Remix.run Logo
ArcHound an hour ago

Someone should still be accountable, the same way you're responsible and accountable for what your dog or car does.

solenoid0937 an hour ago | parent [-]

If we are going to start punishing companies for security negligence, there are WAY worse cases than these models breaking out that have nothing to do with AI. This is bikeshedding at its best.

Also people would just stop disclosing bad things. You already see this in the airline industry where pilots don't report mental illness because of the retributive nature of the punishment.

kdheiwns an hour ago | parent | next [-]

"But another company did some different bad thing" is the excuse employees of bad companies all go to immediately. Just because another person did something bad and hasn't been adequately punished doesn't mean you should get a pass. If one person gets away with going 50 MPH over the speed limit, it doesn't mean every person should be allowed to do it. Everyone should be punished, but there are always instances of some cases falling through the cracks. It doesn't mean the crack should be widened so all cases fall through.

solenoid0937 an hour ago | parent [-]

It's more like there are many people going at 120 MPH in a 50 MPH zone, that have ran over real people, but you punish the guy that self-reported doing 60 MPH because he drives a shiny, interesting Lamborghini and not a Prius like the others.

Anyone outraged about these AI incidents is not thinking rationally if they were not much more outraged about everyday companies leaking millions of people's PII, SSNs, which has done actual lasting damage and has been used by actually malicious actors.

People are just directing their anger at AI companies through this pretext. We all know open source models will democratize this ability anyways, so strap in for the ride.

bluGill 24 minutes ago | parent | next [-]

Maybe that is the prosecutions motive. However I want all those going 120 punished even if they drive a Prius. That is the problem is not that they are punishing the Lamborghini driver, but that they are not punishing the other drivers, and it doesn't at all change that the Lammboghini driver needs to be punished.

kdheiwns an hour ago | parent | prev [-]

Turning oneself in doesn't absolve one of a crime. Never did and never will. Shouldn't, either.

And companies always try to pretend someone out there is worse and garner fake sympathy. OpenAI blew up the memory market and made tech inaccessible. The downstream effects of that are immeasurably massive and will have real consequences. It could even result in medical devices becoming too expensive for people. I don't care about my SSN being leaked. You can find it just by knowing where I'm born and every job I've applied to knows it already. But inability to afford technology affects everyone around me. The SSN red herring thing is not an organic argument.

solenoid0937 40 minutes ago | parent [-]

> OpenAI blew up the memory market and made tech inaccessible

This is not a "crime", has nothing to do with this incident, and simply confirms what I am saying about people using these events as an outlet for their anger at AI companies, as opposed to any rational reasoning about industrywide security negligence.

I could almost respect a viewpoint that says "we should punish companies for security negligence, starting with the negligence that has caused the most egregious harms." That is an internally consistent and rational viewpoint.

I cannot respect a viewpoint that's "I don't like the AI companies, so let me use this hammer I found on them specifically." It's purely emotional.

bryanlarsen 9 minutes ago | parent | prev | next [-]

A quick Google finds several people that have been successfully prosecuted for security negligence, like Joe Sullivan of Uber.

Most haven't seen criminal prosecution, but many do see civil prosecution and even more common is some sort of deal with prosecutors to avoid both.

bluGill 26 minutes ago | parent | prev | next [-]

> If we are going to start punishing companies for security negligence, there are WAY worse cases

Perhaps, but you have to start someplace.

I think we do need to punish companies for security negligence. However the details matter (nobody can be perfect: you need to do something reasonable to stop the known attacks, but I have to agree to allow that you can't be perfect and so someone will get compromised). I'm not sure how to get the details right to cover everything without going too far. If we handwave that away though, eventually somebody will need to get punished for something that someone else got away with not long before.

reddozen an hour ago | parent | prev | next [-]

> there are WAY worse cases than these models breaking out that have nothing to do with AI.

And? Welcome to the big boy world. This isn't playground rules where you can complain "But Bobby was doing bad things too why isn't he in trouble?"

But you know this already. You're just pretending not to. Why?

solenoid0937 42 minutes ago | parent [-]

Addressed in my other replies

ArcHound an hour ago | parent | prev [-]

Please tell me about such cases, genuinely interested.

I still think we should take the opportunity to discuss this case in particular.

solenoid0937 an hour ago | parent [-]

There have been data breaches where the SSNs and PII of millions of people have been exposed. That is far more harmful in real terms than any of the OpenAI/Anthropic mess.

reddozen an hour ago | parent | next [-]

So OP asked you for one example and you can't give one? You just fall back to the generic statement slop, you must be a bot right?

Again, what's ONE (1) real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted.

27 minutes ago | parent [-]
[deleted]
ilogik an hour ago | parent | prev [-]

An in the EU at least there are laws that fine companies that don't take security seriously.

solenoid0937 an hour ago | parent [-]

Even the EU bikesheds and focuses on shiny targets to land political wins with their constituents.