Earlier quoted context omitted.
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.
OpenAI bots knew about the RubyGems caching vulnerability
141–150 of 212 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#142Earlier quoted context omitted.
How is the responsibility diluted? Charge the CEO…
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?
Re: OpenAI bots knew about the RubyGems caching vulnerability
#143Earlier quoted context omitted.
Intent is what is being discussed here though, not liability. A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.
Intent might be what’s being discussed but intent is, for the most part, legally irrelevant. It might make the difference in the degree of a murder charge, or maybe manslaughter, or criminal negligence, but it doesn’t get you off the hook.
The trainer who trained the lion to kill will probably be in jail for life. The one who happened to oversee a lion that went rouge would probably be given probation or something else that is a slap on the wrist.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#144How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#145OpenAI agents carried out an undisclosed attack on RubyGems - https://news.ycombinator.com/item?id=49666735 - Sept 2026 (600 comments)
Re: OpenAI bots knew about the RubyGems caching vulnerability
#146How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#147There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective. You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?" Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#148Re: OpenAI bots knew about the RubyGems caching vulnerability
#149Earlier quoted context omitted.
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?
So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.
Does there? Could be the whole c-suite/board.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#150I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com".