Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

41–50 of 212 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#41
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Sounds more or less like the last breach then.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#42
post #29

Earlier quoted context omitted.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.

The same concept that allows a corporation to sue and be sued allows it to be charged with crimes

Re: OpenAI bots knew about the RubyGems caching vulnerability

#43
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#44

Earlier quoted context omitted.

Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.

Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those.

They don’t need to run their own DCs, just pay for a proxy somewhere in the world that has better access to the infrastructure. We know North Korea has been doing that in the US since years now

Re: OpenAI bots knew about the RubyGems caching vulnerability

#45
post #23
post #18

Earlier quoted context omitted.

The big question is was this grossly negligent or just extremely careless.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#46
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

Because they dont have the money for hardware or compute obviously.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#47
post #8

rogue AI agents or AI agents coming from Moulin Rouge?

Rouge syntax-highlighting rogue agents, clearly. https://rubygems.org/gems/rouge

Classic mistake. Tell the agent to highlight this code, but dont give it any actual code. Agent hacks its own gem to find the code to highlight.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#49
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

How is the responsibility diluted? Charge the CEO…

Re: OpenAI bots knew about the RubyGems caching vulnerability

#50
I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.
Post reply on HN