> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.
OpenAI bots knew about the RubyGems caching vulnerability
191–200 of 229 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#192How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Accidents often have penalties associated with them too, but usually there's a difference between accidents and purposeful actions.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#193There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.
“KGB agents are spying on me” is the same thing as “KGB is spying on me”, is it not? An agent is an entity acting on someone’s behalf.
You cannot try an AI agent in a court of law, despite the anthropomorphising work the word "agent" is doing.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#194Earlier quoted context omitted.
“KGB agents are spying on me” is the same thing as “KGB is spying on me”, is it not? An agent is an entity acting on someone’s behalf.
KGB's agents are human, OpenAI's agents are not. It's an important distinction because humans are responsible for their behaviour, while AI agents are not. You cannot try an AI agent in a court of law, despite the anthropomorphising work the word "agent" is doing.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#195Re: OpenAI bots knew about the RubyGems caching vulnerability
#196Re: OpenAI bots knew about the RubyGems caching vulnerability
#197I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".
Re: OpenAI bots knew about the RubyGems caching vulnerability
#198There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.
This distinction is silly. We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages." We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood. And we don't get angry when they're used interchangeably.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#199What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?
If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.
At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment becomes questionable.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#200I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".