Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

61–70 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#61
post #45
post #23

Earlier quoted context omitted.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

Whoever prompted the agent, whoever supplied the means, whoever knew but didn't say anything.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#62
post #29

Earlier quoted context omitted.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.

Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve.

I, too, have no idea about legal matters.

But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.

I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#63
post #22

Earlier quoted context omitted.

Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.

Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them

Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#65
post #63
post #22

Earlier quoted context omitted.

Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them

Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.

And which of these neutral countries have the capacity to serve them and the lack of awareness that hosting an offensive Russian agent swarm would bring hell back to their doorstep? Best they can do right now is rented botnets

Re: OpenAI bots knew about the RubyGems caching vulnerability

#66
post #45
post #23

Earlier quoted context omitted.

Both. This should result in criminal charges.

Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?

There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk".

https://www.law.cornell.edu/wex/reckless

Re: OpenAI bots knew about the RubyGems caching vulnerability

#67

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title.

I'm going to assume that this will never happen

Re: OpenAI bots knew about the RubyGems caching vulnerability

#68
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

I think it can simultaneously be the case that OpenAI was grossly negligent in directly causing this AND that the AI’s ‘went rogue’ in that they are displaying behavior which is misaligned with OpenAI and humanity generally. The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them. AI is starting to feel like that lin…

Doesn't rogue in this context imply "outside of set limitations"? And then not "failed to properly instruct"? The same applies to humans when given bad instructions.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#69
post #38
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet

I think this fails a lot of logical tests, it should be apparent in day to day life.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#70
post #6

Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

> How are we not seeing insane attacks on Ukraine via Agents?

You live on the wrong side of the fence to be able to read that kind of news.

Did you really believe you had access to an unmanipulated news stream in a time of war?

LOL.

Post reply on HN