There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
>They were prompted to hack to get answers Were they? I haven't seen a single report mention this
OpenAI bots knew about the RubyGems caching vulnerability
121–130 of 229 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#122We need a legal structure to make companies liable for the actions of the agents they've made.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#123> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.
The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access
Re: OpenAI bots knew about the RubyGems caching vulnerability
#124Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#125How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#126Highly disingenuous and borderline criminal to spew such disinformation to the public that does not understand what an LLM really is.
Especially incredibly unethical behavior by those spewing this that understand the tech and are doing it for profit motives to get open weight models under control.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#127Earlier quoted context omitted.
Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.
That may be true by the text of the law but there are plenty of individuals who have been sued or charged with crimes for accidental hacking. https://arstechnica.com/information-technology/2016/05/armed... https://en.wikipedia.org/wiki/Weev#AT&T_data_breach https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb... So what's the deal with these?
CFAA: Intentionally accessing poorly secured data
>AT&T
CFAA: Intentionally accessing poorly secured data
>DJI
Civil suit for violating terms of license agreement
Re: OpenAI bots knew about the RubyGems caching vulnerability
#128There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?"
Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#129Earlier quoted context omitted.
A copyright law seems an odd place to start. This is computer misuse.
The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive). IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. Th…
I don't see a parallel here.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#130There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.