Earlier quoted context omitted.
I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows.
Sure, but it was unfortunate to pick the one dude who is well known, if for nothing else, for dying through means other than defenestration.
OpenAI bots knew about the RubyGems caching vulnerability
231–240 of 302 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#232The press wants to make it sound like these things are sentient and are committing crimes on their own now. Highly disingenuous and borderline criminal to spew such disinformation to the public that does not understand what an LLM really is. Especially incredibly unethical behavior by those spewing this that understand the tech and are doing it for profit motives to get open weight models under control.
We've moved on to LRMs now. Get with it.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#233What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?
I suppose you are not think big (or internet) enough. A single data center is easy to solve. Just unplug it. What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked? One botnet so powerful that we will try to build another internet so that we can a…
Re: OpenAI bots knew about the RubyGems caching vulnerability
#234Earlier quoted context omitted.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.
Individual employees can also be charged for their specific actions as part of the performance of a crime.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#235How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Was not that the goal when companies started using AI for their customer support? Be able to say anything without legal repercussions...
But then this happened: https://www.bbc.com/travel/article/20240222-air-canada-chatb...
And support chatbot got a reality cold shower.
The law will find a way to charge people in particular. Sadly will start with the less powerful in the chain before it actually acts on the people that can actually change things.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#236Earlier quoted context omitted.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#237How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Criminal law may be lagging or inapplicable. (Crimes require "mens rea", a "guilty mind") Tort law is very general: Contribute toward harming someone -> civil suit for damages $$$
Re: OpenAI bots knew about the RubyGems caching vulnerability
#238Earlier quoted context omitted.
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?
> There are no negligent or stochastic hacking laws I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access". You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count. > knowingly accesses a computer without…
Are you sure that is applicable here?
And for the first count with 'knowingly accessed', he would need to have accessed classified national-defense or atomic-energy information, otherwise we are back to 'intentionally accessed'.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#239Earlier quoted context omitted.
I suppose you are not think big (or internet) enough. A single data center is easy to solve. Just unplug it. What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked? One botnet so powerful that we will try to build another internet so that we can a…
well, its war of machine then
Re: OpenAI bots knew about the RubyGems caching vulnerability
#240Earlier quoted context omitted.
I would agree with you generally, but in this particular case, the distinction seems important because a significant percentage of the world population believes that agents can be self-aware, a-là Terminator etc.
I hate to spoil your mood - but it is currently unclear whether agents can be self-aware. And it's very likely something that can never be known.