We need a legal structure to make companies liable for the actions of the agents they've made.
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
OpenAI bots knew about the RubyGems caching vulnerability
181–190 of 248 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#182The problem with agents is not that we don't know how to defend. It's that defenders need to be more careful and work faster than ever. We can say now that wide scoped tokens should have been retired for years and it's all RubyGems fault but the reality is a lot of organization are not prepared for this.
Even if they take security seriously they don't have enough manpower or a good strategy to implement it, and sometimes you have no idea that something is a problem because it wasn't a problem for years.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#183I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#184Earlier quoted context omitted.
This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.
I very much say "Google uses web crawlers to scrape web pages." and if something breaks, or some data is stolen, everyone else is going to be saying that Google has to take responsibility.
I agree with you on the liability issue, but I don't think there much question about this issue outside the anti-AI conspiracy campaigns.
And I disagree with your typical usage claim. I myself tend to use the phrase that has the fewest words in all cases. It's like the rule against using passive tense when writing.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#185I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#186What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#187If I let out rats in the canteen, no one is blaming them when people get sick.
There are actual people behind these agents and in previous cases people knew they were "going rogue" and did nothing. This should be reported to the police like any other crime.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#188I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
This made me laugh. I too, browse like corporate security is sitting at my desk.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#189I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#190I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.