There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
nothing rouge either, I suspect.
OpenAI bots knew about the RubyGems caching vulnerability
91–100 of 229 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#92Re: OpenAI bots knew about the RubyGems caching vulnerability
#93Earlier quoted context omitted.
The same concept that allows a corporation to sue and be sued allows it to be charged with crimes
Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.
https://arstechnica.com/information-technology/2016/05/armed...
https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb...
So what's the deal with these?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#94It's not just that AI can write Rust as well as Ruby if you ask nicely.
It's also all of these considerations as well.
I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable.
This is at the same time everyone and their mother is building their own programming language.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#95Re: OpenAI bots knew about the RubyGems caching vulnerability
#96There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
The big question is was this grossly negligent or just extremely careless.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#97Earlier quoted context omitted.
Both. This should result in criminal charges.
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#98* Hugging Face
* D Programming Language Wiki
* Ruby Gems
If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#99Are "rouge" and "rogue" interchangeable words in American English?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#100There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…
Knee-jerk surface analyses is far more powerful.