Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

191–200 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#192

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Maybe, but do you need to prove intent? Of the people, not the AI.

Accidents often have penalties associated with them too, but usually there's a difference between accidents and purposeful actions.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#193
post #175

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

“KGB agents are spying on me” is the same thing as “KGB is spying on me”, is it not? An agent is an entity acting on someone’s behalf.

KGB's agents are human, OpenAI's agents are not. It's an important distinction because humans are responsible for their behaviour, while AI agents are not.

You cannot try an AI agent in a court of law, despite the anthropomorphising work the word "agent" is doing.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#194
post #175

Earlier quoted context omitted.

“KGB agents are spying on me” is the same thing as “KGB is spying on me”, is it not? An agent is an entity acting on someone’s behalf.

KGB's agents are human, OpenAI's agents are not. It's an important distinction because humans are responsible for their behaviour, while AI agents are not. You cannot try an AI agent in a court of law, despite the anthropomorphising work the word "agent" is doing.

Exactly. It’s still just software, which someone programmed and deployed to do specifically dangerous/malicious things. I feel like we already have legislation and case law surrounding this.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#197
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

It's the personal blog for a well-known Rubyist (i.e., a person who programs in the Ruby programming language). Rubyists teld to be a bit more colorful than your typical software developer (in a good way... most of the time).

Re: OpenAI bots knew about the RubyGems caching vulnerability

#198
post #162

There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.

This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.

oh we do! At least they google is quite good at adhering to robots.txt.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#199
post #160

What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.

I'm increasingly starting to think this is the end-state of AI. The internet becomes infected and fundamentally untrustworthy.

At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment becomes questionable.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#200
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

What kind of esthetic alteration would make you more comfortable clicking on that link?
Post reply on HN