In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
> Maybe we need "quality certifications" for AI agents We need to use the laws that exist. Whoever decided to start the experiment that led to the Huggingface hack, and anyone above him up to Sam Altman, needs to be prosecuted under the CFAA.
OpenAI bots knew about the RubyGems caching vulnerability
431–440 of 454 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#432Re: OpenAI bots knew about the RubyGems caching vulnerability
#433Earlier quoted context omitted.
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?
> There are no negligent or stochastic hacking laws I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access". You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count. > knowingly accesses a computer without…
What, specifically, did Altman himself “knowingly access”?
I don’t think you would at all like where your novel legal theory leads. Certainly HN would be liable for creating a message board where people connected and started an open source project that led to a criminal act, for instance.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#434Earlier quoted context omitted.
That's a good idea, but a physical device is deterministic most of the time (if not always). E.g.: A lawnmower, as credited by the great Bryan Cantrill. However an AI agent, or the model powering it is stochastic by design. How can you certify something which doesn't behave the same twice, and more importantly we don't understand how it works 100%? BTW, really, how is that AI observability work is going in the fronti…
Sounds like owning a Dog
The idea that AI can’t possibly be addressed because it could autonomously break free and ruin something is fucking ridiculous.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#435Earlier quoted context omitted.
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk". https://www.law.cornell.edu/wex/reckless
It basically means anything bad that happens is a criminal indictment against everyone who created the conditions. Have you ever released any software that anyone could misuse? Left a car unlocked that someone could have stolen and killed someone with?
To me this sounds like a recipe for selective enforcement using bad outcomes as leverage. Sure, get the AI CEOs now, we all hate them and they’re jerks. But the tool would be so much more powerful than that.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#436Earlier quoted context omitted.
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#437In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…
It’s a good thought, but the tricky part is that few tools in the physical world are Turing complete and general purpose enough to do any job. The agent isn’t the model; it’s a layer on top of the model. So it’s kind of like saying that all of the tools made with a lathe are dangerous because you can make dangerous tools with a lathe. That’s not quite right of course because agents are packaged more tightly with mode…
Re: OpenAI bots knew about the RubyGems caching vulnerability
#438Earlier quoted context omitted.
It shouldn't actually take that much bravery. If your case isn't completely frivolous, isn't your maximum loss limited to the court filing fees and a lawyer payment that you know in advance and can decide when to stop paying? It's not the same as getting sued.
Can't you be ordered to pay the legal fees of the person you sued if you lose badly enough?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#439Earlier quoted context omitted.
There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.
What is its one their "under development" models who escaped it's training, because it wasn't tuned properly?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#440Earlier quoted context omitted.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.