Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

401–410 of 416 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#401
post #302

Earlier quoted context omitted.

We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

The grandparent comment said "liable". That's civil court, not criminal, and doesn't need the DOJ to be involved. HuggingFace and/or RubyGems could sue OpenAI. States also have their own laws against unauthorized computer use (hacking). A state Attorney General could bring a suit under those laws, regardless of who is in the white house.

HF falls under French jurisdiction, right? Couldn’t a case be made over there?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#403
post #344

Earlier quoted context omitted.

No, it's not. The current so-called scandals about AI hacking into other companies were because a bunch of human beings intentionally configured the software to go and do exactly that thing. There's nothing deterministic about weather, so hopefully you're not just being disingenuous. It's obvious that the global transportation system, or financial markets, or any number of other things are complex adaptive dynamic sy…

>There's nothing deterministic about weather, so hopefully you're not just being disingenuous. You're the one being disingenuous. Look at what you wrote. > Is AI less deterministic than an airline dealing with weather? You didn't talk about how deterministic the weather is. You talked about how an airline responds to a weather event in comparison to AI, which means that it's about responding to presented information…

> rules are as deterministic as possible even if they rely on pilot intuition

I think you are profoundly confused.

An airplane, and an AI algorithm encoded into silicon, are inert physical objects.

Every evaluation we are doing here is of a complex system that involves the interaction of people and machines and physical connections and so on.

An aviation system connected to every country and region with millions of people and machines involved is no less complex than what’s under discussion here and no more deterministic.

We don’t regulate airplanes because they aren’t people. We regulate pilots and mechanics and leaders of the companies that make and own them.

The task at hand is to regulate the people involved in AI to get the outcomes we want.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#404

Earlier quoted context omitted.

That's a good idea, but a physical device is deterministic most of the time (if not always). E.g.: A lawnmower, as credited by the great Bryan Cantrill. However an AI agent, or the model powering it is stochastic by design. How can you certify something which doesn't behave the same twice, and more importantly we don't understand how it works 100%? BTW, really, how is that AI observability work is going in the fronti…

If something is risky, and the end operator cannot be considered to have orchestrated the outcomes of too use, then that tool typically has significant restrictions placed on it. Liability will shift to the maker of the tool if they claim that it’s easy to use, safe, or that you don’t need unique skills or training to use it. That would be considered reckless. Cars analogy - We have licenses for cars, and different t…

It's going to be interesting, because liability cases tend to revolve around the involved people, the duty they had in a situation, and if they fulfilled that duty (or were prevented in some way by someone else not fulfilling their duty).

For example, for a runaway car (example from a sibling comment), the driver could be liable because they forgot the parking brake. The driver could be liable for a lack of maintenance and inspection. A mechanic could be liable for not reinstalling brake pads correctly. Or the manufacturer of the car or the brake pads could be liable because of a systemic defect.

Or it could grow even more complex, maybe the brakes are designed that they have to be maintained in a very specific way, and the mechanic did a reasonable maintenance and inspection but it failed later due to this maintenance. That could split liability between the manufacturer and the mechanic.

As an example, with other software, you as a developer or operator of a software have a duty to ensure it does not access computer systems you do not own in unintended ways. And this could go beyond liability into criminal territory.

It'll be interesting what OpenAI gets slapped with there.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#405

Earlier quoted context omitted.

Negligence works fine.

One thing that works for that angle is that they didn't notify any of the parties involved afterwards. And there are reports that they are forbidden to talk about it. That seems a bit bad to me? But they can also say that the tech is so new that there is no known guardrails yet We live in exciting times

This is how law develops, no?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#406

Earlier quoted context omitted.

> In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. Software executes in the physical world, and is generally not exempt from existing liability rules, and actually (especially with commercial products) blame in traditional liability is non-exclusive and much broader than “either the maker or the u…

If I park my car on a hill but forget to set the parking brake and it rolls down the hill and kills somebody, who is at fault? Me? The Manufacturer? Gravity?

https://www.whatvan.co.uk/news/no-handbrake-van-driver-convi...

You.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#408

Earlier quoted context omitted.

I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.

How? Aren't all US frontier models ban the usage of AI for military purpose by parties other than US? I remember Anthropic even refusing allowing US government to use Claude for military purpose

I think it was mostly a matter of "how much" and marketing rather than "my principles won't allow for this!"

Re: OpenAI bots knew about the RubyGems caching vulnerability

#409
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled. Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all. As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign c…

There are several ways to get hold of tech and of any other thing. Russia did not have access to the H-bomb too, until it was handed to them. Ideals or money are very effective.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#410
post #236

Earlier quoted context omitted.

There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.

What is its one their "under development" models who escaped it's training, because it wasn't tuned properly?

The you treat it like an employee you started a fire that got out of control and damaged property. Was the employee supposed to start a fire, is the company liable ect.
Post reply on HN