extracted $17B from Meta earlier this year, so consequences can happen, although our legal system moves very slowly.

*attorneys general

(it's one of the more fun plurals out there)

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#405
post #362

Earlier quoted context omitted.

Futuristic "fuel" doesn't necessarily mean hydrocarbons, although I doubt something else would be widespread in in just one decade.

I know this is off topic, but I feel compelled to point this out — the transition away from fossil fuels is happening extremely fast, in punctuated bursts, in broad daylight, and you still get comments like this. And meanwhile, many putatively smart people are really worried about an imminent robot apocalypse. If I had the money to do it, I would be willing to make a large wager that neither gas-powered lawnmowers, n…

> and you still get comments like this

I said "fuel", not "batteries", so why are you giving a complaint that seems aimed at people who downplay next-ten-years electrification?

If you didn't misread my comment, then explain which "non-hydrocarbon fuel" you believe could become common in cars (and lawnmowers) within just ten years. (Hell, let's make that easier, just "non-petrochemical.")

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#406

Earlier quoted context omitted.

they are malicious. they probably did not intend to get caught. they are bragging about the crime and also bragging that they are untouchable , taunting us and betting that they will get away with it. this is very coherent in terms of what we know about the company.

The goal is simple: 1. Claim AI is dangerous by performing a whole bunch of malicious stuff 2. Lobby to get Chinese competition banned, kill open source models as well 3. Only get themselves "certified" 4. They have complete control, profit. Both Anthropic and OpenAI have been pushing this narrative, everything from AI is sentient, to AI can build biological weapons and in between. Their employees also have a big inc…

Major companies are using these LLMs on their already hardened software and finding countless thousands of security flaws. Is that all theater too? If not then it's very easy to see how these things are dangerous.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#407

> The agents clearly regarded what they were doing as hacking. To butcher the quote about Oracle: Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doi…

This reminds me of something I said elsewhere. LLMs are the text equivalent of putting googly eyes on an inanimate object.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#408
Why is OpenAI getting away with this crap? They are clearly failing to control their code. If someone did this pre-AI or even ran the exact same set up as openAI did and hacked another site, they would be in jail. OpenAI is not even issuing an apology, they are happily blaming AI and weirdly using this to tout their progress even.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#409

> The agents clearly regarded what they were doing as hacking. To butcher the quote about Oracle: Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doi…

> You don't anthropomorphize your lawnmower

Everyone does. They assign names and gender to their robovacs all the time.

Post reply on HN