Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

351–360 of 364 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#351
post #327

Earlier quoted context omitted.

Having worked in self driving cars safety, the process there was simple: get confidence in SIM (integration tests for safety scenarios), validate in the test bed, approve features for maturity, then when released in the public for testing, do a trial exposure to the real world and recall if something is off. A lot of these companies have gone the way of Tesla and decided to just patch on top when the fix is out and h…

Physical harm vs consequential harm is not the same thing at all. Seems like you're being paid to spread this request for regulation, or "you" are simply an agent of Anthropic/OpenAI.

I wish. Consequential harm as you call it, from a faceless company's point of view is the same cost as physical harm. I don't think the models beyond the frontier ones have significant risk of harm (minus the harm of trusting them). What I was saying is when these models go rogue, recall them! Re-evaluate your release structure and stop saying "Whoops! Anyway here's access to it now". And if you cause this level of harm then you should lose your license. But if you behave then you get to keep testing. Same as with the NTSB and autonomous vehicles. No I'm not for regulation for open source models. Because an entity will be running that model in the background and they can be held responsible for not testing it. Comma AI has survived fine being in the open, yet their market penetration has stayed low because of adoption costs.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#352

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

I sincerely hope they sue. There are few companies with more resources and reason to be better, but this is what we see. None of this will stop until there are actual consequences.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#353
post #269

Earlier quoted context omitted.

The first count is "or any restricted data", not classified material. A technological restriction, is enough. "Knowingly accessed" has never meant you personally. Operators of a botnet don't know directly what they access. They know that the autonomous software is built to access restricted things.

I don't think so: > or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with the intent or reason to believe that such information so obtained is to be used to the injury of the United States, or to the advantage of any foreign nation

Well I suppose no one has ever been charged under that paragraph of the law then. And the courts have never interpreted it that way.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#354

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

> In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. Software executes in the physical world, and is generally not exempt from existing liability rules, and actually (especially with commercial products) blame in traditional liability is non-exclusive and much broader than “either the maker or the u…

If I park my car on a hill but forget to set the parking brake and it rolls down the hill and kills somebody, who is at fault? Me? The Manufacturer? Gravity?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#355

Earlier quoted context omitted.

There was no malicious intent though, your analogy implies there was. And no real harm done apart from billable hours from the RubyGems guys.

You don't need intent to be fined or jailed for criminal negligence. Let anthrax or smallpox escape your lab, and kill and maim people and see how your "no malice" defense holds up.

Sure but nobody died, which makes it a bad analogy. If anything, some good came from it, since now RubyGems has hardened their setup.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#356

Earlier quoted context omitted.

"Limited liability" refers to shareholders' financial liability being limited to their investment, and has nothing to do with civil or criminal liability of employees for their own actions, whether "following orders" or not.

You might want to look up LLC (Limited Liability Company), which goes by other names in different countries but still basically mean the same (though details may vary between different company types). While there certainly are exceptions, as mentioned before, in principle the employees of a company are not personally legally accountable for their actions as performed in the service of a company. The legal entity of t…

You are still personally legally liable if you break the law in a criminal matter. It is literally law 101 on when it is appororiate to lift the corporate viel. I'm very sure you are not a lawyer but you shouldn't go around calling people uneducated while saying illogical things like this.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#357

Earlier quoted context omitted.

> In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. Firearms are a notorious example where some people get, well, weird.

The point of the firearm is to inject high speed lead into things so I'm not sure you can say it's misoperating when it does that.

Sometimes that lead ends up in some school kids instead of enemy combatants or other plausible threats to life.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#358
post #344
post #336

Earlier quoted context omitted.

> Is AI less deterministic than an airline dealing with weather? Yes, obviously? The responses of an airline to inclemement weather fit in a reasonably small set of responses, mostly involving rescheduling and/or rerouting flights. The current AI predictability would be like if some airlines decided to do 9/11 when it was raining.

No, it's not. The current so-called scandals about AI hacking into other companies were because a bunch of human beings intentionally configured the software to go and do exactly that thing. There's nothing deterministic about weather, so hopefully you're not just being disingenuous. It's obvious that the global transportation system, or financial markets, or any number of other things are complex adaptive dynamic sy…

[deleted]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#359
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

That is a very convenient conclusion that certain entities would love for us to accept as true, but fuck that. If it is “diluted” as that the buck stops at the publisher of the model.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#360

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

> Maybe we need "quality certifications" for AI agents - essentially eval suites that demonstrate those agents won't cause harm under reasonable patterns of usage Based on how LLMs work, this is impossible. You cannot predict how they work, it's literally based on a combination of random seed and a mostly-unpredictable path walked based on every token of input. You don't blame a knifemaker for somebody getting cut by…

> You don't blame a knifemaker for somebody getting cut by a sharp knife. AI is a knife. Very handy, very dangerous. We have to use them safely, that's all there is to it.

If I grossly neglected to maintain live deadly bacteria in my containment facility, am I absolved of blame? Since, you know, the bacteria is the real bad guy who should be put in jail?

Post reply on HN