|
| ▲ | CodeWriter23 28 minutes ago | parent | next [-] |
| Not a lawyer but I think training a model with hacking skills they explicitly prevent the public from accessing without doing anything to stop the model itself from using those demonstrates intent. |
| |
| ▲ | john_strinlai 24 minutes ago | parent [-] | | what you described is negligence. unless you can prove that openai specifically targeted huggingface and specifically instructed their model to hack huggingface, it would not be intent. anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa's requirements. it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid. |
|
|
| ▲ | jordanb an hour ago | parent | prev | next [-] |
| How many times does it have to happen before they no longer get to claim that they didn't intend for it to happen? If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts "oopse!" |
| |
| ▲ | john_strinlai an hour ago | parent [-] | | >If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts "oopse!" yes, they look very silly. but that's not how intent works. openai is being negligent (willfully so, in my opinion). but i have seen no evidence that they intended to specifically hack huggingface. which is the part that the cfaa wants. again, there are other laws and other ways to hold openai responsible. but the cfaa is a poor choice. |
|
|
| ▲ | devin an hour ago | parent | prev | next [-] |
| Willful negligence or gross negligence, then. |
| |
| ▲ | rot09 6 minutes ago | parent | next [-] | | This lines up. In the infosec community it is well known that OpenAI did not hire many security engineers or researchers pre-April 2026. There has been a crazy hiring push from both companies to poach security engineers/researchers from Google, Apple, and Meta since Q2/Q3, but the response was very delayed. Many talented security engineers/researchers I know at Apple/Google/Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal/personal liability and the more likely risk of tarnishing their careers. | |
| ▲ | john_strinlai an hour ago | parent | prev | next [-] | | indeed, that'd be a better angle than a cfaa violation | |
| ▲ | EGreg an hour ago | parent | prev [-] | | So then… you’re liable? https://www.brandonjbroderick.com/new-york/dog-leash-laws-ne... |
|
|
| ▲ | cmiles8 an hour ago | parent | prev | next [-] |
| Criminal negligence is a thing too |
|
| ▲ | EGreg an hour ago | parent | prev [-] |
| https://jtnylaw.com/2025/08/new-yorks-leash-law-realities/ Plaintiffs seeking damages must show that owners knew or should have known about the dog’s patterns. Past complaints or vet records help build a strong case. |
| |