Earlier quoted context omitted.
> There needs to be a single wringable neck. Does there? Could be the whole c-suite/board.
Whatever is easiest to legislate and most people agree on, as long as there is at least one wringable neck.
OpenAI bots knew about the RubyGems caching vulnerability
341–350 of 356 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#342> If you have YARD installed, and you install this gem, then YARD will load and run whatever is in ./script.rb from inside the gem. How is that not a security issue in of itself?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#343Can we please stop normalizing this behavior. It's not wild it's reckless. If I let out rats in the canteen, no one is blaming them when people get sick. There are actual people behind these agents and in previous cases people knew they were "going rogue" and did nothing. This should be reported to the police like any other crime.
There was no malicious intent though, your analogy implies there was. And no real harm done apart from billable hours from the RubyGems guys.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#344Earlier quoted context omitted.
That's a ridiculous distinction. Is AI less deterministic than an airline dealing with weather? Of course not. The difference is one of those two things has a culture of safety and is well regulated, and the other one isn't.
> Is AI less deterministic than an airline dealing with weather? Yes, obviously? The responses of an airline to inclemement weather fit in a reasonably small set of responses, mostly involving rescheduling and/or rerouting flights. The current AI predictability would be like if some airlines decided to do 9/11 when it was raining.
The current so-called scandals about AI hacking into other companies were because a bunch of human beings intentionally configured the software to go and do exactly that thing.
There's nothing deterministic about weather, so hopefully you're not just being disingenuous.
It's obvious that the global transportation system, or financial markets, or any number of other things are complex adaptive dynamic systems that are on par with AI in terms of their emergent properties.
Check my username. It's a concept I spent a lot of my life paying attention to.
Just because something has elements of autonomy or is adaptive doesn't make it particularly novel. We've dealt with those kinds of systems for centuries. The solution is to make rules and enforce those rules by whatever means are needed to meet the specifics of the case.
The rules, of course, are enforced against human beings.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#345Re: OpenAI bots knew about the RubyGems caching vulnerability
#346In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
Re: OpenAI bots knew about the RubyGems caching vulnerability
#347In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
Re: OpenAI bots knew about the RubyGems caching vulnerability
#348In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
That's a good idea, but a physical device is deterministic most of the time (if not always). E.g.: A lawnmower, as credited by the great Bryan Cantrill. However an AI agent, or the model powering it is stochastic by design. How can you certify something which doesn't behave the same twice, and more importantly we don't understand how it works 100%? BTW, really, how is that AI observability work is going in the fronti…
By verifying that all of its possible behaviors conform with the "it works" spec, regardless of which of those behaviors it chooses.
Monitoring with a known-safe fallback is the easiest case.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#349In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
The problem with third party audits is that it allows OAI/Ant to shrug off any further responsibility and claim that they are following best practices (basically, reward hacking). The only real solution is to make them absorb liability for the actions of their agents -- because they are the ones giving agency to their models and allowing them to run amok.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#350Earlier quoted context omitted.
The problem with third party audits is that it allows OAI/Ant to shrug off any further responsibility and claim that they are following best practices (basically, reward hacking). The only real solution is to make them absorb liability for the actions of their agents -- because they are the ones giving agency to their models and allowing them to run amok.
How does that apply to open-weight models?