Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

201–210 of 248 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#201

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Criminal law may be lagging or inapplicable. (Crimes require "mens rea", a "guilty mind")

Tort law is very general: Contribute toward harming someone -> civil suit for damages $$$

Re: OpenAI bots knew about the RubyGems caching vulnerability

#202

Earlier quoted context omitted.

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

> There needs to be a single wringable neck. Does there? Could be the whole c-suite/board.

Whatever is easiest to legislate and most people agree on, as long as there is at least one wringable neck.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#203

Are "rouge" and "rogue" interchangeable words in American English?

The fact that both are valid from a spelling and grammar perspective makes it an easy human mistake.

Also, the fact that both are very unusual from a spelling perspective makes it an easy human mistake.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#204
post #177

Earlier quoted context omitted.

In this case, who holds the agency is exactly the point. Anthropic and OAI are claiming we need protection from AI itself, but the statement supported by putting agency in the right place is that we need protection from them .

I think those companies are referring to other companies - say Chinese AI companies - who we also need protection from.

"We" need protection from, or "OpenAI and Anthroptic's dreams of profits" need protection from?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#206

Earlier quoted context omitted.

I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.

How? Aren't all US frontier models ban the usage of AI for military purpose by parties other than US? I remember Anthropic even refusing allowing US government to use Claude for military purpose

Kimi / open models or jailbreaking frontier models. Your recollection of the Anthropic refusal isn't quite accurate, cyber hacking wasn't a sticking point, just domestic drag net surveillance and fully automated weaponry.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#207
post #58
post #49

Earlier quoted context omitted.

How is the responsibility diluted? Charge the CEO…

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

That is not how it works, at least in a civilized country. The charges are not about agents, it is about operational responsibility and negligence in the company itself.

CEO is responsible for letting this to happen, not enforcing enough supervision, if not intentionally, then being grossly negligent. More severe if encouraging and letting this kind of agent research and operations happen at scale, while knowing that it can damage other systems and businesses.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#208

Earlier quoted context omitted.

He did not fall out of a window. He fell out of the sky . After his plane exploded. Happens all the time. Is tragedy.

I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows.

Sure, but it was unfortunate to pick the one dude who is well known, if for nothing else, for dying through means other than defenestration.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#209
post #177

Earlier quoted context omitted.

I think those companies are referring to other companies - say Chinese AI companies - who we also need protection from.

"We" need protection from, or "OpenAI and Anthroptic's dreams of profits" need protection from?

I think that AI is dangerous and could be used as a weapon.

So yes, I would like to be protected from all parties. I don't think that's nuts.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#210

Earlier quoted context omitted.

These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled. Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all. As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign c…

Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.

I appreciate this line of questioning. It's really interesting to see how many excuses people need to reach for to avoid the conclusion that the "secret unheard of power" is B.S...
Post reply on HN