‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. alex-moon · · focus · HN ↗
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    1. colinhb · · focus · HN ↗
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: <a href="https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai-hugging-face-incident-exposed-the-cfaa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai...
      1. podocarp · · focus · HN ↗
        Wait so if I was making a bomb but you couldn&#x27;t prove I wanted to blow someone up or had some motive (e.g. I&#x27;m just a chemistry enthusiast, plenty of those YouTube channels around) so it just becomes an &quot;accident&quot;?

        So as long as there&#x27;s no motive behind it then it&#x27;s just OK?

        1. dwedge · · focus · HN ↗
          That&#x27;s a bad faith metaphor. A better one would be something like a new battery that exploded and killed someone - perhaps it was always your intention, perhaps not.

          Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

          1. lelanthran · · focus · HN ↗
            &gt; Funnily enough the US already has one similar real argument around guns - should gun manufacturers be liable for damages caused by their product?

            The question is already settled - gun users are responsible for damages arising from their usage of the guns.

            Why would AI users not be responsible for damages arising from their usage of the AI?

            1. Lyrkan · · focus · HN ↗
              &gt; Why would AI users not be responsible for damages arising from their usage of the AI?

              Because, as usual with that kind of question, it&#x27;s not that simple.

              Let&#x27;s say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server. Should the user be responsible or OpenAI?

              1. lelanthran · · focus · HN ↗
                &gt; Let&#x27;s say an user asks ChatGPT to get some info about something and for some reason it starts using exploits in the background to get them from a server.

                Okay, lets go with that as scenario #1.

                For scenario #2 lets use &quot;developer asks an agent to a self-hosted LLM to get the docs for a ERP system, and it hacks the vendor to get unreleased and undocumented docs&quot;.

                We&#x27;ll assume, for the sake of this argument, that in neither case did the user intend for any malicious action to be performed.

                &gt; Should the user be responsible or OpenAI?

                In scenario #1, the agent+LLM is under the control of OpenAI, not the user, so OpenAI is liable.

                In scenario #2, the agent+LLM is under the control of the user, so the user is liable.

                There is no scenario anyone can come up with that is not addressed sufficiently by existing laws[1].

                It&#x27;s very clear, and it&#x27;s only getting muddied because there&#x27;s a group of powerful people who want exemptions from the current law.

                IOW, the only reason to draft new laws for AIs is to exempt their usage from the current laws.

                ========================

                [1] Possible 3rd option (local agent + OpenAI LLM). In that case an investigation would determine where the culpability lies. Just like how it is currently done in law.

                When a pressure-cooker explodes and kills someone there are only two possible liable parties: either the user or the manufacturer. An investigation determines who&#x27;s liable. I see no reason to automatically exempt everyone from liability just because an agent did something.

                1. hermannj314 · · focus · HN ↗
                  The retailer or distributor can also be named as a defendant if the manufacturer is difficult to track down, bankrupt or overseas according to me spending a few minutes reading about pressure cooker lawsuits.

                  I have lost track of the metaphor, but man pressure cooker lawsuits are more common than I thought.

              2. [deleted] · · focus · HN ↗

                [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.