OpenAI bots knew about the RubyGems caching vulnerability
311–320 of 330 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#312Earlier quoted context omitted.
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#313Earlier quoted context omitted.
I think it is common that in installing packages you have hooks to execute code anyway.
This should not be common.
What we need is actually sandboxed dev environments.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#314How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title. I'm going to assume that this will never happen
I'm also in favor of charging engineers so long as rich scumbags also get theirs.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#315Earlier quoted context omitted.
If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.
I'm increasingly starting to think this is the end-state of AI. The internet becomes infected and fundamentally untrustworthy. At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment b…
Re: OpenAI bots knew about the RubyGems caching vulnerability
#316Earlier quoted context omitted.
If it's covered by criminal law they don't need to sue. They can call the FBI.
Same FBI that prosecuted the Epstein crime ring so aggressively!
https://newrepublic.com/post/215320/texts-kash-patel-order-s...
Re: OpenAI bots knew about the RubyGems caching vulnerability
#317Earlier quoted context omitted.
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
It shouldn't actually take that much bravery. If your case isn't completely frivolous, isn't your maximum loss limited to the court filing fees and a lawyer payment that you know in advance and can decide when to stop paying? It's not the same as getting sued.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#318Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.
Clearly, look at what is going on with Ukraine.
They are great at propaganda, so is China, Iran and North Korea, it's why everyone runs around spouting such stupid nonsense...
Re: OpenAI bots knew about the RubyGems caching vulnerability
#319We need a legal structure to make companies liable for the actions of the agents they've made.
We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).
Im not in support of any party btw. Im only in support of humanity doing humane things.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#320Earlier quoted context omitted.
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
Uh huh. It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact. Had this gone after a bank or a government agency someone would be going to jail.