Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

151–160 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#151
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

The site is safe. It has been a trademark of Aaron Patterson a core Ruby on Rails contributor for decades.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#153

Earlier quoted context omitted.

Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective. You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?" Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.

It was literally a prompt to fill in a spreadsheet with data that they didn't have access to, and they used rubygems as an internet proxy basically since they were sandboxed.

It was a model literally trained to hack. To be good at that. Doing an exploit gym from all of the things. And they trained it so that it performs as well as possible on that exploit gym thing.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#154
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Based on the thumbnail I think it’s actually tenderlove making dot com, though I agree with your sentiment.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#155
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#156

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...

No. They don't say "sorry". They say - our technology is just that powerful - please consider that in next funding round.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#158

> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.

The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access

So, not a sandbox then.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#159
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#160
What a time to be alive until the next agent waves hacks something really serious.

What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute.

It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

Post reply on HN