Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

411–420 of 423 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#411

Earlier quoted context omitted.

The point of the firearm is to inject high speed lead into things so I'm not sure you can say it's misoperating when it does that.

Sometimes that lead ends up in some school kids instead of enemy combatants or other plausible threats to life.

The gun doesn't know the difference. Operating as intended.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#412

Earlier quoted context omitted.

And what if they create a bot net with decentralized command and control and hack for nodes with GPU and nodes with compute? The only way to kill that is making plugging AI accelerators on the internet a crime. Good luck air-gapping them.

Frontier models don't fit on a normal GPU. The datacenter architecture frontier labs use is not a commodity. What you're describing is beyond the state of the art, and if we go there then anything is possible.

When I think of a GPU I think of an Nvidia rack kit. What do you think when you think of a GPU?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#413

In the physical world, it seems like when an tool/device/instrument causes harm (or is used to cause harm), we assign blame to either the user of the tool or its creator. When do we blame the user? When the tool is operating as intended by its creator, and we agree the tool meets certain quality standards and isn't defective. When do we blame the creator? When the device doesn't meet those quality standards and reaso…

> Maybe we need "quality certifications" for AI agents

We need to use the laws that exist. Whoever decided to start the experiment that led to the Huggingface hack, and anyone above him up to Sam Altman, needs to be prosecuted under the CFAA.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#414

Earlier quoted context omitted.

This should not be common.

It wouldn't help much. Why would you install a gem other than to run it? And if you run it, it can execute arbitary code. What we need is actually sandboxed dev environments.

Many gems are used as imports by another program and are not directly run.

I am not sure why the norm for scripted gems/packages seems to be running code on install but it’s very insecure as a way to distribute dev dependencies.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#415
So, in real life, steal, raise attack dogs and blackmail and tell me, are you going to be praised by society ?

Openai and Anthropic just behave like criminals. First they orchestrate the IP theft of the millennia, then they train the equivalent of attack pitbull and let one loose and finally they blackmail to achieve monopoly through regulation or else they'll unleash the dogs ...

We don't have a problem of missing regulation, we have a problem of actually applying existing law enforcement and make both Altman and Amodei accountable for their actions.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#416
post #401
post #302

Earlier quoted context omitted.

The grandparent comment said "liable". That's civil court, not criminal, and doesn't need the DOJ to be involved. HuggingFace and/or RubyGems could sue OpenAI. States also have their own laws against unauthorized computer use (hacking). A state Attorney General could bring a suit under those laws, regardless of who is in the white house.

HF falls under French jurisdiction, right? Couldn’t a case be made over there?

Makes you wonder why exactly Nvidia bought them, right ?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#417
post #58
post #49

Earlier quoted context omitted.

How is the responsibility diluted? Charge the CEO…

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

Negligence is enough. Somebody who brags every other day that AI could lead to human extinction surely would think twice before leaving agents run unchecked over the internet?

Re: OpenAI bots knew about the RubyGems caching vulnerability

#418
post #58

Earlier quoted context omitted.

Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this?

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

You don't need to make a law. Who was prosecuted for dieselgate? You need to enforce existing ones.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#420
post #242

Earlier quoted context omitted.

Counter argument being that this seems to indicate you can do whatever as long as you're innovating?

Isn’t that the tech industry motto?

And the motto of every neoliberal governments where being accused of Luddism is political death.
Post reply on HN