Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

131–140 of 199 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#131

Earlier quoted context omitted.

Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities.

He did not fall out of a window. He fell out of the sky . After his plane exploded. Happens all the time. Is tragedy.

I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#132
post #85

Earlier quoted context omitted.

Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…

> There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping. This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.

Intent is what is being discussed here though, not liability.

A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#133

Earlier quoted context omitted.

> There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping. This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.

Intent is what is being discussed here though, not liability. A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.

Except liability always precedes intent.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#134
post #45
post #23

Earlier quoted context omitted.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

[dead]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#135
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Oh yeah, more of hacking agent lores...

Agreed that this looks very intention to me as well.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#137

Earlier quoted context omitted.

> There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping. This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.

Intent is what is being discussed here though, not liability. A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.

Intent might be what’s being discussed but intent is, for the most part, legally irrelevant. It might make the difference in the degree of a murder charge, or maybe manslaughter, or criminal negligence, but it doesn’t get you off the hook.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#138
post #85
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide…

> Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process.

Who gives a shit? Not my circus; not my monkeys! It's the responsibility of whoever deploys the agents that they are instructed / sandboxed well enough that they can't cause collateral damage. That is the only way this doesn't get out of hand with everybody deploying their agents / robots for a world of utter chaos.

It is impossible (and asinine) to audit every model and deployment; far better to impose liability and the the socio-legal system figure it out.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#139
I wonder why we don't hear of other frontier labs experiencing these "break outs".

Is it that they're orchestrated? Do these labs lack fundamental safety guidelines in their sandboxes as opposed to their peers? Is it another version of hype-filled fear mongering?

Maybe LLM companies need regulation but it's becoming obvious that those screaming the loudest for it are the only ones I see deserving of it.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#140
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

[flagged]
Post reply on HN