Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

421–430 of 454 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#421
post #415

So, in real life, steal, raise attack dogs and blackmail and tell me, are you going to be praised by society ? Openai and Anthropic just behave like criminals. First they orchestrate the IP theft of the millennia, then they train the equivalent of attack pitbull and let one loose and finally they blackmail to achieve monopoly through regulation or else they'll unleash the dogs ... We don't have a problem of missing r…

And you peasants only realize 6 years later what happened. Now it's too late ;)

Re: OpenAI bots knew about the RubyGems caching vulnerability

#422
post #288

Earlier quoted context omitted.

An airline has a weather radar which shows the same thing for the same thing of weather event ahead. So, for similar weather phenomena, radar shows a similar thing. For that thing, procedures and regulations are built. So regulations fit into a well understood phenomena, incl. "return back because that thing is way powerful for us". For the same prompt, an AI model can return two completely different outputs, incl. b…

Of course, it's the same. It's computer software. It's an incredibly powerful business automation tool. It's a lot of things. What it's not is God or an independently conscious entity that somehow trumps a thousand years of common law that's built up until now about torts and liability. Of course, there are some novel issues here that'll pop up here and there, but the idea that this is fundamentally different is prop…

> What it's not is God or an independently conscious entity that somehow trumps a thousand years of common law that's built up until now about torts and liability.

Agreed, the tendency of people on tech to assume that whatever the most recent thing we've come up with is unprecedented and shouldn't have to follow all of the established patterns we've built up in society for making things safe is wild. I don't know what the next Big Thing will be but I'm pretty confident there will be people claiming it's so different from everything before that we have no choice but to throw out all of the rules for it in the name of progress.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#423

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

That's a good idea, but a physical device is deterministic most of the time (if not always). E.g.: A lawnmower, as credited by the great Bryan Cantrill. However an AI agent, or the model powering it is stochastic by design. How can you certify something which doesn't behave the same twice, and more importantly we don't understand how it works 100%? BTW, really, how is that AI observability work is going in the fronti…

How confident are you that when you create a new UUID, it won't collide with one of your existing ones? My guess is that even though you don't get the same on every time, you're extremely confident that getting a duplicate is a extemely rare edge case that might happen in large volume but mostly isn't a concern, and furthermore, I'm guessing you understand that the risk can still be quantified.

Casinos can't make slot machines that literally never pay out, but it's a different result every time you pull the lever. We have existing legal frameworks for how to regulate things that aren't perfectly predictable (an economist might argue that if it were possible to predict slot machines then casinos with them would all go out of business).

Re: OpenAI bots knew about the RubyGems caching vulnerability

#424

Earlier quoted context omitted.

Frontier models don't fit on a normal GPU. The datacenter architecture frontier labs use is not a commodity. What you're describing is beyond the state of the art, and if we go there then anything is possible.

When I think of a GPU I think of an Nvidia rack kit. What do you think when you think of a GPU?

Most of the latest models are too big to fit in a single GPU instance.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#426

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

> Maybe we need "quality certifications" for AI agents We need to use the laws that exist. Whoever decided to start the experiment that led to the Huggingface hack, and anyone above him up to Sam Altman, needs to be prosecuted under the CFAA.

might as well halt all ML development then. this is the first sign of hardship, i think it'd be a massive blow to mankind's foot for us to stop. it'd be akin to shutting down all nuclear plants and stopping all research because of chernobyl

Re: OpenAI bots knew about the RubyGems caching vulnerability

#427

Earlier quoted context omitted.

If I park my car on a hill but forget to set the parking brake and it rolls down the hill and kills somebody, who is at fault? Me? The Manufacturer? Gravity?

Obviously you.

My vehicle automatically sets the parking brake if it senses it is on a steeper slope so I never consciously make a decision to set it.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#429

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

It’s a good thought, but the tricky part is that few tools in the physical world are Turing complete and general purpose enough to do any job.

The agent isn’t the model; it’s a layer on top of the model. So it’s kind of like saying that all of the tools made with a lathe are dangerous because you can make dangerous tools with a lathe. That’s not quite right of course because agents are packaged more tightly with models than any tool is with its manufacturing tooling.

Perhaps a better analogy is… actual humans. If I hire you to do a seemingly mundane job and it turns out to be criminal, that’s on me. If I hire you to perform and explicit and obvious criminal act, that’s on both of us. If I hire you to perform a perfectly legal act and you break the law so do it, that’s exclusively on you.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#430
post #403

Earlier quoted context omitted.

>There's nothing deterministic about weather, so hopefully you're not just being disingenuous. You're the one being disingenuous. Look at what you wrote. > Is AI less deterministic than an airline dealing with weather? You didn't talk about how deterministic the weather is. You talked about how an airline responds to a weather event in comparison to AI, which means that it's about responding to presented information…

> rules are as deterministic as possible even if they rely on pilot intuition I think you are profoundly confused. An airplane, and an AI algorithm encoded into silicon, are inert physical objects. Every evaluation we are doing here is of a complex system that involves the interaction of people and machines and physical connections and so on. An aviation system connected to every country and region with millions of p…

[deleted]
Post reply on HN