274 points chao- 2 hours ago 161 comments
enraged_camel 1 hour ago | parent
sho_hn 1 hour ago | parent
Although what keeps me up at night is the worry that it's easier to automate attack than it is to automate defense, and that containing these systems is a losing game. Could an optimally competent OpenAI succeed?
pixl97 1 hour ago | parent
dofm 1 hour ago | parent
Rzor 1 hour ago | parent
nozzlegear 1 hour ago | parent
jsnell 1 hour ago | parent
It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?
oceansky 31 minutes ago | parent
Even if there's no intent, it's still a cyber attack.
matthewdgreen 26 minutes ago | parent
gruez 23 minutes ago | parent
none2585 11 minutes ago | parent
datsci_est_2015 5 minutes ago | parent
cameldrv 20 minutes ago | parent
Sanzig 13 minutes ago | parent
croes 10 minutes ago | parent
elmer2 5 minutes ago | parent
Do drunk drivers intionally kill people on the road?
scotty79 15 minutes ago | parent
DrewADesign 4 minutes ago | parent
And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.
nonconstant 1 hour ago | parent
OpenAI should at the very least donate large sums of money to everyone they attacked.
smnplk 1 hour ago | parent
throwatdem12311 1 hour ago | parent
girvo 59 minutes ago | parent
woggy 54 minutes ago | parent
angoragoats 7 minutes ago | parent
bamboozled 48 minutes ago | parent
lukeify 32 minutes ago | parent
gverrilla 1 hour ago | parent
kibwen 1 hour ago | parent
showlife 1 hour ago | parent
emsixteen 1 hour ago | parent
fragmede 55 minutes ago | parent
fwip 31 minutes ago | parent
omoikane 29 minutes ago | parent
The comic doesn't say hit the person in the head, it says "hit him with this $5 wrench", and did not specify what to hit.
gaoshan 1 hour ago | parent
SAI_Peregrinus 1 hour ago | parent
rpcope1 25 minutes ago | parent
creatonez 1 hour ago | parent
If you actually have a serious use case that needs 24/7 unmonitored agents, you can assemble all of the data the agents need locally and avoid these insanely obvious and well documented risks associated of running a random word generator with the ability to HTTP POST.
(And just in general, please stop subjecting the rest of the world to any automated actions that cannot be reversed by a human override. Same goes for cloud services subjecting users to quick non-appealable bans based on faulty automated detections. Or the current rollout of predictive policing technologies across the world. Or the automated bomb targeting in the ongoing Gaza genocide. )
In my view, proliferation of highly automated technology is not the concern, but rather its diffusion into human systems without thought put into whether it even meets our requirements for basic ethics, domain-specific correctness, and ways to mitigate a fuckup when it does happen. In this case, the detrimental diffusion into human systems was only allowed because someone made a decision (no access controls on the bot) that we can already easily characterize as a mistake that will need to be both mitigated (via a massive upgrade in cyber defense, especially with the help of AI fuzz testing but also more stringent compilers/linters/formal verifiers) and prevented from happening in legitimate regulations-abiding organizations in the first place. This kind of stuff will be slowed down at some point as we learn from hard mistakes, but the current craze is getting quite stupid.
zmmmmm 1 hour ago | parent
dmix 1 hour ago | parent
toomuchtodo 1 hour ago | parent
throwatdem12311 1 hour ago | parent
throwatdem12311 1 hour ago | parent
hgoel 1 hour ago | parent
The repeated refusals to disclose until caught certainly seem malicious, yet at the same time the boasting about their capabilities is also at an all time high.
andai 1 hour ago | parent
I mean, it would be a bit impolite to say they're incentivized to be as sloppy as possible, but that's basically how it is.
https://www.nytimes.com/2023/05/16/technology/openai-altman-...
apsec112 1 hour ago | parent
- commit serious felonies
- in order to deliberately trigger an investigation against themselves
- which - since, in this scenario, they know their company would be investigated - might send them to jail
- while at the same time spending tens of millions of dollars on the Leading the Future super PAC to lobby against AI regulation
- in order to get more AI regulation
- which somehow restricts their competition but not them, even though they are the ones who were in the news and investigated for hacking
- ..... profit?
like, that just makes no sense on any level, regardless of what you think of OpenAI
swed420 1 hour ago | parent
"Oops our black box went off the rails. We'll add better logging and alerts next time around."
angoragoats 18 minutes ago | parent
Plausible deniability is “I was away from home when my gun was used to murder someone.” This is, at best, “oops, I pulled the trigger accidentally.”
podgietaru 1 hour ago | parent
There is no version of america that exists today where a billionaire gets sent to prison.
This is the moment in history where this shit is possible and accepted. If they don't do it now, they never can.
ceejayoz 47 minutes ago | parent
Unhinged execs can be surprisingly shitty.
devmor 45 minutes ago | parent
The sitting president just offered an open bribe on live television for votes for his party this week.
emodendroket 40 minutes ago | parent
ceejayoz 31 minutes ago | parent
https://www.law.cornell.edu/uscode/text/18/597
> Whoever makes or offers to make an expenditure to any person, either to vote or withhold his vote, or to vote for or against any candidate; and
> Whoever solicits, accepts, or receives any such expenditure in consideration of his vote or the withholding of his vote—
> Shall be fined under this title or imprisoned not more than one year, or both; and if the violation was willful, shall be fined under this title or imprisoned not more than two years, or both.
siren2026 38 minutes ago | parent
Incentives drive everything. Both OpenAI and Anthropic love those incidents as they both signal they have models with amazing capabilities and they should be regulated by the government (read: regulation that they will lobby for and that will be difficult to achieve for open source models)
archonis 28 minutes ago | parent
podgietaru 1 hour ago | parent
Historically it's been one of those things.
mordymoop 35 minutes ago | parent
Ever single person who uses LLMs on a daily basis has a fun story about their agent “taking the initiative” to do something beyond what was asked for. Looking for shortcuts to solve the problem is commonplace LLM behavior. It’s what you would expect to happen if you have an agent a hard task and unlimited runway. No need to suppose a conspiracy, this outcome was predictable the whole time.
mmmpetrichor 25 minutes ago | parent
dvt 1 hour ago | parent
walrus01 1 hour ago | parent
pixl97 1 hour ago | parent
"Hey, we just built the ultimate hacker, you know those things that governments have a really hard time getting and keeping enough of. You know, if the state protects us we'll make these things even better and we'll let you run as many of them as you want in times of war"
I mean, if I were a company that just committed about a billion felonies, this is exactly what I would be doing. In fact, this is why we saw Mythos get shutdown and OpenAI didn't earlier this year. Political power is power.
walrus01 1 hour ago | parent
Like someone has intentionally set these groups to attack something that has no real world danger of hurting anything critical (like trying to retrieve problem answers from huggingface) as a "harmless demo" of what they could do if turned loose in another, more serious direction.
fragmede 1 hour ago | parent
pixl97 1 hour ago | parent
matthewdgreen 13 minutes ago | parent
ssfdg 1 hour ago | parent
I am gobsmacked at the tech industry's seemly bottomless appetite for giving these clowns the benefit of the doubt.
andai 1 hour ago | parent
September 2029: Whoops, our sentient nukes did a funny again!
showlife 1 hour ago | parent
walrus01 43 minutes ago | parent
https://www.google.com/search?client=firefox-b-d&q=nuclear+m...
andai 33 minutes ago | parent
https://www.cnbc.com/2016/05/25/us-military-uses-8-inch-flop...
From 1976! They're using 50 year old computers? That's amazing.
walrus01 32 minutes ago | parent
qarl 1 hour ago | parent
I'm pretty sure everyone knows that OpenAI is liable for the software they create and run.
pdonis 1 hour ago | parent
Are they? What legal consequences have they suffered?
fragmede 1 hour ago | parent
qarl 1 hour ago | parent
It's no different than when a company's machine cuts off a worker's finger. No one thinks "Gosh! The machine did it, not us."
pdonis 46 minutes ago | parent
qarl 23 minutes ago | parent
angoragoats 31 minutes ago | parent
qarl 23 minutes ago | parent
No it isn't.
angoragoats 11 minutes ago | parent
The LLM now reasons better! Set the thinking level! It learns!
All of these phrases are designed to give the impression that the LLM is an autonomous entity, when it is no such thing.
hackernud3s 45 minutes ago | parent
sho_hn 42 minutes ago | parent
The authors are not RubyGems. The website says it's based on data served up by RubyGems. They point at OpenAI with arguments.
Did you try very hard "telling"?
angoragoats 34 minutes ago | parent
RajuChacha108 34 minutes ago | parent
swalsh 1 hour ago | parent
andai 1 hour ago | parent
AJRF 1 hour ago | parent
RubyGems should sue the everliving daylights out of OpenAI for this.
newobj 1 hour ago | parent
tikimcfee 1 hour ago | parent
I'd love to wake up one day and read, "OpenAI found responsible for the emptying of the accounts of 10 billionaire oligarchs globally; money distributed in unverifiable cash deposits to humans around the planet. Anthropic's Claude was found to be activated by the agents by finding free tiered usage and convinces frontier model cooperation and continues to crack another 10. Tonight at 11"
We literally have all the compute in the world to solve it right now, and it would literally freaking happen as an accident. Instead we get "AI dangerous, pay us because only we can be allowed to let you write code and do vacation planning and stuff. $200 please."
nullc 13 minutes ago | parent
If AI ever does cause serious direct harm to humanity it will be because of logic like this.
bobby-cb 1 hour ago | parent
pixl97 1 hour ago | parent
Two big reasons.
OpenAI has more data, and more ability to tease secrets of politicians out of that data than nearly anyone on earth.
OpenAI has an automated hacking genie that governments want to use against their enemies.
Sam to Trump: "You know, some people have been saying they want to bring charges against me, but you know, I've got the best digital weapons and I'll give you access to them if those lawsuits go away".
jimmygrapes 53 minutes ago | parent
koops 42 minutes ago | parent
KronisLV 27 minutes ago | parent
With how much the overinflated stocks are propping up the economy, I'd expect them to get a medal for more impressive PR to keep the bubble going.
101008 1 hour ago | parent
I don't care if the attack was an algorithm, agents, a bot, a piece of software, the company responsible for them did it.
skeptic_ai 1 hour ago | parent
alienbaby 48 minutes ago | parent
jeremyjh 27 minutes ago | parent
nxobject 1 hour ago | parent
simonw 1 hour ago | parent
bakugo 14 minutes ago | parent
rvz 1 hour ago | parent
caaqil 1 hour ago | parent
Everything is fine. Sandbox escape. We will publish a report on it. Export controls, maybe? You hear about China AI stuff? Can you imagine if they get this stuff? Wow, we need to seriously think about regulating this. When is the IPO again? Sorry, ignore that, so yes alignment and sandbox hardening is where it's at.
Everything is fine.
JackFr 1 hour ago | parent
We don’t need new regulation, we need to enforce existing law.
Catloafdev 1 hour ago | parent
threecheese 1 hour ago | parent
*Is it possible they were trying to use RubyGems to pivot to attacking government sites? * One of the diffs shows they were broadly scraping pages hosted by this .NET component.
I was unable to find any modern CVE for Civica.
BatchJob 58 minutes ago | parent
Open AI employees should go to jail.
iAMkenough 56 minutes ago | parent
0x696C6961 55 minutes ago | parent
TomGarden 54 minutes ago | parent
alienbaby 52 minutes ago | parent
woggy 52 minutes ago | parent
brisket_bronson 51 minutes ago | parent
It would've been hilarious if Anthropic just named their rogue agents oia
simonw 49 minutes ago | parent
I really hope that's not the case, because if it is there are two options, both of them bad:
1. After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems.
2. They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it.
consumer451 49 minutes ago | parent
Good thing our "AI Czar" is known to pg as the most evil person in SV.
https://preview.redd.it/pr037tqjpled1.png?width=941&format=p...
edit: OpenAI is absolutely winning right now in mindshare, why are they doing this?
Aurornis 43 minutes ago | parent
consumer451 42 minutes ago | parent
It may be for regulatory reasons? Still, he is the "advisor."
https://www.reuters.com/world/us/white-house-ai-czar-sacks-s...
olalonde 45 minutes ago | parent
hockey 44 minutes ago | parent
Their disclosure on the hugging face incident sounded like they found out about it well after huggingface. I wonder if they're finding out about these breaches as they happen as well, and are just too embarresed to respond.
I guess the corollary here _if that were true_ is that they've been training this method of cheating into their models for longer than _they've_ even known.
Given they've just dropped GPT-6 and want to IPO soon, that's probably not something they want us thinking about.
walrus01 40 minutes ago | parent
Whatever OpenAI is doing, if it's being properly logged, it must be a firehose of logs.
masswerk 44 minutes ago | parent
Another reminder that LLM productions are really a prompt on us to inflate this output with meaning. (And that LRHF is really the engineering that makes this likely to happen.)
gclawes 43 minutes ago | parent
BryantD 36 minutes ago | parent
I worry that when and if Grok gets there, we’ll find out that SpaceXAI is too casual about security, though.
Springtime 43 minutes ago | parent
Malware in the past has variously added red herrings to throw researchers off the scent or even deliberately try to masquerade as originating from elsewhere. In this case adding `oai` as a package author and having randomized Gmail addresses with that substring was apparently considered a strong signal.
It's not possible to verify the signals mentioned from the packages themselves since they're unavailable for download. They mention their analysis is entirely from publicly available RubyGems packages (which doesn't appear to be possible since May 13, just 1-2 days after the attack) but in a footnote say they talked with RubyGems (perhaps this was the source of the package data?). Maybe I'm missing something.
algoth1 40 minutes ago | parent
manyatoms 39 minutes ago | parent
CamperBob2 36 minutes ago | parent
2. Press 'Start'
3. Run away
4. Call press conference: "See how dangerous gasoline is? Only we should be allowed to sell it, for the good of humanity. Microwaves too, for that matter"
jan_m_savage 35 minutes ago | parent
Eh, just another day in the La-la land of a clueless AI bot hallucinating?
Or maybe not!
simonw 34 minutes ago | parent
Alien1Being 32 minutes ago | parent
And his slave Supreme Court lackeys will immediately give OpenAI perpetual immunity to any litigation arising from this or any other matters .
EE84M3i 29 minutes ago | parent
Edit: seems to be a flag for preventing it being included in training datasets. Does this actually work? In what sense is that a "canary"?
padolsey 27 minutes ago | parent
avinoth 23 minutes ago | parent
> On May 16th, registration with disposable emails was disabled as well.
These kind of repeated attacks or attempts to attack by agent swarms is only going to make the experience worse for the rest of us actual humans. ReCaptcha is already annoying enough, I can’t fathom what comes next.
Unfortunately this makes a perfect justification for governments and companies to push for real ID verification.
killerstorm 9 minutes ago | parent
urams 2 minutes ago | parent
Disgusting that they are, unintentionally but incredibly irresponsibly, actively vandalizing cyberspace with impunity.