Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

171–180 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#171
post #144

Earlier quoted context omitted.

> One of the main purposes of LLMs is to launder responsibility No it isn't.

Yes, it is, for the reasons I stated in my comment, and you only need look at any OAI/Anthropic press release to see evidence of this in the language they use. The LLM now reasons better! Set the thinking level! It learns! All of these phrases are designed to give the impression that the LLM is an autonomous entity, when it is no such thing.

"Learning" is Samuel 1959, "agent" is standard textbook AI, "inference" is older still.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#172
post #145

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

> No harm, no foul.

What? That’s not how criminal law works, at all.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#173
post #19

I wonder how much of this is intentional "incompetence" so they can justify the most recent campaign to build a regulatory moat against competition. The repeated refusals to disclose until caught certainly seem malicious, yet at the same time the boasting about their capabilities is also at an all time high.

they are malicious. they probably did not intend to get caught. they are bragging about the crime and also bragging that they are untouchable, taunting us and betting that they will get away with it.

this is very coherent in terms of what we know about the company.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#174

Earlier quoted context omitted.

While his proposed policy is likely extremely unwise there's nothing illegal about it.

Bullshit. $5,000 for everyone if they vote to keep the GOP in power is clearly illegal. https://www.law.cornell.edu/uscode/text/18/597 > Whoever makes or offers to make an expenditure to any person, either to vote or withhold his vote, or to vote for or against any candidate; and > Whoever solicits, accepts, or receives any such expenditure in consideration of his vote or the withholding of his vote— > Shall be fined…

It's no more illegal than promising a tax cut for everyone if you're elected. What you can't do is promise money exclusively to the people who vote for you. That's bribery.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#177

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

>It’s interesting that a lot of U.S. law requires intent.

mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.

"sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"

I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#179

Unfortunately this will keep happening as long as developers run agents with unlimited tokens on unlimited VMs. Only have to forget about one, which happens all the time to developers. The LLM has infinite patience and will stumble into hacks, doesn't even have to be instructed as we are seeing. So tens of thousands of developers running agents, subagents as we speak, whats the chances...

Need a sheriff agent, who surely won't be bribed by the criminal agents and descend into corruption...

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#180
post #145

Earlier quoted context omitted.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

That's not really true. Unauthorized access to a system is a crime regardless if there was damage. https://www.law.cornell.edu/uscode/text/18/1030

You read your own source?

>having knowingly accessed [...]

>intentionally accesses a computer without authorization [...]

Post reply on HN