Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

171–180 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#171
post #162

Earlier quoted context omitted.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

I would agree with you generally, but in this particular case, the distinction seems important because a significant percentage of the world population believes that agents can be self-aware, a-là Terminator etc.

I hate to spoil your mood - but it is currently unclear whether agents can be self-aware. And it's very likely something that can never be known.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#174
post #162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

In this case, who holds the agency is exactly the point. Anthropic and OAI are claiming we need protection from AI itself, but the statement supported by putting agency in the right place is that we need protection from them.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#175

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

“KGB agents are spying on me” is the same thing as “KGB is spying on me”, is it not?

An agent is an entity acting on someone’s behalf.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#176
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

It doesn't need to be twisted to violate the DMCA anticircumvention clause because it is already just plain old hacking.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#177
post #162

Earlier quoted context omitted.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

In this case, who holds the agency is exactly the point. Anthropic and OAI are claiming we need protection from AI itself, but the statement supported by putting agency in the right place is that we need protection from them .

I think those companies are referring to other companies - say Chinese AI companies - who we also need protection from.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#178

Earlier quoted context omitted.

The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive). IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. Th…

Those provisions are specifically for the breaking or circumvention of technical measures designed to prevent copyright infringement. I don't see a parallel here.

They've been twisted to support almost anything, for example repairing your tractor is illegal because of this same law. But I agree this is just plain old hacking under a plain old reading of the CFAA and doesn't need any twists.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#179
post #162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

I very much say "Google uses web crawlers to scrape web pages." and if something breaks, or some data is stolen, everyone else is going to be saying that Google has to take responsibility.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#180
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.

How? Aren't all US frontier models ban the usage of AI for military purpose by parties other than US? I remember Anthropic even refusing allowing US government to use Claude for military purpose
Post reply on HN