Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

311–320 of 346 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#312
post #29

Earlier quoted context omitted.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.

There is no such thing as a Corporate person. Sounds like a something that was created by a legal system for people to absolve themselves of responsibility.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#313

Earlier quoted context omitted.

I think it is common that in installing packages you have hooks to execute code anyway.

This should not be common.

It wouldn't help much. Why would you install a gem other than to run it? And if you run it, it can execute arbitary code.

What we need is actually sandboxed dev environments.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#314
post #67

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title. I'm going to assume that this will never happen

I'd rather see executives and investors charged.

I'm also in favor of charging engineers so long as rich scumbags also get theirs.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#315

Earlier quoted context omitted.

If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.

I'm increasingly starting to think this is the end-state of AI. The internet becomes infected and fundamentally untrustworthy. At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment b…

If it were physically possible to run LLMs on IoT devices we would already have a global outbreak.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#316

Earlier quoted context omitted.

If it's covered by criminal law they don't need to sue. They can call the FBI.

Same FBI that prosecuted the Epstein crime ring so aggressively!

They're gonna get to the Epstein stuff right after they get the guy that called Kash Patel names.

https://newrepublic.com/post/215320/texts-kash-patel-order-s...

Re: OpenAI bots knew about the RubyGems caching vulnerability

#317

Earlier quoted context omitted.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

It shouldn't actually take that much bravery. If your case isn't completely frivolous, isn't your maximum loss limited to the court filing fees and a lawyer payment that you know in advance and can decide when to stop paying? It's not the same as getting sued.

Can't you be ordered to pay the legal fees of the person you sued if you lose badly enough?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#318
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

Is the Kremlin technologically useless?

Clearly, look at what is going on with Ukraine.

They are great at propaganda, so is China, Iran and North Korea, it's why everyone runs around spouting such stupid nonsense...

Re: OpenAI bots knew about the RubyGems caching vulnerability

#319

We need a legal structure to make companies liable for the actions of the agents they've made.

We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

It will remain this way in slightly differnt shades of colors until there is a systemic change. IM sorry this isn't a one party problem. There are people across the isle that are allowing this to continue.

Im not in support of any party btw. Im only in support of humanity doing humane things.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#320

Earlier quoted context omitted.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

Uh huh. It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact. Had this gone after a bank or a government agency someone would be going to jail.

Exactly. Just follow the patterns. Its pretty obvious.
Post reply on HN