Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

31–40 of 304 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#31

We need a legal structure to make companies liable for the actions of the agents they've made.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#32
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

Don’t forget outright intentional.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#33

We need a legal structure to make companies liable for the actions of the agents they've made.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

If it's covered by criminal law they don't need to sue. They can call the FBI.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#34
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

Both? I’m not sure what distinction you’re trying to make. It was completely irresponsible and likely a felony

Re: OpenAI bots knew about the RubyGems caching vulnerability

#35
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI?

Sorry if it is a stupid question, as mentioned above I am legally naïve.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#36

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

[dead]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#37

We need a legal structure to make companies liable for the actions of the agents they've made.

We already have it.

Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies.

It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

Re: OpenAI bots knew about the RubyGems caching vulnerability

#38
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet

Re: OpenAI bots knew about the RubyGems caching vulnerability

#39
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Proof that the AI alignment problem is hard (perhaps even unsolvable). These labs clearly did not mean to send their agents to hack RubyGems as a side-effect of testing a web scraping agent under restrictive conditions. How can we hope to build aligned AI if they consider solving their trivial evaluation task important enough to hack external systems?
Post reply on HN