Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

101–110 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#102
post #45
post #23

Earlier quoted context omitted.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

‘It wasn’t us, it was a bug in the software’ used to be the defense for bad code. Then it became the defense for self-driving cars. Now it’s being used for AI cyber attacks.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#103
post #26

Earlier quoted context omitted.

Marketing actually.

AI is dropping out of the spotlight so they are using desperate measures like this.

No, I remember being threatened by OpenAI and then Anthropic (and now both) since back when ChatGPT was seriously useless.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#105
post #90
post #69

Earlier quoted context omitted.

I think this fails a lot of logical tests, it should be apparent in day to day life.

> In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center […], and which were used as "criminal proxies" and used spear-phishing schemes to target Russians l…

Yes.

I again am just shocked the sky is not falling, when thats the sales pitch.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#106
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

A copyright law seems an odd place to start. This is computer misuse.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#107

We need a legal structure to make companies liable for the actions of the agents they've made.

We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

You may be disappointed in how little a democrat president (who will also have taken billions of dollars from the tech lobby) will be willing to go after these tech firms over crimes that are several years old (as of 2029) much less contemporary bad behavior.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#108

Earlier quoted context omitted.

I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.

If it's covered by criminal law they don't need to sue. They can call the FBI.

Same FBI that prosecuted the Epstein crime ring so aggressively!

Re: OpenAI bots knew about the RubyGems caching vulnerability

#109
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

AI is literally state sponsored so I don't see that happening unless the AI turns against the sponsor.

Wait until OpenAI or Anthropic exploit FAANG.

Post reply on HN