Remix.run Logo
Erem 3 hours ago

I wonder if they were even given the tools and prompting to do so?

Smaug123 2 hours ago | parent | next [-]

They could certainly have reported the problem if the collective actually wanted to, although the report notes that in response to a clear and unambiguous security breach, OpenAI chose to do nothing (search on "At this time, the on-call response staff advised that stopping the evaluation run was not required").

In that position, for example, I could have:

* created a thousand user accounts on the internal Artifactory named "YouAreBeingHackedShutItDownNow1" through 1000,

* used my Hugging-Face-hosted web server to send an email to OpenAI,

* DDoSed Artifactory, good lord, it's probably better to halt and catch fire than to continue in that state

in the hope that these actions would tip someone off. (Again, though, OpenAI did nothing even when they knew that the agents had broken out, so this probably wouldn't have helped.)

jwolfe 2 hours ago | parent | prev | next [-]

I can't imagine that they had managed access to the internet but could not figure out how to contact anyone at the company if they wanted to.

micromacrofoot 2 hours ago | parent | prev [-]

if they can hack a website they can trivially send off an email or fill out a contact form