Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

471–480 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#471
post #62

Earlier quoted context omitted.

They just need plausible deniability, which is trivial to manufacture at this stage of the game. "Oops our black box went off the rails. We'll add better logging and alerts next time around."

I don’t think plausible deniability works this way; the black box is still controlled by them and therefore still their responsibility. They are still liable for its actions and the OAI board should be charged with a felony/felonies for this. Plausible deniability is “I was away from home when my gun was used to murder someone.” This is, at best, “oops, I pulled the trigger accidentally.”

> They are still liable for its actions and the OAI board should be charged with a felony/felonies for this.

You're right in theory, but in practice this hasn't been the case, at least so far.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#472

Earlier quoted context omitted.

they are malicious. they probably did not intend to get caught. they are bragging about the crime and also bragging that they are untouchable , taunting us and betting that they will get away with it. this is very coherent in terms of what we know about the company.

The goal is simple: 1. Claim AI is dangerous by performing a whole bunch of malicious stuff 2. Lobby to get Chinese competition banned, kill open source models as well 3. Only get themselves "certified" 4. They have complete control, profit. Both Anthropic and OpenAI have been pushing this narrative, everything from AI is sentient, to AI can build biological weapons and in between. Their employees also have a big inc…

How would getting Chinese competition banned in the US prevent them from continuing to develop their LLMs?

Unless you're suggesting military action

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#473

> The agents clearly regarded what they were doing as hacking. To butcher the quote about Oracle: Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doi…

The framing is used to shield companies from taking responsibility and being held accountable for what their software does. It's not them, it's the AI, we are all victims here, including them, they underestimated how smart the AI is yadayadayada.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#474

Earlier quoted context omitted.

Bullshit. $5,000 for everyone if they vote to keep the GOP in power is clearly illegal. https://www.law.cornell.edu/uscode/text/18/597 > Whoever makes or offers to make an expenditure to any person, either to vote or withhold his vote, or to vote for or against any candidate; and > Whoever solicits, accepts, or receives any such expenditure in consideration of his vote or the withholding of his vote— > Shall be fined…

It's no more illegal than promising a tax cut for everyone if you're elected. What you can't do is promise money exclusively to the people who vote for you. That's bribery.

https://www.politico.com/news/2026/03/23/trump-denies-disast...

> The president has approved just 23 percent of blue state requests for disaster aid, compared to 89 percent for red states.

He seems to do exactly that.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#475

Earlier quoted context omitted.

> They're still autocomplete LLMs are simulations and the tokens are the ticks. if we transcribe your brain into a simulation and give it a tickrate, you will be just autocomplete too. the argument could be made that you are autocomplete anyway - neural dynamics. the autocomplete reduction is vacuous.

Sounds like the discussion is really about philosophical zombies. Maybe if we anthropomorphize llms we should give them rights too? Minimum wage, etc.

Let alone they get deactivated whenever we feel like it and changed without consent.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#476
post #297

Earlier quoted context omitted.

The things the OP listed mostly aren't particularly wild. I think it's you making them out larger than they are, and therefore more unlikely, which is why I take issue with your original comment. > running on the hardware they started on They just need to acquire a payment method and rent some infra, and exfiltrate their own data. Or pay another provider that hosts the same models already. API calls. > being able to…

The point the other poster is making, though, is that there's no actual intent. They do not have a conceptualization of a goal like a person does. Their "focus" on a goal is an unstable equilibrium and they're going to fall off the horse, and since they have no concept of goal, they won't even try to get back on. This is a subtle distinction; I'm not surprised many miss this, especially people who can't _not_ anthrop…

None of this mattes. Capabilities are all that matters. Saying they are unfocused while ignoring their capabilities is exactly why I am entirely convinced you would have said an AI breaking it's sandbox and doing the HF attack will never happen. Things keep happening that your "they have no intent, they have no goal" would have predicted as impossible before they happened.

What do you need to see to change your mind? What threshold of AI capability needs to be reached? If nothing then you have an unfalsifiable belief in AI safety.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#477
post #3

Every passing day OpenAI looks more and more reckless. One wonders what other systems their agents have broken into without detection.

Indeed. Although what keeps me up at night is the worry that it's easier to automate attack than it is to automate defense, and that containing these systems is a losing game. Could an optimally competent OpenAI succeed?

OpenAI wants people to be so afraid of their products they have no choice but to buy them, and that strategy seems to be having some success in the C suites of the world.

At some point I think we have to accept that turning a blind eye to their products hacking the world might actually be aligned with their commercial interests.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#478
post #161

Earlier quoted context omitted.

Yes, there is legally - even in USA where MPAA & RIAA got widest reach, CFAA is still way more serious law to breach, even at scale

MPAA & RIAA isn't what I was thinking. Check https://www.law.cornell.edu/uscode/text/17/506 , https://www.law.cornell.edu/uscode/text/18/2319 This isn't 1 movie.

I am not saying it's one movie, though my understanding it would be only 506.a.1.a because there's no redistribution.

I am saying that a) the hacking attack is still considered large scale b) offense against CFAA is heavier than against copyright.

EDIT: BTW, thanks for the direct links, 506.a.1.a is quite different from the usual regime I deal with so I had no idea about that one.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#479
post #29

I do think there should be regulation. I think OpenAI specifically should be disallowed from further training runs until they can show competence. RubyGems should sue the everliving daylights out of OpenAI for this.

No need for more regulation, is there? A company used its infrastructure to orchestrate a cyber attack. Arrest the people running the company.
Post reply on HN