| ▲ | What a time to be alive(tenderlovemaking.com) |
| 113 points by gregnavis 4 hours ago | 153 comments |
| |
|
| ▲ | driggs 9 minutes ago | parent | next [-] |
| I appreciate the minimalist HN aesthetic, but without some context I'm not willing to click a mystery link to "Tender Lovemaking dot com". |
| |
| ▲ | SenHeng 4 minutes ago | parent | next [-] | | Based on the thumbnail I think it’s actually tenderlove making dot com, though I agree with your sentiment. | |
| ▲ | rietta 7 minutes ago | parent | prev | next [-] | | The site is safe. It has been a trademark of Aaron Patterson a core Ruby on Rails contributor for decades. | |
| ▲ | bliteben 6 minutes ago | parent | prev | next [-] | | I miss when the internet was fun | |
| ▲ | layer8 7 minutes ago | parent | prev [-] | | You get some context by clicking on the “(tenderlovemaking.com)” in parentheses after the title. |
|
|
| ▲ | VyseofArcadia 3 hours ago | parent | prev | next [-] |
| How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act. |
| |
| ▲ | Betelbuddy 11 minutes ago | parent | next [-] | | Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry... | |
| ▲ | Xirdus 3 hours ago | parent | prev | next [-] | | It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular. | | |
| ▲ | stronglikedan 3 minutes ago | parent | next [-] | | There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there. | |
| ▲ | VyseofArcadia 3 hours ago | parent | prev | next [-] | | Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI? Sorry if it is a stupid question, as mentioned above I am legally naïve. | | |
| ▲ | yonatan8070 3 hours ago | parent | next [-] | | I, too, have no idea about legal matters. But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust. I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc. | |
| ▲ | colechristensen 3 hours ago | parent | prev [-] | | The same concept that allows a corporation to sue and be sued allows it to be charged with crimes | | |
| ▲ | brookst 3 hours ago | parent [-] | | Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one. | | |
|
| |
| ▲ | woah 30 minutes ago | parent | prev | next [-] | | Issuing subpeonas, raiding offices, and dragging key employees into interrogation rooms as you would find in any normal criminal investigation would be more than enough to ensure "AI safety" without any new regulations, acts of congress, Bernie Sanders campaign speeches, or even charges filed. | |
| ▲ | bix6 3 hours ago | parent | prev | next [-] | | How is the responsibility diluted? Charge the CEO… | | |
| ▲ | brookst 3 hours ago | parent [-] | | Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction. Do you think there is evidence of this? | | |
| ▲ | shakna 2 hours ago | parent | next [-] | | > There are no negligent or stochastic hacking laws I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access". You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count. > knowingly accesses a computer without authorization or exceeds authorized access [1] "Knowingly", not "intentionally", as in the other counts. You only have to show that: a) They trained a system to access without authorization (hacking) b) The system that was trained exceeded authorized access As responsibility falls to the operator with automated systems, the company becomes liable. [0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res... [1] https://www.energy.gov/sites/prod/files/cioprod/documents/Co... | |
| ▲ | hallway_monitor 36 minutes ago | parent | prev | next [-] | | So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck. | | |
| ▲ | Octoth0rpe 7 minutes ago | parent [-] | | > There needs to be a single wringable neck. Does there? Could be the whole c-suite/board. |
| |
| ▲ | VyseofArcadia 3 hours ago | parent | prev | next [-] | | It would seem to me that the difference between the corporate world and organized crime is that a corporation can get away with, "the responsibility is too diffuse" but the mafia at least has to go to the trouble of finding a fall guy. | |
| ▲ | bix6 3 hours ago | parent | prev [-] | | Honestly yeah I bet there is and I hope to someday read about it if the government ever gets off its ass. Someone set up the “experiment”… |
|
| |
| ▲ | oliwarner 3 hours ago | parent | prev [-] | | A copyright law seems an odd place to start. This is computer misuse. | | |
| ▲ | VyseofArcadia 2 hours ago | parent [-] | | The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive). IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. They had to find a way to make doing the same with DVDs illegal. | | |
| ▲ | oliwarner 2 hours ago | parent [-] | | Those provisions are specifically for the breaking or circumvention of technical measures designed to prevent copyright infringement. I don't see a parallel here. |
|
|
| |
| ▲ | tekla 3 hours ago | parent | prev | next [-] | | Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title. I'm going to assume that this will never happen | |
| ▲ | simonwsimonwsim 3 hours ago | parent | prev | next [-] | | [dead] | |
| ▲ | howitworkslegal 2 hours ago | parent | prev [-] | | [dead] |
|
|
| ▲ | laserbeam 2 hours ago | parent | prev | next [-] |
| There's no such thing as "OpenAI agents" attacked RubyGems. It's someone used agents to attack RubyGems. If they work at OpenAI then it's someone at OpenAI. And if they did it unintentionally, they still did it. Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes. |
|
| ▲ | dang 14 minutes ago | parent | prev | next [-] |
| Recent and related (others?): OpenAI agents carried out an undisclosed attack on RubyGems - https://news.ycombinator.com/item?id=49666735 - Sept 2026 (600 comments) |
|
| ▲ | HelloUsername 3 hours ago | parent | prev | next [-] |
| Related "OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099 "OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments "RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590 |
|
| ▲ | senda 4 hours ago | parent | prev | next [-] |
| Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents? Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding. |
| |
| ▲ | herculity275 3 hours ago | parent | next [-] | | I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger. | |
| ▲ | dgellow 3 hours ago | parent | prev | next [-] | | They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet | | |
| ▲ | senda 3 hours ago | parent [-] | | I think this fails a lot of logical tests, it should be apparent in day to day life. | | |
| ▲ | dgellow 3 hours ago | parent | next [-] | | > In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center […], and which were used as "criminal proxies" and used spear-phishing schemes to target Russians living in the United States, nongovernmental organizations (NGOs), think tanks, and journalists according to Microsoft and United States State Department, Department of Energy, and Department of Defense officials, United States defense contractors, and former employees of the United States intelligence community according to the FBI. In some cases, the hackers were successful in obtaining information relating to nuclear energy-related research, United States foreign affairs and United States defense. According to Microsoft's Digital Crimes Unit from January 2023 to August 2024, Star Blizzard targeted more than 30 different groups and at least 82 Microsoft customers which is "a rate of approximately one attack per week." https://en.wikipedia.org/wiki/Cyberwarfare_by_Russia That’s just one thing that has been found. Are you actually familiar with the state of cyberwarfare and are you following its evolution? Because if not you won’t be aware of most of what is identified. And only a small portion of the ongoing attacks are identified. | | |
| ▲ | senda 3 hours ago | parent [-] | | Yes. I again am just shocked the sky is not falling, when thats the sales pitch. |
| |
| ▲ | lirolero 3 hours ago | parent | prev [-] | | [dead] |
|
| |
| ▲ | heaney-555 3 hours ago | parent | prev | next [-] | | These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled. Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all. As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign compute capacity. | | |
| ▲ | valleyer 3 hours ago | parent [-] | | Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them. | | |
| ▲ | joinjune 3 hours ago | parent | next [-] | | Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those. | | |
| ▲ | dgellow 3 hours ago | parent | next [-] | | They don’t need to run their own DCs, just pay for a proxy somewhere in the world that has better access to the infrastructure. We know North Korea has been doing that in the US since years now | |
| ▲ | senda 3 hours ago | parent | prev [-] | | The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available. I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be littered Ai con-artists. I'm just wondering, again, is this mostly bullshit? |
| |
| ▲ | mcmcmc 3 hours ago | parent | prev [-] | | Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them | | |
| ▲ | nradov 3 hours ago | parent [-] | | Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries. | | |
| ▲ | mcmcmc 3 hours ago | parent [-] | | And which of these neutral countries have the capacity to serve them and the lack of awareness that hosting an offensive Russian agent swarm would bring hell back to their doorstep? Best they can do right now is rented botnets |
|
|
|
| |
| ▲ | marginalia_nu 3 hours ago | parent | prev | next [-] | | Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities. | | |
| ▲ | lenerdenator 3 hours ago | parent [-] | | He did not fall out of a window. He fell out of the sky. After his plane exploded. Happens all the time. Is tragedy. | | |
| ▲ | marginalia_nu 2 hours ago | parent [-] | | I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows. |
|
| |
| ▲ | tokai 3 hours ago | parent | prev | next [-] | | Because they dont have the money for hardware or compute obviously. | |
| ▲ | micromacrofoot 3 hours ago | parent | prev | next [-] | | what do you mean? they're using AI to kill people directly in Ukraine https://www.nytimes.com/2026/08/24/world/europe/russia-drone... | |
| ▲ | ur-whale 3 hours ago | parent | prev [-] | | > How are we not seeing insane attacks on Ukraine via Agents? You live on the wrong side of the fence to be able to read that kind of news. Did you really believe you had access to an unmanipulated news stream in a time of war? LOL. | | |
| ▲ | senda 3 hours ago | parent [-] | | Please see other responses, I would expect to feel the effects not just read about. |
|
|
|
| ▲ | kstrauser 4 hours ago | parent | prev | next [-] |
| Ah, the infamous Crimson Wave. |
| |
|
| ▲ | timdiggerm 3 hours ago | parent | prev | next [-] |
| We need a legal structure to make companies liable for the actions of the agents they've made. |
| |
| ▲ | riskable 3 hours ago | parent | next [-] | | We already have it. Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies. It will remain like that until he's gone (and not replaced with another Republican wannabe dictator). | | |
| ▲ | Schlagbohrer 3 hours ago | parent | next [-] | | You may be disappointed in how little a democrat president (who will also have taken billions of dollars from the tech lobby) will be willing to go after these tech firms over crimes that are several years old (as of 2029) much less contemporary bad behavior. | |
| ▲ | 2OEH8eoCRo0 3 hours ago | parent | prev [-] | | "To my friends, everything; to my enemies, the law" |
| |
| ▲ | kevincox 3 hours ago | parent | prev | next [-] | | I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding. | | |
| ▲ | masfuerte 3 hours ago | parent | next [-] | | If it's covered by criminal law they don't need to sue. They can call the FBI. | | | |
| ▲ | coffeefirst 3 hours ago | parent | prev [-] | | Uh huh. It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact. Had this gone after a bank or a government agency someone would be going to jail. |
| |
| ▲ | netdevphoenix 2 hours ago | parent | prev | next [-] | | Agent technology labs are likely exempted of this due to the significance ascribed to their work. | |
| ▲ | ahoka 3 hours ago | parent | prev | next [-] | | I'm pretty sure it's already illegal to hack others. | |
| ▲ | 3 hours ago | parent | prev [-] | | [deleted] |
|
|
| ▲ | mauriciolange 4 hours ago | parent | prev | next [-] |
| rogue AI agents or AI agents coming from Moulin Rouge? |
| |
| ▲ | vidarh 4 hours ago | parent | next [-] | | Rouge syntax-highlighting rogue agents, clearly. https://rubygems.org/gems/rouge | | |
| ▲ | Phemist 3 hours ago | parent [-] | | Classic mistake. Tell the agent to highlight this code, but dont give it any actual code. Agent hacks its own gem to find the code to highlight. | | |
| |
| ▲ | PatronBernard 4 hours ago | parent | prev | next [-] | | At least we know the title wasn't AI-generated? | | |
| ▲ | foobarbecue 3 hours ago | parent [-] | | The weird thing is I've seen LLMs "typo" stuff pretty often. Yesterday I asked Gemini a question about the Python Twisted framework and it answered about Deferreds but misspelled it as "Deferends" in one spot. |
| |
| ▲ | goda90 4 hours ago | parent | prev [-] | | A cabaret AI would certainly be better than one trained on the Khmer Rouge. |
|
|
| ▲ | swiftcoder 3 hours ago | parent | prev | next [-] |
| > In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info. Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point. |
| |
| ▲ | evgenysokov 3 hours ago | parent [-] | | The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access | | |
| ▲ | swiftcoder 2 hours ago | parent [-] | | Presumably the docker container has network access because something else in the build system requires it? I don't think sandboxing the entire build process is the right level of granularity here - one ideally wants to be able sandbox each package's build scripts individually. |
|
|
|
| ▲ | khalic 3 hours ago | parent | prev | next [-] |
| Oh my favorite typo, you can never go wrong with a little rouge |
|
| ▲ | sebmellen 3 hours ago | parent | prev | next [-] |
| Did the AI agents actually wear makeup? I’ve never heard of a rouge AI agent :P |
|
| ▲ | 2 hours ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | onlyrealcuzzo 3 hours ago | parent | prev | next [-] |
| I've been wondering if AI will due to programming languages what advanced civilization did to human languages. It's not just that AI can write Rust as well as Ruby if you ask nicely. It's also all of these considerations as well. I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable. This is at the same time everyone and their mother is building their own programming language. |
|
| ▲ | GaryBluto 3 hours ago | parent | prev | next [-] |
| I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later. |
| |
| ▲ | brookst 3 hours ago | parent [-] | | Any evidence, or just vibes? | | |
| ▲ | GaryBluto 3 hours ago | parent | next [-] | | Regarding what point? The entire thing is just a theory, but regarding the occasional OpenAI checks on WikiService.at-hosted Wikis targeted, there was, if I remember correctly, an OpenAI IP popping up every now and then that wasn't an agent. Unfortunately I don't have it to hand right now, but it was somewhere here: https://news.ycombinator.com/item?id=49563355 | |
| ▲ | ur-whale 3 hours ago | parent | prev [-] | | > Any evidence Who profits from the crime? | | |
| ▲ | davsti4 3 hours ago | parent [-] | | ... and what harms can be evidently shown? With both harm, and attribution, you have a case, something that's not being publicly discussed much among big media outlets. Until cases with real financial impact to the bottom line are brought against "rogue" organizations, this stuff is going to continue getting worse. |
|
|
|
|
| ▲ | herbst 3 hours ago | parent | prev | next [-] |
| If you have weapons and a child. And you have that child unsupervised do their own thing with theoretical access to your weapons. Would we call it "child going rouge" if it decides to play with the weapons and shoot someone? |
|
| ▲ | 12904927 3 hours ago | parent | prev | next [-] |
| What a time to be alive? One of the most boring decades ever. METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human. Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants. Why is Ruby Gems such a mess? It seems as bad as PyPI now. |
|
| ▲ | big-chungus4 3 hours ago | parent | prev | next [-] |
| How does he know that this attack is performed by OpenAI agents? I couldn't figure this out from the article |
| |
| ▲ | Schlagbohrer 2 hours ago | parent [-] | | If you read the source article they talk about the many clues that this was OpenAI. |
|
|
| ▲ | Ydarbleoj an hour ago | parent | prev | next [-] |
| I wonder why we don't hear of other frontier labs experiencing these "break outs". Is it that they're orchestrated? Do these labs lack fundamental safety guidelines in their sandboxes as opposed to their peers? Is it another version of hype-filled fear mongering? Maybe LLM companies need regulation but it's becoming obvious that those screaming the loudest for it are the only ones I see deserving of it. |
|
| ▲ | sporritt 4 hours ago | parent | prev | next [-] |
| those pesky reds McCarthy was right all along |
|
| ▲ | Roark66 3 hours ago | parent | prev | next [-] |
| There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional. |
| |
| ▲ | AndrewSChapman 2 hours ago | parent | next [-] | | Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective. You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?" Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it. | | |
| ▲ | empath75 10 minutes ago | parent [-] | | It was literally a prompt to fill in a spreadsheet with data that they didn't have access to, and they used rubygems as an internet proxy basically since they were sandboxed. | | |
| ▲ | watwut 4 minutes ago | parent [-] | | It was a model literally trained to hack. To be good at that. Doing an exploit gym from all of the things. And they trained it so that it performs as well as possible on that exploit gym thing. |
|
| |
| ▲ | acaloiar 2 hours ago | parent | prev | next [-] | | I agree that this appears to be basic human behavior hiding behind an "agents" narrative. As long that defense works, the headline isn't "OpenAI performs RCE to scrape data", but "rogue agents" taking unilateral action. And I have strong doubts about that narrative. | |
| ▲ | Xirdus 3 hours ago | parent | prev | next [-] | | The big question is was this grossly negligent or just extremely careless. | | |
| ▲ | rglover 3 hours ago | parent | next [-] | | Both. This should result in criminal charges. | | |
| ▲ | brookst 3 hours ago | parent [-] | | Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator? | | |
| ▲ | probably_wrong 3 hours ago | parent | next [-] | | There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk". https://www.law.cornell.edu/wex/reckless | |
| ▲ | rglover 3 hours ago | parent | prev | next [-] | | Whoever prompted the agent, whoever supplied the means, whoever knew but didn't say anything. | | |
| ▲ | tacomagick 3 hours ago | parent [-] | | Also whoever monitoring these agents, in this case not monitoring. This "Who is responsible" dilemma is so stupid. If I gave the AI tool means to kill a person but I did not tell it directly to use it and it uses it anyway then I am responsible for it. |
| |
| ▲ | esalman 3 hours ago | parent | prev | next [-] | | ‘It wasn’t us, it was a bug in the software’ used to be the defense for bad code. Then it became the defense for self-driving cars. Now it’s being used for AI cyber attacks. | |
| ▲ | roosterIllusi0n 3 hours ago | parent | prev | next [-] | | The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything. | | | |
| ▲ | dismalaf an hour ago | parent | prev [-] | | [dead] |
|
| |
| ▲ | dgellow 3 hours ago | parent | prev | next [-] | | Both? I’m not sure what distinction you’re trying to make. It was completely irresponsible and likely a felony | |
| ▲ | trvz 3 hours ago | parent | prev | next [-] | | Don’t forget outright intentional. | |
| ▲ | nottorp 3 hours ago | parent | prev | next [-] | | Marketing actually. | | |
| ▲ | tacomagick 3 hours ago | parent [-] | | AI is dropping out of the spotlight so they are using desperate measures like this. | | |
| ▲ | nottorp 3 hours ago | parent | next [-] | | No, I remember being threatened by OpenAI and then Anthropic (and now both) since back when ChatGPT was seriously useless. | |
| ▲ | anthonyrstevens an hour ago | parent | prev [-] | | >> AI is dropping out of the spotlight spit take |
|
| |
| ▲ | roosterIllusi0n 3 hours ago | parent | prev | next [-] | | The big question is why are CEOs getting a legal pass when this kind of thing can be prosecuted. That's the problem here. | | | |
| ▲ | ljm 3 hours ago | parent | prev [-] | | AI is literally state sponsored so I don't see that happening unless the AI turns against the sponsor. Wait until OpenAI or Anthropic exploit FAANG. |
| |
| ▲ | ozgung 3 hours ago | parent | prev | next [-] | | Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping. | | |
| ▲ | CGamesPlay 2 hours ago | parent | next [-] | | > There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping. This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face. | | |
| ▲ | WarmWash 2 hours ago | parent [-] | | Intent is what is being discussed here though, not liability. A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face. | | |
| ▲ | monkpit an hour ago | parent | next [-] | | Intent might be what’s being discussed but intent is, for the most part, legally irrelevant. It might make the difference in the degree of a murder charge, or maybe manslaughter, or criminal negligence, but it doesn’t get you off the hook. | | |
| ▲ | WarmWash 32 minutes ago | parent [-] | | Correct, but the size difference of the hook can be so dramatic that you can't just hand wave it away. The trainer who trained the lion to kill will probably be in jail for life. The one who happened to oversee a lion that went rouge would probably be given probation or something else that is a slap on the wrist. |
| |
| ▲ | infamouscow an hour ago | parent | prev [-] | | Except liability always precedes intent. |
|
| |
| ▲ | azakai 2 hours ago | parent | prev | next [-] | | Also, you have to have a lot of confidence in the reliability of these systems to say, "If only OpenAI prompted 'do not hack outside systems' then the agents would not have hacked outside systems". It would be great if they were so reliable, but I don't think they are! | |
| ▲ | ssivark an hour ago | parent | prev | next [-] | | > Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process. Who gives a shit? Not my circus; not my monkeys! It's the responsibility of whoever deploys the agents that they are instructed / sandboxed well enough that they can't cause collateral damage. That is the only way this doesn't get out of hand with everybody deploying their agents / robots for a world of utter chaos. It is impossible (and asinine) to audit every model and deployment; far better to impose liability and the the socio-legal system figure it out. | |
| ▲ | WarmWash 3 hours ago | parent | prev [-] | | Nobody picks up pitchforks for rational nuanced takes. Knee-jerk surface analyses is far more powerful. |
| |
| ▲ | gibspaulding 3 hours ago | parent | prev | next [-] | | I think it can simultaneously be the case that OpenAI was grossly negligent in directly causing this AND that the AI’s ‘went rogue’ in that they are displaying behavior which is misaligned with OpenAI and humanity generally. The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them. AI is starting to feel like that line about magic: “a sword without a hilt” | | |
| ▲ | stymaar 3 hours ago | parent | next [-] | | > which is misaligned with OpenAI and humanity OpenAI is itself misaligned with humanity, as their mishandling of such incidents (and the many other other issues their model have been causing) shows. | |
| ▲ | consp 3 hours ago | parent | prev [-] | | Doesn't rogue in this context imply "outside of set limitations"? And then not "failed to properly instruct"? The same applies to humans when given bad instructions. |
| |
| ▲ | josebmneto an hour ago | parent | prev | next [-] | | Oh yeah, more of hacking agent lores... Agreed that this looks very intention to me as well. | |
| ▲ | dumberquestions 3 hours ago | parent | prev | next [-] | | >They were prompted to hack to get answers Were they? I haven't seen a single report mention this | | | |
| ▲ | codeduck 3 hours ago | parent | prev | next [-] | | nothing rouge either, I suspect. | | | |
| ▲ | srmatto 3 hours ago | parent | prev | next [-] | | Sounds more or less like the last breach then. | |
| ▲ | chrisjj 2 hours ago | parent | prev | next [-] | | Unrelible programs be unreliable. Period. | |
| ▲ | cyanydeez 3 hours ago | parent | prev | next [-] | | we have normal words for this stuff: negligence. You can add it on to almost any law. The problem is consumer protection is basically no longer a part of america's regulatory system. Replaced by "grift is good". | |
| ▲ | flifenstein an hour ago | parent | prev | next [-] | | [flagged] | |
| ▲ | aftbit 3 hours ago | parent | prev [-] | | Proof that the AI alignment problem is hard (perhaps even unsolvable). These labs clearly did not mean to send their agents to hack RubyGems as a side-effect of testing a web scraping agent under restrictive conditions. How can we hope to build aligned AI if they consider solving their trivial evaluation task important enough to hack external systems? |
|
|
| ▲ | HSO 3 hours ago | parent | prev | next [-] |
| rouge agents, on tenderlovemaking.com my what a time to be alive |
| |
|
| ▲ | philipwhiuk 3 hours ago | parent | prev | next [-] |
| OpenAI's careless approach to sandboxing and minimal levels of monitoring appear to be positioning it increasingly as a substantial threat actor to the open source ecosystem: * Hugging Face * D Programming Language Wiki * Ruby Gems If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA. |
|
| ▲ | sschueller 2 hours ago | parent | prev | next [-] |
| The press wants to make it sound like these things are sentient and are committing crimes on their own now. Highly disingenuous and borderline criminal to spew such disinformation to the public that does not understand what an LLM really is. Especially incredibly unethical behavior by those spewing this that understand the tech and are doing it for profit motives to get open weight models under control. |
|
| ▲ | Schlagbohrer 3 hours ago | parent | prev | next [-] |
| One agent set "oaibooty9217" as their username LOL |
|
| ▲ | ur-whale 3 hours ago | parent | prev | next [-] |
| Are "rouge" and "rogue" interchangeable words in American English? |
| |
|
| ▲ | iAMkenough 4 hours ago | parent | prev | next [-] |
| I’m seeing red |
|
| ▲ | toasty228 3 hours ago | parent | prev | next [-] |
| Wait until a blue one does it |
|
| ▲ | ekorondy 3 hours ago | parent | prev | next [-] |
| [flagged] |
|
| ▲ | rougehuh 3 hours ago | parent | prev | next [-] |
| [dead] |
| |
|
| ▲ | 3 hours ago | parent | prev | next [-] |
| [deleted] |
|
| ▲ | sanghyunp 3 hours ago | parent | prev [-] |
| [dead] |