Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

221–230 of 248 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#221
post #160

What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

I suppose you are not think big (or internet) enough.

A single data center is easy to solve. Just unplug it.

What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked?

One botnet so powerful that we will try to build another internet so that we can actually use it again.

It’s like Kessler Syndrome, but the rocks are malicious network packets honed to exploit the recipients.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#222

The press wants to make it sound like these things are sentient and are committing crimes on their own now. Highly disingenuous and borderline criminal to spew such disinformation to the public that does not understand what an LLM really is. Especially incredibly unethical behavior by those spewing this that understand the tech and are doing it for profit motives to get open weight models under control.

We've moved on to LRMs now. Get with it.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#224

Earlier quoted context omitted.

Those provisions are specifically for the breaking or circumvention of technical measures designed to prevent copyright infringement. I don't see a parallel here.

They've been twisted to support almost anything, for example repairing your tractor is illegal because of this same law. But I agree this is just plain old hacking under a plain old reading of the CFAA and doesn't need any twists.

> for example repairing your tractor is illegal because of this same law.

No it's not. There has never been a case establishing that, and it's absurd on its face. The protection measures that the law makes illegal to break must control access to a copyrighted work, and you can't copyright functionality.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#225

Earlier quoted context omitted.

I, too, have no idea about legal matters. But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust. I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you g…

Let's take a hypothetical example: Suppose you're a firework company and your fireworks blow up, burning down the entire town. Could the company be sued? What is considered reasonable safety measures? IANAL, but I'm pretty confident there would be a lawsuit. Who gets charged might differ, depending if it is the firework factory that didn't take adequate safety precautions or a chemical supplier or someone else. If th…

There's a difference between being able to be successfully sued (civil liability, petitioned by a private entity) and charged (criminal liability, or petitioned by a government entity).

The thresholds for suing and charging differ greatly depending on the circumstances.

Another set of hypothetical examples that make things muddier:

- If I drive a fishing boat into a pier, I am liable, not the manufacturer of the boat

- If I drive a car over someone lying in the road, I am liable, not the manufacturer of the car

- If my life is in danger and I shoot a gun and kill my attacker, neither I nor the manufacturer are liable so long as I obeyed the relevant self defense laws and gun possession of whatever jurisdiction I am in

- If I fire a gun into a crowd indiscriminately, I am liable and several jurisdictions have used that to also hold gun manufacturer liable as well

That last example has been less successful as of late, but there are other variations too.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#226
post #29

Earlier quoted context omitted.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.

As far as I know (IANAL) it is in fact the only "person" you can charge. To the best of my knowledge, the whole point these "limited liability" legal constructions exist in the first place, is to protect individuals within a corporation for whatever they do as part of the business of a company (barring exceptions that have clearly not been part of that business and obvious individually committed crimes), typically "just following orders". If a company commits a crime, or in a worse case runs a criminal enterprise, it is the company that is legally responsible, not its employees. That is, in principle.

This can get more complicated higher up the management tree, where decisions can also be prosecuted on personal little, but that's usually a far more complicated matter. Also, if a whole group of employees willingly conspires to commit crimes, they might also be prosecuted individually for those crimes (there are limits to limited liabilities). However, that usually only works under special conditions and it would e.g. require that there's an obvious criminal enterprise aspect to it, rather than individual cases of illegal conduct.

That said, with the track record of some of these companies, actually designating some of the AI companies as a criminal enterprises may eventually happen (in due time) in some jurisdictions outside the USA. Certainly if it ever turns out that these companies have been storing and (ab)using everything they ever had access too, while blatantly lying about that just because some particular (post 9/11) US laws gives them that opportunity (and impunity) as long as the US government somehow requested them to do so (covertly; with gag order). Might legally work withing US jurisdiction, but would still be very much illegal everywhere else.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#227
post #160

What a time to be alive until the next agent waves hacks something really serious. What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute. It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

I suppose you are not think big (or internet) enough. A single data center is easy to solve. Just unplug it. What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked? One botnet so powerful that we will try to build another internet so that we can a…

Just let them communicate on the Bitcoin blockchain. "We" would have to freeze the chain and lose access to "our" billions of wealth, so not going to happen.

Sorry if that turns out the way they kill us.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#228
post #55

Earlier quoted context omitted.

The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available. I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be litter…

Why do you think they're not, and why do you think Russia cares about Reddit?

It’s an example of potential use by bad actors.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#229

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...

> Any future rich techbro computer criminal

Re: OpenAI bots knew about the RubyGems caching vulnerability

#230
post #65
post #63

Earlier quoted context omitted.

Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.

And which of these neutral countries have the capacity to serve them and the lack of awareness that hosting an offensive Russian agent swarm would bring hell back to their doorstep? Best they can do right now is rented botnets

Um... China?

No one is attacking China

Post reply on HN