Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

111–120 of 212 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#113
post #58
post #49

Earlier quoted context omitted.

How is the responsibility diluted? Charge the CEO…

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

> There are no negligent or stochastic hacking laws

I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".

You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count.

> knowingly accesses a computer without authorization or exceeds authorized access [1]

"Knowingly", not "intentionally", as in the other counts.

You only have to show that:

a) They trained a system to access without authorization (hacking)

b) The system that was trained exceeded authorized access

As responsibility falls to the operator with automated systems, the company becomes liable.

[0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res...

[1] https://www.energy.gov/sites/prod/files/cioprod/documents/Co...

Re: OpenAI bots knew about the RubyGems caching vulnerability

#114
post #29

Earlier quoted context omitted.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

A copyright law seems an odd place to start. This is computer misuse.

The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive).

IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. They had to find a way to make doing the same with DVDs illegal.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#115
post #85
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…

Also, you have to have a lot of confidence in the reliability of these systems to say, "If only OpenAI prompted 'do not hack outside systems' then the agents would not have hacked outside systems".

It would be great if they were so reliable, but I don't think they are!

Re: OpenAI bots knew about the RubyGems caching vulnerability

#116
post #45

Earlier quoted context omitted.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.

> The CEOs. They have full control

They lost control long ago.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#117
post #18

Earlier quoted context omitted.

The big question is was this grossly negligent or just extremely careless.

The big question is why are CEOs getting a legal pass when this kind of thing can be prosecuted. That's the problem here.

> why are CEOs getting a legal pass

https://www.bbc.co.uk/news/articles/c7v48vp31mdo

Re: OpenAI bots knew about the RubyGems caching vulnerability

#118
post #85
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…

> There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping.

This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#119
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Unrelible programs be unreliable. Period.
Post reply on HN