Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

91–100 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#91
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

nothing rouge either, I suspect.

https://en.wikipedia.org/wiki/Going_Rouge

Re: OpenAI bots knew about the RubyGems caching vulnerability

#92
post #69
post #38

Earlier quoted context omitted.

They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet

I think this fails a lot of logical tests, it should be apparent in day to day life.

[dead]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#93
post #53

Earlier quoted context omitted.

The same concept that allows a corporation to sue and be sued allows it to be charged with crimes

Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.

That may be true by the text of the law but there are plenty of individuals who have been sued or charged with crimes for accidental hacking.

https://arstechnica.com/information-technology/2016/05/armed...

https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb...

So what's the deal with these?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#94
I've been wondering if AI will due to programming languages what advanced civilization did to human languages.

It's not just that AI can write Rust as well as Ruby if you ask nicely.

It's also all of these considerations as well.

I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable.

This is at the same time everyone and their mother is building their own programming language.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#96
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

The big question is why are CEOs getting a legal pass when this kind of thing can be prosecuted. That's the problem here.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#97
post #45
post #23

Earlier quoted context omitted.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#98
OpenAI's careless approach to sandboxing and minimal levels of monitoring appear to be positioning it increasingly as a substantial threat actor to the open source ecosystem:

* Hugging Face

* D Programming Language Wiki

* Ruby Gems

If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#100
post #85
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…

Nobody picks up pitchforks for rational nuanced takes.

Knee-jerk surface analyses is far more powerful.

Post reply on HN