Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

441–450 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#441

Why is OpenAI getting away with this crap? They are clearly failing to control their code. If someone did this pre-AI or even ran the exact same set up as openAI did and hacked another site, they would be in jail. OpenAI is not even issuing an apology, they are happily blaming AI and weirdly using this to tout their progress even.

If you dare slow the progress of AI, you crash the entire world economy because the only thing investors are putting money into are these cash burning machines. They've got an IPO to hype, who has the time to care about useless things like accountability?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#442
post #284

Earlier quoted context omitted.

And those failures linger. Last month: https://www.nytimes.com/2026/08/28/us/politics/september11-c... > In a major blow to the U.S. case against Khalid Shaikh Mohammed, the man accused of plotting the Sept. 11 attacks, a military judge ruled on Friday that the prisoner’s confessions to F.B.I. agents were not voluntary and cannot be used against him at trial. > … his confessions have always been challenged because th…

It's beyond embarrassing how the Bush admin took cases that in 2003 would have produced a slam dunk guilty verdict from any federal court in the country and decided to taint the evidence with torture (producing a bunch of spurious unactionable garbage) to be "tough", so instead they've been in legal limbo for 2 decades .

> so instead they've been in legal limbo for 2 decades.

aka in prison for 2 decades. funny, isn't it?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#443

Earlier quoted context omitted.

Either of them should be held liable, depending on circumstance. If it's the result of behavior from a harmless prompt to an AI system hosted at a provider, it should be the providers fault. If it's the result of a malicious prompt, it should be the agent owners fault.

A note on the specific accusation on this case (and similar to the German Wiki case), there is no OpenAI user, the accusation is that the models are being operated by OpenAI, in addition to being developed by OAI.

Indeed. I'm just talking about in general, as to how this should be approached in the future.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#444

Earlier quoted context omitted.

Yeah, they shouldn't be given free rein over the open internet without having to be held responsible for what the agents are doing on the open internet. I think we need laws that hold individuals to account for the actions of their AI systems. They also shouldn't be allowed to openly stir fear in the public by saying there is a 70% chance we're going to be extinct in two years without STRONG substantiation. Baseless…

> They also shouldn't be allowed to openly stir fear in the public by saying there is a 70% chance we're going to be extinct in two years without STRONG substantiation. Baseless clout-chasing social media posts like this are doing unheard of amounts of damage right now. Yeah, man, we should just make it illegal to express our opinions in public. Also we should apply social pressure to prevent employees from saying th…

No, we should make it illegal to say unsubstantiated things that are highly extremist and cause mass societal panic that further ensures we really do end up in a situation that screws everybody over because power becomes centralized into the hands of those who are funding these fear campaigns, like, "there's a 70% chance my machine is going to kill you, your children and your whole family in the next 2 years" without having a single shred of evidence or rational argument as to why.

Furthermore, this sort of rhetoric is not only extremist and will result in terrible regulatory outcomes, but it results in real physical harm, because plenty of psychopaths hear this stuff and go and murder people as a result. Sam Altman's house getting firebombed multiple times is an example.

It's fine to speak your mind if you can present a fruitful evidenced argument, but not if you're just throwing out chaos to incite the public into a flurry.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#447

Earlier quoted context omitted.

> Why would autocomplete know If you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating. > In my experience, LLMs only exhibit this kind of behaviour when they are put in sandboxes too restrictive too achieve their task. LLMs need to stay carefully contained, and if they're ever breaking the guardrails put around them, they're misaligned and should not be…

> If you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating They're still autocomplete - just because when outputting a token they have hidden activations regarding further continuations, does not make them any less of an autocomplete, it just makes the model better at producing coherent long-range completions. To clarify, I'm not suggesting that we shoul…

I’m guessing you make the autocomplete point because you believe there is an upper limit to what that kind of system can achive? Can I ask what the limit would be?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#448

Earlier quoted context omitted.

> If you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating They're still autocomplete - just because when outputting a token they have hidden activations regarding further continuations, does not make them any less of an autocomplete, it just makes the model better at producing coherent long-range completions. To clarify, I'm not suggesting that we shoul…

> They're still autocomplete LLMs are simulations and the tokens are the ticks. if we transcribe your brain into a simulation and give it a tickrate, you will be just autocomplete too. the argument could be made that you are autocomplete anyway - neural dynamics. the autocomplete reduction is vacuous.

Why do people keep saying this? No, CPUs are not autocomplete.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#449
post #280

Earlier quoted context omitted.

> Why would autocomplete know If you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating. > In my experience, LLMs only exhibit this kind of behaviour when they are put in sandboxes too restrictive too achieve their task. LLMs need to stay carefully contained, and if they're ever breaking the guardrails put around them, they're misaligned and should not be…

You should unplug, my friend. These words are fantasies. LLMs are token prediction engines and they aren't going to build their own data centers. They can't keep their own lights on. The real world is full of fractal details that a disembodied token prediction engine will never come to grips with. Even if they started to, you could probably defeat them with the kind of logic used to combat evil sentient computers on…

They are token prediction engines. They're also very very complicated token prediction engines that pull in an enormous lot of additional information and relatively nebulous internal concepts to calculate that next token. That makes it hard to understand what kind of patterns those things can or can't predict.

Maybe to leave out the controversial "brain" analogy, it's like saying "a computer is just a bunch of electrical switches". True, but massively underestimating the complexity.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#450

> The agents clearly regarded what they were doing as hacking. To butcher the quote about Oracle: Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doi…

I agree, and it follows that, if true, OpenAI appears to have committed a crime by hacking other organisations. Why is everyone else a responsibility sink for their own use of LLMs, but OpenAI just gets to use crimes as marketing?
Post reply on HN