Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

181–190 of 248 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#181

We need a legal structure to make companies liable for the actions of the agents they've made.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

It shouldn't actually take that much bravery. If your case isn't completely frivolous, isn't your maximum loss limited to the court filing fees and a lawyer payment that you know in advance and can decide when to stop paying? It's not the same as getting sued.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#182
Build scripts being able to run arbitrary code or access the network is always dangerous even if it was just local on developer machines. It's also more evidence that Docker/LXC is not a security boundary and all untrusted code should run in a Firecracker VM.

The problem with agents is not that we don't know how to defend. It's that defenders need to be more careful and work faster than ever. We can say now that wide scoped tokens should have been retired for years and it's all RubyGems fault but the reality is a lot of organization are not prepared for this.

Even if they take security seriously they don't have enough manpower or a good strategy to implement it, and sometimes you have no idea that something is a problem because it wasn't a problem for years.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#183
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.

Presumably the browser still has to fetch the page in that case, right? From a "surveilled net traffic" perspective, how is that different than clicking the link?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#184
post #162

Earlier quoted context omitted.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

I very much say "Google uses web crawlers to scrape web pages." and if something breaks, or some data is stolen, everyone else is going to be saying that Google has to take responsibility.

Those are two different issues. One is about typical speech patterns and one is about liability.

I agree with you on the liability issue, but I don't think there much question about this issue outside the anti-AI conspiracy campaigns.

And I disagree with your typical usage claim. I myself tend to use the phrase that has the fewest words in all cases. It's like the rule against using passive tense when writing.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#185
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Don't worry! It's actually "Tenderlove Making," going by how the site header is constructed. Definitely a maker/hacker site, and not whatever you were thinking. Hope this allays your concern.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#186
post #160

What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#187
Can we please stop normalizing this behavior. It's not wild it's reckless.

If I let out rats in the canteen, no one is blaming them when people get sick.

There are actual people behind these agents and in previous cases people knew they were "going rogue" and did nothing. This should be reported to the police like any other crime.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#188
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

This made me laugh. I too, browse like corporate security is sitting at my desk.

Pretty incredible how much humans can be conditioned, isn’t it?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#190
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

Firefox has got some kind of feature to take a peek at at a link by hovering or something... Now I understand the usecase.

From an infosec/networking stand point, aren’t still actively loading the site? Whether it’s in a preview window or not?
Post reply on HN