Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

301–310 of 310 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#301
post #67

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title. I'm going to assume that this will never happen

[dead]

Re: OpenAI bots knew about the RubyGems caching vulnerability

#302

We need a legal structure to make companies liable for the actions of the agents they've made.

We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

The grandparent comment said "liable". That's civil court, not criminal, and doesn't need the DOJ to be involved. HuggingFace and/or RubyGems could sue OpenAI.

States also have their own laws against unauthorized computer use (hacking). A state Attorney General could bring a suit under those laws, regardless of who is in the white house.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#303

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

I wonder what kind of new AI law would be useful right now. Maybe this one: if an AI agent does something, you (the prompter) are responsible by default, unless you can show that your the agent itself behaved in an unexpected way and that you in no way prompted or hinted at the bad behavior, in which case the model provider is liable The idea is that by making it clear who is responsible, corporations and others star…

Far too many words. Tort law still applies.

The law that should be in place is that AI users and provides should be required to carry liability insurance when operating machines that may cause harm to the public.

We already do this for drivers, who are likely to hit the public with a few tons of steel.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#305

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

NAL. For fraud and abuse you need to have intent. There was very likely no intent on the side of OpenAI. They could sue for negligence I guess? I don't know how that works with AI agents

Re: OpenAI bots knew about the RubyGems caching vulnerability

#306

Earlier quoted context omitted.

"Limited liability" refers to shareholders' financial liability being limited to their investment, and has nothing to do with civil or criminal liability of employees for their own actions, whether "following orders" or not.

You might want to look up LLC (Limited Liability Company), which goes by other names in different countries but still basically mean the same (though details may vary between different company types). While there certainly are exceptions, as mentioned before, in principle the employees of a company are not personally legally accountable for their actions as performed in the service of a company. The legal entity of t…

Where I'm from, LLC has nothing to do with criminal and everything to do with financial liability. They can cause millions in damages but only get sued for a couple thousands. But years in prison are still years in prison.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#307
post #296
post #171

Earlier quoted context omitted.

I hate to spoil your mood - but it is currently unclear whether agents can be self-aware. And it's very likely something that can never be known.

How would one define self-awareness?

Well - yes - there is no agreed upon definition. Which makes the issue even harder to clearly determine.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#308
post #242
post #236

Earlier quoted context omitted.

What is its one their "under development" models who escaped it's training, because it wasn't tuned properly?

Counter argument being that this seems to indicate you can do whatever as long as you're innovating?

Isn’t that the tech industry motto?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#309

Earlier quoted context omitted.

I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows.

Sure, but it was unfortunate to pick the one dude who is well known, if for nothing else, for dying through means other than defenestration.

So what I'm saying by saying that he fell out a window is that Putin and/or the FSB arranged his death. It's not a statement of the means of his death, but who arranged it.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#310

Can we please stop normalizing this behavior. It's not wild it's reckless. If I let out rats in the canteen, no one is blaming them when people get sick. There are actual people behind these agents and in previous cases people knew they were "going rogue" and did nothing. This should be reported to the police like any other crime.

There was no malicious intent though, your analogy implies there was. And no real harm done apart from billable hours from the RubyGems guys.
Post reply on HN