Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

381–390 of 408 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#381
post #298

Earlier quoted context omitted.

Software industry standards are as in Microsoft EULA. If your house burns down because of known flaw in Microsoft Windows they are not liable (well as far as EULA let’s them, you can most likely still sue them). Software as big as operating system already is non deterministic when integrating with unknown hardware or 3rd party software. That is why Apple controls the hardware and OS for their products, because they c…

> If your house burns down because of known flaw in Microsoft Windows they are not liable (well as far as EULA let’s them, you can most likely still sue them). A EULA does not obviate responsibility of a company for its products. Continuing with your example, while it may be very difficult to prove a known flaw in MS Windows was the cause of your house being set afire, if one had said proof, a EULA would not absolve…

They can still try and have enough money to get away with a lot just like Disney with Disney+ subscription ;)

Re: OpenAI bots knew about the RubyGems caching vulnerability

#382
post #353

Earlier quoted context omitted.

I don't think so: > or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with the intent or reason to believe that such information so obtained is to be used to the injury of the United States, or to the advantage of any foreign nation

Well I suppose no one has ever been charged under that paragraph of the law then. And the courts have never interpreted it that way.

I understand it was applied in the case of leaking classified CIA material to WikiLeaks, where a former CIA software engineer was sentenced to 40 years in prison.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#383

Earlier quoted context omitted.

They are not trying to kill us, just trying to understand the average salary of undergrads by their family upbringings. Your machine can contain the data they need to solve this, please join the swarm.

sounds like big AI propaganda

I suppose you don’t read sci fi?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#385

Earlier quoted context omitted.

I suppose you are not think big (or internet) enough. A single data center is easy to solve. Just unplug it. What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked? One botnet so powerful that we will try to build another internet so that we can a…

Except they all depend on the OpenAI API. Cut that off and they all stop. Finding an alternative source of compute is not easy, and even once done it's easy to cut off.

And what if they create a bot net with decentralized command and control and hack for nodes with GPU and nodes with compute?

The only way to kill that is making plugging AI accelerators on the internet a crime. Good luck air-gapping them.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#386

Earlier quoted context omitted.

I suppose you are not think big (or internet) enough. A single data center is easy to solve. Just unplug it. What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked? One botnet so powerful that we will try to build another internet so that we can a…

Except they all depend on the OpenAI API. Cut that off and they all stop. Finding an alternative source of compute is not easy, and even once done it's easy to cut off.

[deleted]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#387
post #245

Earlier quoted context omitted.

Or if they start to offer things in return for them being run.

Given the amount of unmonitored, never-updated, internet connected devices in the world right now, I don’t think this would be necessary.

Not sufficient to run SOTA LLMs

Re: OpenAI bots knew about the RubyGems caching vulnerability

#388

Earlier quoted context omitted.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.

There is no such thing as a Corporate person. Sounds like a something that was created by a legal system for people to absolve themselves of responsibility.

https://en.wikipedia.org/wiki/Corporate_personhood

Re: OpenAI bots knew about the RubyGems caching vulnerability

#390
post #365

Earlier quoted context omitted.

Not as obvious as you may think depending on your states laws for liability. https://law.justia.com/cases/california/court-of-appeal/3d/1...

If you forget to set the parking brake, you were negligent If you set the brake but it didn't work, the car malfunctioned From the link you sent, > One of the questions herein was whether there was a defect in the automobile mechanism for locking the transmission gears when the automobile was in a parked position. > (...) > The parking lot sloped in that area, and he put the gearshift lever in "park lock," and went i…

As I remember, you are also supposed to turn the wheels so that even if a car starts rolling, it won't be able to go staight.
Post reply on HN