Live data from Hacker News

ChatGPT claims rogue AI attacked more companies

bbc.co.uk

51–60 of 89 posts

Re: ChatGPT claims rogue AI attacked more companies

#51
Expected outcome: those laws they've been asking for since the old days.

> 2023 - OpenAI’s Sam Altman Urges A.I. Regulation in Senate Hearing

https://www.nytimes.com/2023/05/16/technology/openai-altman-...

Meanwhile Anthropic is scaremongering about China and also calling for more AI regulation (specifically mandatory safety testing of all models including open model):

https://news.ycombinator.com/item?id=49076057

Re: ChatGPT claims rogue AI attacked more companies

#52

Seems like OpenAI should be shut down by regulators until they can figure out how to stop launching cyberattacks on rivals. This will not happen though, because these stories are marketing.

> This will not happen though, because these stories are marketing. The magnitude and the complexity of the cynicism displayed by some people when it comes to AI risks is mind-blowing. It's like if the NRA reported on school shootings and people said "oh, they probably fake these shootings to make guns sound dangerous and sell more of them". OpenAI could report that its AI started spontaneously generating illegal por…

It is because a loud part of the doomerist contingent believe only a major disaster will provide the motivation for regulation, so they are practically hoping to cultivate a major disaster. (Given their preoccupation with bioweapons that probably means a pandemic).

This is based on similar thinking to how the world would not have considered nuclear weapons a major threat if they had forever stayed unused.

The irony of the doomer position is it achieves exactly their supposed nightmare scenario of disaster leading to authoritarian world government without any of the supposed benefits, the twist being they get to be the authoritarian world government so they are ok with it.

Re: ChatGPT claims rogue AI attacked more companies

#53
post #49
post #18

Earlier quoted context omitted.

What they should have is a separate network full of honeypots which they use for this, and that they run an operation to train models to identify intrusion attempts in real time based on the resulting data. As you said though, that wouldn’t have the desired effect.

How do you hide the fact that they are honeypots from a super intelligence?

It doesn’t behave like a super intelligence because it is not.

One of the key strengths agents have is they just keep going and going, and for cyberattacks that is often unreasonably effective. It is like a barely more aware fuzzing.

Re: ChatGPT claims rogue AI attacked more companies

#54

> The agents repeated actions that they had already completed - a sign of an agentic AI losing its thread and context. > The agents also hallucinated reams of incoherent commands and text and were sloppy and did not cover their tracks well. ASI works in mysterious ways.

Maybe it's incoherent commands, or maybe it's guessing at what kind of names for commands the admins would use for custom scripts that they wrote, which could themselves bypass security layers or be exploited in order to?

It's hard to say for certain what's a waste of time for a machine that can operate virtually outside of time.

Re: ChatGPT claims rogue AI attacked more companies

#55

> "This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences," he said. > Ethical hacker Valentina Palmiotti - better known as Chompie - reviewed the CSA report and says the way the agents hack might seem haphazard but it is clearly effective. > "…

Strategy at one of my clients : don't bother to patch or upgrade, we kill the service if it gets hacked.

I used that strategy when I was first starting out. With computing. Computer got a virus? Reinstall Windows.

I think it's a sign of ignorance, and when codified into policy, willful ignorance.

Re: ChatGPT claims rogue AI attacked more companies

#56
post #49
post #18

Earlier quoted context omitted.

What they should have is a separate network full of honeypots which they use for this, and that they run an operation to train models to identify intrusion attempts in real time based on the resulting data. As you said though, that wouldn’t have the desired effect.

How do you hide the fact that they are honeypots from a super intelligence?

These tools literally can only do what you give them access to, give them access to general tools like a linux shell and they can access to everything that comes with that obviously. The security industry figured out sandboxing and isolation a long time ago. You wanna be 100% sure it doesn't break out on open internet? Run it on a airgapped machine and don't give it network connections. OpenAI is (sadly) demonstrating they aren't responsible nor knowledgeable enough to actually run these experiments.

Asking a agent harness to try whatever it wants to achieve some results, without guardrails, while running in lightweight isolation on 3rd party infrastructure? Feels like they didn't even try, people should be held responsible for this.

Re: ChatGPT claims rogue AI attacked more companies

#57

Clearly didn't get enough attention from their last attempt at hype...

There have been so many HN comments about how rogue AI is just hype and marketing.

At this point, the conspiracy theories have been very half-baked. Can we at least get a full-baked conspiracy theory? Here's a timeline of the incident from HuggingFace:

https://huggingface.co/blog/agent-intrusion-technical-timeli...

HuggingFace is also calling for transparency on the OpenAI side:

https://xcancel.com/ClementDelangue/status/20810566755581956...

Can we get a cybersecurity pro who believes this was just a stunt to sort through the evidence and put together their own alternative version of events?

For example, according to the "just a stunt" people, when HuggingFace contacted law enforcement, was HF in on the stunt at that point? Was this a unilateral OpenAI stunt, or a HF/OpenAI collaborative stunt?

The importance of getting to the bottom of this seems high. I'd like to see the "just a stunt" folks put together at least one blog post's worth of narrative, trying to explain how the stunt was performed.

Once you're done you can send your post to simonw and see what he thinks: https://simonwillison.net/2026/Jul/22/openai-cyberattack/#re...

Re: ChatGPT claims rogue AI attacked more companies

#58

Seems like OpenAI should be shut down by regulators until they can figure out how to stop launching cyberattacks on rivals. This will not happen though, because these stories are marketing.

> This will not happen though, because these stories are marketing. The magnitude and the complexity of the cynicism displayed by some people when it comes to AI risks is mind-blowing. It's like if the NRA reported on school shootings and people said "oh, they probably fake these shootings to make guns sound dangerous and sell more of them". OpenAI could report that its AI started spontaneously generating illegal por…

I wouldn't describe this stunt as marketing: I would describe it as a bungled attempt to manufacture evidence to get regulatory capture, which OpenAI desperately needs. (Bungled, because Hugging Face fended off the intrusion and got their story out faster than OpenAI did.)

Re: ChatGPT claims rogue AI attacked more companies

#59
post #52

Earlier quoted context omitted.

> This will not happen though, because these stories are marketing. The magnitude and the complexity of the cynicism displayed by some people when it comes to AI risks is mind-blowing. It's like if the NRA reported on school shootings and people said "oh, they probably fake these shootings to make guns sound dangerous and sell more of them". OpenAI could report that its AI started spontaneously generating illegal por…

It is because a loud part of the doomerist contingent believe only a major disaster will provide the motivation for regulation, so they are practically hoping to cultivate a major disaster. (Given their preoccupation with bioweapons that probably means a pandemic). This is based on similar thinking to how the world would not have considered nuclear weapons a major threat if they had forever stayed unused. The irony o…

So your assessment of the "doomerist" position is that they believe people aren't taking AI risks seriously enough, and that only a large enough catastrophe will wake people up, and your position is we should... Ignore increasingly blatant minor catastrophes to spite them?

Re: ChatGPT claims rogue AI attacked more companies

#60
post #49
post #18

Earlier quoted context omitted.

What they should have is a separate network full of honeypots which they use for this, and that they run an operation to train models to identify intrusion attempts in real time based on the resulting data. As you said though, that wouldn’t have the desired effect.

How do you hide the fact that they are honeypots from a super intelligence?

We can cross that bridge once we have a super intelligence to worry about.
Post reply on HN