Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

141–150 of 212 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#141
post #45

Earlier quoted context omitted.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.

Why not both? (all people involved)

Re: OpenAI bots knew about the RubyGems caching vulnerability

#142
post #58
post #49

Earlier quoted context omitted.

How is the responsibility diluted? Charge the CEO…

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#143

Earlier quoted context omitted.

Intent is what is being discussed here though, not liability. A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.

Intent might be what’s being discussed but intent is, for the most part, legally irrelevant. It might make the difference in the degree of a murder charge, or maybe manslaughter, or criminal negligence, but it doesn’t get you off the hook.

Correct, but the size difference of the hook can be so dramatic that you can't just hand wave it away.

The trainer who trained the lion to kill will probably be in jail for life. The one who happened to oversee a lion that went rouge would probably be given probation or something else that is a slap on the wrist.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#144
post #29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Issuing subpeonas, raiding offices, and dragging key employees into interrogation rooms as you would find in any normal criminal investigation would be more than enough to ensure "AI safety" without any new regulations, acts of congress, Bernie Sanders campaign speeches, or even charges filed.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#146

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...

Re: OpenAI bots knew about the RubyGems caching vulnerability

#147
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective. You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?" Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.

It was literally a prompt to fill in a spreadsheet with data that they didn't have access to, and they used rubygems as an internet proxy basically since they were sandboxed.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#149
post #58

Earlier quoted context omitted.

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

> There needs to be a single wringable neck.

Does there? Could be the whole c-suite/board.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#150
post #148

I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".

You get some context by clicking on the “(tenderlovemaking.com)” in parentheses after the title.
Post reply on HN