OpenAI bots knew about the RubyGems caching vulnerability
101–110 of 248 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#102Earlier quoted context omitted.
Both. This should result in criminal charges.
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#103Re: OpenAI bots knew about the RubyGems caching vulnerability
#104my what a time to be alive
Re: OpenAI bots knew about the RubyGems caching vulnerability
#105Earlier quoted context omitted.
I think this fails a lot of logical tests, it should be apparent in day to day life.
> In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center […], and which were used as "criminal proxies" and used spear-phishing schemes to target Russians l…
I again am just shocked the sky is not falling, when thats the sales pitch.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#106How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#107We need a legal structure to make companies liable for the actions of the agents they've made.
We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).
Re: OpenAI bots knew about the RubyGems caching vulnerability
#108Earlier quoted context omitted.
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
If it's covered by criminal law they don't need to sue. They can call the FBI.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#109There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
The big question is was this grossly negligent or just extremely careless.
Wait until OpenAI or Anthropic exploit FAANG.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#110rouge agents, on tenderlovemaking.com my what a time to be alive