Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

391–400 of 416 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#391

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

>truly air-gapped environments

I don't think people have given much thought about just how hard this would be for large AI models, that need super powerful hardware/cooling etc.

Are you going to air-gap your entire data center?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#392

Earlier quoted context omitted.

Except they all depend on the OpenAI API. Cut that off and they all stop. Finding an alternative source of compute is not easy, and even once done it's easy to cut off.

And what if they create a bot net with decentralized command and control and hack for nodes with GPU and nodes with compute? The only way to kill that is making plugging AI accelerators on the internet a crime. Good luck air-gapping them.

Frontier models don't fit on a normal GPU. The datacenter architecture frontier labs use is not a commodity. What you're describing is beyond the state of the art, and if we go there then anything is possible.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#393

We need a legal structure to make companies liable for the actions of the agents they've made.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

I mean it's surprising to think you're 99% sure while being wildly off base. Everything in there require intent.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#394

Earlier quoted context omitted.

Sometimes that lead ends up in some school kids instead of enemy combatants or other plausible threats to life.

True, but that's unfortunately (usually) not because the thing misfired randomly.

Yes. That’s “is used to cause harm” situation, exactly.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#396

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

>truly air-gapped environments I don't think people have given much thought about just how hard this would be for large AI models, that need super powerful hardware/cooling etc. Are you going to air-gap your entire data center?

You don't need data center for inference. Even largest models run on a single server. You need data center for training; or for serving millions of users. Evaluating the model is neither of those.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#397

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

>truly air-gapped environments I don't think people have given much thought about just how hard this would be for large AI models, that need super powerful hardware/cooling etc. Are you going to air-gap your entire data center?

Why not?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#398

Earlier quoted context omitted.

Why wouldn’t this same concept apply to whoever is serving it up? Open-weight models are still being served up by infra providers and neoclouds, right? They should be in the hot seat. Not sure? Don’t provide the model. Need assurance? A certified evaluation like the previous comments have mentioned can help. Hosting and running it yourself? You’re in the hot seat.

So is there no liability for, say, a company that releases a known dangerous open-weight model, but fails to disclose that it is dangerous? How about a company that distributes malware under the guise of legitimate software?

Perhaps don't deploy random weights of unknown origin?

Also not every model provider might be capable of babysitting all your uncontrolled agent deployments. If you want SLOs, get into a contractual relationship with entities whose weights you deploy, and also monitor your agents so they don't go off the rails.

All this is just like deploying any other tech in the world eg. if you buy a car, or a chainsaw, or a book.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#399
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

Cyber attacks between these countries were happening on large scale since the beginning of the war. There were several huge breaches, but otherwise most high-profile companies adapted and significantly strengthened their protections. Rest assured, you can be sure that both sides right now utilize available AI both for attack and defense.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#400

Earlier quoted context omitted.

I could make a non-deterministic chainsaw fairly easily. I’d also get sued into the ground if I sold it, and I wouldn’t be able to claim ‘Oh, it’s just an unavoidable part of progress’.

A non-deterministic machine is usually called defective

It’s not a defect, the stochastic “temperature” setting unleashes the chainsaw’s creativity and imagination! Who are we to cast aspersions on the Oracle Chainsaw’s intelligence—nay, wisdom!—just because it happens to be non-living?
Post reply on HN