Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

161–170 of 248 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly.

We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages."

We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood.

And we don't get angry when they're used interchangeably.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#163
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.

… a feature which, at least for me, is rendered almost entirely useless by massive cookie banners that always cover the entire field of view of the hover. But, surprisingly, not in this specific case.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#164
post #162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

Google's web crawlers are automated and that's part of their business practice.

The attack here is neither of those things.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#166
post #162

Earlier quoted context omitted.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

Google's web crawlers are automated and that's part of their business practice. The attack here is neither of those things.

That distinction doesn't matter to my point.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#167
Let me leave yet another reminder, the real-reason-nobody-talks-about that OpenAI likes to frame these incident as a watershed "lets all be scared about safety moment" - is driven not by some great danger, not because they strategically want to build a legislative moat, but by a very simple human response.

If they do not frame their tool as a force of nature, we'd be debating how to hold OpenAI responsible for not putting the agents in a container.

Their actions were an illegal use of a computer, the same way launching any bot-net attempting thousands of hacks against different servers is illegal.

I'm somewhat radical that I think its debatable if that _should_ be illegal, but under current law their actions unambiguously are illegal.....

except if they can make it ambiguous by having the public focus on all of AI's inherent danger.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#168
post #162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

I would agree with you generally, but in this particular case, the distinction seems important because a significant percentage of the world population believes that agents can be self-aware, a-là Terminator etc.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#169

Earlier quoted context omitted.

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

> There needs to be a single wringable neck. Does there? Could be the whole c-suite/board.

I'd settle for any number of necks. Currently, when a corporation fucks something up, breaks the law, or hurts or even kills people, there aren't consequences besides a tiny token fine and a strongly worded letter telling them to not do it again or they'll get another tiny fine and letter, and their CEO might even have to sit down in front of Congress to say a few words and look sad.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#170
post #55

Earlier quoted context omitted.

Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those.

The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available. I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be litter…

Why do you think they're not, and why do you think Russia cares about Reddit?
Post reply on HN