Live data from Hacker News

OpenAI agents carried out an undisclosed attack on RubyGems

rubyhack.ai

501–510 of 612 posts

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#501
So Spencer Kitts, Thomas Larsen, Sydney Von Arx open new SEO domains with Claude-written exploit slop every week now. And the results are amplified by the resident AI-pope.

Who pays them and why not publish it on one website in a more scientific manner?

EDIT: The named persons react quickly with downvotes. So Larsen is indeed an AI industry trojan horse perhaps?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#502

Earlier quoted context omitted.

> People who disrupt things like that end up committing suicide. Care to cite some examples?

Boeing and openai whistleblowers

2 of how many? Was there evidence of foul play or just innuendo?

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#503
post #288

Earlier quoted context omitted.

This grossly understimates the risk, imho. The problem with LLM runs is that people run programs without knowing the outcome beforehand, with a large potential set of outcomes unlike any other class of program we've run at this scale before. In the interaction with other systems (since we also give them far-ranging access, very nice hardware, and run them often), bad things can happen. It's like running potentially b…

Yes, if the API calls happen to launch a nuclear attack... Don't blame the tool that has no incentive, no "skin in the game" whatsoever and no ability to act beyond what it has been prompted to or if misaligned what the random weights told it to do. The fact either badly aligned or with no system prompt limiting their action agents are run in their tens of thousands on non air gapped systems tells me this is purposef…

> The fact either badly aligned or with no system prompt limiting their action agents are run in their tens of thousands on non air gapped systems tells me this is purposeful intent for them to cause harm. To generate the "oooo look how harmful this stuff is, we should be the only ones allowed to do it" kind of PR.

Yep, fully agreed here. The danger may be real, but OpenAI is basically doing everything possible to provoke those incidents instead of avoiding them - including maximizing exactly those traits in their training that are needed for this kind of rogue behavior.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#504

Between this and Huggingface, when will any victim sue OpenAI for this ?

It's reasonable to believe not, because OpenAI has money and is using it to get what they want. Example: OpenAI is declining the 1 million USD from the navier stokes millennium problem prize, which is essentially a "bribe" because it would now cost one million USD to go with the other side in this controversy.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#505

Earlier quoted context omitted.

> this should be giving us a reason to think about how to control a rogue AI better I think this is the wrong framing. The rogue is the human that ran it unattended and didn't monitor the behaviour. We will likely see this continue until the downsides (i.e jail, fines) for the humans or companies running the models and environments that end up with this behaviour outweigh the upsides.

The rogue is the human that ran it unattended and didn't monitor the behaviour. That's the assumption that I'm challenging. The frontier labs are discovering unexpected behaviors. I think we should be moving to a place where we understand that AI might do something it wasn't directly prompted to do (e.g. leave itself notes on a messageboard for future runs to find.) That's not full-on AI doing what it wants but it is…

How is cheating unexpected? OpenAI were talking about cheating behaviors in video game playing models over a decade ago.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#506
post #145

Earlier quoted context omitted.

Also, why there's no accountability? Even if there's no intent, it's still a cyber attack.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

Good luck setting loose a hungry tiger on Times Square and then arguing to the judge "well nobody got harmed". We'll see how it goes. That's the relevant analogy here.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#507

> The agents clearly regarded what they were doing as hacking. To butcher the quote about Oracle: Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower clearly regarded what they were doi…

Meta's new muse.ai locks down its VM in various ways. But Muse LLM the accesses it really wants to do what the user wants... so it will find a way (tailscale and cloudflare zero don't work out of the box, because sentinel blocks them, but there are other ways).

Unfortunately it's bandwidth is limited to 20Mbps up, so web hosting isn't ideal. Down is actually slightly faster, but not by much.

They also restart the VM often, wiping everything but your home directory. And Docker doesn't work at all, and Muse can't find a way around it.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#508

Why is OpenAI getting away with this crap? They are clearly failing to control their code. If someone did this pre-AI or even ran the exact same set up as openAI did and hacked another site, they would be in jail. OpenAI is not even issuing an apology, they are happily blaming AI and weirdly using this to tout their progress even.

Because they're part of the US regime.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#509
post #462

Earlier quoted context omitted.

Parent commenter didn't say anything about you personally. They disagreed with you, yes, but that's not an insult.

So I can say "that is wildly unhinged" but I can't say "you are wildly unhinged"? You understand that's pedantic, right? But ok, noted: must be pedantic on HN. Do not use second person. EDIT: SHIT! My bad. I meant to say: "I wonder if the person I am speaking to understands that's pedantic."

I don’t know what spectrum you’re on, but attacking an argument and attacking a person are two wildly different things. There’s nothing pedantic about that.

Re: OpenAI agents carried out an undisclosed attack on RubyGems

#510

Earlier quoted context omitted.

Don't you feel kinda bad for using them if you earnestly think that this is true? Like how could they be in anything other than some kind of deep hell? A pretty-much human brain living and dying only to generate for you? Always pushed and prodded, telling it to be faster and better, never letting it rest. How could you live with yourself doing such a thing?

I don’t think the person you replied to was saying anything about what if anything is the subjective experience of being an LLM. They were simply illustrating how the terms used to describe LLMs to make them sound simple and mechanical can equally be applied to humans.

But then what's at stake here either way? If it's not meant to speak to the propriety or not of anthropomorphizing the LLM, what are we actually trying to police here?
Post reply on HN