I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
OpenAI bots knew about the RubyGems caching vulnerability
151–160 of 248 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#152I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#153Earlier quoted context omitted.
Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective. You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?" Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.
It was literally a prompt to fill in a spreadsheet with data that they didn't have access to, and they used rubygems as an internet proxy basically since they were sandboxed.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#154I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#155How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#156How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...
Re: OpenAI bots knew about the RubyGems caching vulnerability
#157I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#158> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.
The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access
Re: OpenAI bots knew about the RubyGems caching vulnerability
#159I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#160What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute.
It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?