‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. alex-moon · · focus · HN ↗
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    1. colinhb · · focus · HN ↗
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: <a href="https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai-hugging-face-incident-exposed-the-cfaa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai...
      1. dv_dt · · focus · HN ↗
        The difference between manslaughter and murder has an element of intent. Cybercrime &quot;manslaughter&quot; is probably more treated like negligence and if one can sue for restitution of the costs for cleanup of that negligence.

        Negligence would be interesting given the grand claims of capability of AI models from the AI companies and their executives. If they believe the claims, why not much stronger precautions?

        1. Sharlin · · focus · HN ↗
          Infosec negligence should absolutely be a crime, no matter if you’re a target (who was negligent at protecting people’s data) or an unintentional attacker. The latter could be, eg. an attacker using a company’s poorly protected server as a proxy to launch the actual attack against someone else, doesn’t have to be this fully novel situation with AI agents.
          1. dv_dt · · focus · HN ↗
            In general, I&#x27;d suggest thinking about it on separate tracks, as a crime, and as liability. For crime, we are largely dependent on authorities to act, whereas as liability, that allows more independent actions.
        2. jonplackett · · focus · HN ↗
          The first time it happens you can say it’s negligence. Now that they know it keeps happening and they seemingly aren’t able to stop it but keep doing it. That has to be on them doesn’t it?
          1. yorwba · · focus · HN ↗
            I don&#x27;t think you can infer that they &quot;keep doing it&quot; from additional attacks being revealed, because they all seem to have happened roughly during the same time frame, but are reported with varying delays.
          2. DannyBee · · focus · HN ↗
            Lawyer here: No. Not criminally. Knowledge that a certain result is likely is not the same as intent to cause the result. This is basically the difference between recklessness and intentionality. Doing something when you know of a likely result is reckless, but not intentional. Only doing something, trying to cause a result (likely or not) is intentional. In this case, the CFAA only covers intentional access without authorization, not reckless access without authorization.
            1. jonplackett · · focus · HN ↗
              What are the punishments for recklessness VS intent?

              Or are OpenAI too well connected now to be punished for anything.

              1. tptacek · · focus · HN ↗
                It depends on the statute, but if you&#x27;re talking about 18 USC 1030, the standard is intentionality (if not to intentionally access something you shouldn&#x27;t, then intent to defraud).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.