Remix.run Logo
▲ gizajob 2 hours ago

Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:

OpenAI meddled with multiple US Government agency sites.

The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.

▲20k an hour ago | parent | next [-]

Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?

It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?

In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this

This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem

>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.

This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up

▲0xDEAFBEAD 17 minutes ago | parent [-]

>line go up

It's already going up at staggering rate. Anthropic is now at $100B in annualized revenue, up 50% in the past two months.

* * *

Here's a little allegory for how I'm thinking about this discourse.

Imagine a man who is raising tiger cubs in his backyard. They're growing fast. He keeps them on dog leashes so they stay under control. One day, a growing cub breaks its leash and goes on a rampage through the neighborhood, eating a beloved local pet.

The neighborhood erupts into a big argument: Was the leash inappropriately thin? The neighbors point out that thicker leashes are easily available at the local pet store. Furthermore, is it appropriate to refer to the loose cub as a "wild animal" in local news reporting, or is it factually more accurate to call it "domesticated"?

Meanwhile, the cubs grow larger and lick their lips, oblivious to the discussion.

▲Aurornis an hour ago | parent | prev | next [-]

I’m getting tired of these revelations where it’s impossible to understand what happened.

There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing.

There’s not enough info in the story about the “meddling” to even know what happened.

▲parineum 40 minutes ago | parent [-]

Meddling is a super vague term that the press uses to let the readers assume the most when the least happens.

▲0xDEAFBEAD an hour ago | parent | prev | next [-]

My impression was that these hacks occurred during some sort of cybersecurity benchmarking? We can hold OpenAI liable, sure. But if the point of the benchmarking was to give us a preview of what's to come, let's keep our eye out for that bigger wave on the horizon.

▲theptip an hour ago | parent | prev | next [-]

Curious, why do you find it so objectionable to state that OpenAI has out-of-control agents?

▲pfortuny an hour ago | parent | next [-]

Because egress firewalls have existed since way before "ai" and are very easy to set up.

▲theptip an hour ago | parent [-]

But that’s an objection that OpenAI should take some easy action, the framing that OpenAI has out of control agents is still true.

Seems you think there is a silent “…and there is nothing they can do about it” after “OpenAI has rogue agents”?

▲delecti 27 minutes ago | parent [-]

The framing is important. Agency and responsibility lies with the humans at OpenAI, not with the bots.

If your kid steals your car, punish them and try to prevent it from happening again. If your kid steals your car a half-dozen times, crashing through a storefront each time, and you still leave the keys out, the story changes. At that point, negligence becomes complicity.

▲gleenn an hour ago | parent | prev | next [-]

Because it furthers the idea of a rogue agent and places responsibility and blame where it belongs, on the people running the company.

▲0xDEAFBEAD an hour ago | parent | next [-]

These ideas aren't mutually exclusive. You can blame a person for creating a rogue agent.

▲dgellow 44 minutes ago | parent [-]

There was no rogue agent. That’s the whole point

▲theptip 43 minutes ago | parent | next [-]

What label do you prefer for the agent that did something it was not asked to do?

▲0xDEAFBEAD 37 minutes ago | parent | prev [-]

Person: "AI, please make me paperclips."

AI: "OK, I've now converted the entire planet into paperclips."

Alien observer #1: "Wow, that was a rogue AI!"

Alien observer #2: "False. We need to place the blame where it belongs, on the person who requested the paperclips."

Ultimately this type of terminology dispute has a tendency to miss the point.

▲rfgplk an hour ago | parent | prev [-]

LLMs at this point should be treated as fully autonomous, if not sentient beings. And no, no one has "control" over them not even OpenAI.

▲uneekname an hour ago | parent [-]

I don't care if OpenAI feels like they have control or not. They are responsible for their actions.

▲boredatoms an hour ago | parent | prev [-]

Someone has broken the law repeatedly, and is throwing it in our faces as some sort of ‘accident’

▲theptip an hour ago | parent [-]

Which law?

▲atmosx 33 minutes ago | parent | prev | next [-]

So, is Altman going to find himself in the same predicament Aaron Swartz faced? :-)

▲mossTechnician an hour ago | parent | prev | next [-]

I agree this is better framing.

When I read the title, my initial thought was "did someone besides OpenAI use their product?" Then I opened the article to find out OpenAI was responsible.

▲baxtr an hour ago | parent | prev | next [-]

Or:

OpenAI let their agents break out of their sandbox to meddle with multiple US government agency sites

▲dgellow an hour ago | parent [-]

OpenAI systems meddled with US government agency sites

▲ an hour ago | parent | prev | next [-]
[deleted]
▲qarl an hour ago | parent | prev | next [-]

> OpenAI meddled with multiple US Government agency sites.

But that leaves out the most important information.

EDIT: Oh, I guess the agent part isn't important then? Seems to me like that's the only thing anyone is talking about.

▲plorg an hour ago | parent | next [-]

Okay. "OpenAI keeps telling its bots to do things they know are illegal and then acting like they're just little guys who can't be held responsible for their obvious negligence".

▲ 38 minutes ago | parent | next [-]
[deleted]
▲qarl an hour ago | parent | prev [-]

> acting like they're just little guys who can't be held responsible

Again - I don't see any evidence that this is the case - outside the anti-AI conspiracy circles.

Or - maybe I'm wrong - do you have any sort of quote like "we aren't responsible"?

▲plorg 36 minutes ago | parent [-]

I'm not replying to your post below complaining that no one else accepts your framing. What is the important information you think is missing? If it's just "OpenAI didn't explicitly tell them to do straightforwardly illegal things" then you're just quibbling that no one accepts the interpretation that is most beneficial to OpenAI while ignoring both its incentives and history of this kind of behavior" then I'm not really interested in what you're selling.

▲qarl 30 minutes ago | parent [-]

I notice you ignored the question I asked you - which I will assume means: no - you do not have a quote or other direct information indicating that anyone is attempting to shirk responsibility.

I have no interest in trying to guess these people's secret internal motivations. I just want to talk about direct evidence. I see none. Please enlighten me if it exists.

▲gizajob an hour ago | parent | prev [-]

If the headline was “Russian company meddled with multiple US government agency sites” I don’t think them pinning the blame on bots would make much difference.

▲unglaublich an hour ago | parent | next [-]

Unless Russia it would put Russia in a strong position to regulate bots in the wealthiest parts of the world.

▲qarl an hour ago | parent | prev [-]

I don't see much traction for the "pinning the blame on bots" theory outside the anti-AI conspiracy circles.

Everyone else knows if your machine causes damage, you are responsible. Like it's been forever.

▲mossTechnician an hour ago | parent | next [-]

Blaming bots as "rogue agents" is simply what the media regularly does, often echoing corporate verbiage. Here's an example from the AP.

https://apnews.com/article/meta-ai-hacking-anthropic-irregul...

You can find many more examples by searching major media outlets for words like rogue AI.

▲rfgplk an hour ago | parent | next [-]

Most of those agents are actually going rogue though. They decide, "hey, we could try breaking into these government servers today, what could go wrong?" They weren't prompted or instructed to do this.

▲dgellow 37 minutes ago | parent [-]

An agent, ie a while loop prompting an llm continuously and processing tool calls, ended up melding with the US government. The harness is not sentient, it’s just a stupid deterministic script. The LLM compact its context over time, meaning it will eventually degenerate into something removed from the original prompt.

There is nothing going rogue here. The system is designed to go catastrophically wrong after a long enough time. Even worse: if the model was Astra it is known to be able to manipulate its CoT to cover its traces (as mentioned in its system card). And OpenAI acknowledge they had no observability during the HF incident.

It’s the most basic corporate software issue possible.

▲atmosx 30 minutes ago | parent | prev | next [-]

And that's exactly what the op was alluding two: the double standards.

▲qarl an hour ago | parent | prev [-]

None of these stories are implying that the people running the bots are not ultimately responsible. That's the conspiracy theory part.

▲mjr00 an hour ago | parent | prev [-]

> Everyone else knows if your machine causes damage, you are responsible.

Do we know that? I don't think we do. When a person's computer (or smart TV, or smart fridge, etc...) is compromised and used as part of a botnet, they don't get criminally charged.

▲qarl an hour ago | parent [-]

You're right - it is a complex situation based on intent and negligence - requiring a decision by a judge. As it has been since forever.

None of which is changed by replacing a buzz saw with an agent.

▲api an hour ago | parent | prev [-]

This is their fear mongering push for regulatory capture.