‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. alex-moon · · focus · HN ↗
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    1. colinhb · · focus · HN ↗
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: <a href="https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai-hugging-face-incident-exposed-the-cfaa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai...
      1. podocarp · · focus · HN ↗
        Wait so if I was making a bomb but you couldn&#x27;t prove I wanted to blow someone up or had some motive (e.g. I&#x27;m just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an &quot;accident&quot;?

        So as long as there&#x27;s no motive behind it then it&#x27;s just OK?

        1. i_v · · focus · HN ↗
          I think it’s more along the lines of PEPCON. They didn’t try to make a bomb. Their plant exploded and caused two fatalities and $100 MM in damages.

          I don’t think OpenAI or any large company will see more than some fines and new legislation but only after a disaster.

          1. tgv · · focus · HN ↗
            Factories try to avoid accidents, and (almost always) actively try to prevent explosions, but in this case they did teach the models hacking, and let them roam. What they did was not safe, and they knew it, or could have known it.
            1. pixl97 · · focus · HN ↗
              It&#x27;s easy to say that post ad hoc, but there is evidence they did not just let them roam and there was a large mismatch between expected model capabilities and actual model capabilities. Teaching a model hacking in itself is no way illegal unless you&#x27;re trying to say that everyone in infosec is now guilty of a crime. That&#x27;s not exactly a precedent I want to be set.

              &gt;Factories try to avoid accidents, and (almost always) actively try to prevent explosions

              It doesn&#x27;t take much more than a few minutes on the USCB channel that explosions still happen all the time. Some due to direct negligence and others due to unexpected conditions that were difficult to foresee. Hence why we have to do investigations rather than blindly blathering about what happened before we actually know.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.