Early rogue AI agent activity and attempts to hack found on urlquery.net
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Early rogue AI agent activity and attempts to hack found on urlquery.net
Unofficial Hacker News client; not affiliated with Y Combinator.
jagraff · · focus · HN ↗
bamboozled · · focus · HN ↗
They have claimed this happened during a "training run", but why are they training on systems connected to the internet?
That's why people are skeptical.
jagraff · · focus · HN ↗
The models were not trained on systems intentionally connected to the internet; they chained mutliple zero-days (that they discovered) together to get access to the open internet and into huggingface.
simoncion · · focus · HN ↗
If Amazon connects an AWS Top Secret region to the Internet, it doesn't matter whether or not it's intentional... they're getting nailed to the wall by the US government either way. Frankly, it's way worse for them if it was accidental; deliberate, sophisticated sabotage is a much better story than rank incompetence and/or negligence.
A similar sort of thing applies to the manufacturers of tools that they claim to be dangerous, that have been deliberately built to exceed their authorized access to other computer systems, and are deliberately being tested on how well they can do the thing they've been built to do.
Deliberate, sophisticated sabotage by one or more humans in their employ is much more forgivable than "Whoopsie, we didn't think to make it literally impossible to connect this dangerous automated computer-hacking tool to the Internet.".
jagraff · · focus · HN ↗
What I dispute is that AI agents are simple tools. I think rogue is an accurate word to describe them; I think what OpenAI is doing is more akin to gain-of-function research on a dangerous lifeform. I think this attack would have been prevented by air-gapping, but that wouldn’t solve the fundamental issue which is that they are creating something dangerous that they have no idea how to control
simoncion · · focus · HN ↗
You're in luck! I agree that they are not simple tools. I never claimed that they were. Slow down and read more carefully.
I couldn't disagree more with the insinuation that the LLM manufacturers are doing things akin to scary research on uncontrollable hazardous biologicals and with the claim that "rogue AI" is the correct thing to call those complicated tools. The first is fearmongering which I'll address indirectly in my second-to-last paragraph. The second shifts the conversation from
"How could you have not predicted that the computer-attacking tool you built, explicitly instructed to attack computers, [0] and connected to the Internet attacked someone else's computers that were connected to the Internet?"
to
"Wow, that thing went rogue. Noone's to blame but the tool, and it can't be blamed!".
There are so many extremely complex systems out there [1] and when they do things that we don't want them to do, it's not described as "going rogue"... either there's some error(s) in the underlying system that caused the confusing behavior, or the programmer didn't understand well enough how that system works.
> ...they are creating something dangerous that they have no idea how to control
Ignoring the fact that "put it in a box and don't let it out of the box" is the simplest possible control mechanism, [2] if they have no idea how to control the tools they've been building, it's because they haven't bothered to learn as they went. Tangentially related, there's a Tumblr post I saw recently that's a fictional conversation with the Tumblr user and the CEO of Anthropic. It went something like
[0] That is -after all- the task that the tool was put to when it attacked other people's computers.[1] Have you ever tried to really understand a specific AMD x86-64 CPU, let alone the entire stack that makes up the system that is a consumer-grade PC and its installed software? Both are definitely way more than any one human can keep in their head at once, and are tasks that would take a very long time to complete.
[2] ...it's also the most appropriate control mechanism for the task that started all this conversation, and neither of the major manufacturers used it!
writeslowly · · focus · HN ↗
jagraff · · focus · HN ↗
drillsteps5 · · focus · HN ↗
And when this results in actuators executing some bad actions they scream in horror "AI went rogue! It escaped the containment!!! It's going to kill us all!!!"
Go fix your software before you let it do stuff online or IRL. It's not "Terminator", it's just bad QC.
jagraff · · focus · HN ↗
simoncion · · focus · HN ↗
If we take the major LLM companies' claims at face value, they're knowingly building WMDs that have a high probably of wiping out the entire human race. [0] Manufacturers that are designing, building, and selling that sort of thing need to have a dreadfully serious culture of safety.
When manufacturers run live tests of their extremely dangerous -again, the claim of danger is their claim- tools with the tools' safeties removed, one expects that those tests will be run on a carefully-controlled range cleared of all bystanders. One also expects that the results of those tests will be scrutinized and everything that got damaged that they didn't intend to be damaged will be noticed and noted very quickly after the conclusion of the test.
In actuality, these manufacturers connected said tools to the Internet and did not discover the unintended damage caused by those tools until weeks to months after the tests. In some (most?) cases, they had to be notified of the damage by the damaged party! This means that their safety culture is entirely inadequate for the dangerous task they've deliberately chosen to undertake.
[0] A 10% chance of causing the destruction of the entire human race is -given the stakes- _enormous_.
jagraff · · focus · HN ↗
simoncion · · focus · HN ↗
You and I and Nvidia CEO Jensen Huang seem to agree on this. Excerpts from his interview with Ezra Klein: [0]
Klein:
Huang: Former FTC chair Lina Kahn has suggestions, too. [1]Thoughts?
[0] <<a href="https://www.nytimes.com/2026/09/23/opinion/ezra-klein-podcast-jensen-huang.html" rel="nofollow">https://www.nytimes.com/2026/09/23/opinion/ezra-klein-podcas...>
[1] <<a href="https://x.com/linamkhan/status/2099204390548639960" rel="nofollow">https://x.com/linamkhan/status/2099204390548639960>
jagraff · · focus · HN ↗
simoncion · · focus · HN ↗
Why? Existing truth-in-advertising, liability, safety, and -where and when appropriate- weapons-development laws and regulations constrain the past and current conduct of the LLM manufacturers just fine.
The only possible reason for making new laws that I can see [0] is that existing laws "don't work" because the LLM manufacturers are ignoring them. Which, like, _if_ the new laws are going to actually constrain their behavior, why the hell would the LLM manufacturers pay any attention to them? They've already demonstrated that they give zero shits about the existing laws that prohibit what they have been doing and continue to do.
[0] ...that isn't "The LLM manufacturers are engineering a panic with their very real, actual, and actually alarming conduct so that they can 'guide' lawmakers and regulators into 'accidentally' letting the LLM manufactures capture those who would regulate their behavior"...
jagraff · · focus · HN ↗
simoncion · · focus · HN ↗
a) Both OpenAI and Anthropic have done far more damage with their jaw-droppingly-sloppy testing of computer-attacking tools than Aaron Swartz did by downloading documents from JSTOR. It's good to see that you and I both agree that there are things for them to be prosecuted for.
b) Is your claim that the cost to thoroughly investigate and clean up after a cyberattack doesn't count as damage? If so, that runs contrary to every relevant claim of damages in a CFAA case that I've seen.
jagraff · · focus · HN ↗
What I'm saying is that that is not sufficient to stop future harm; I expect the total damages would be less than the cost of a full training run, so it would effectively just be the cost of doing business. Liability is not sufficient to protect the world from dangerous technology - we need proactive rules around how the technology is developed, tested, monitored, and deployed, as we do with other dangerous industries such as airplanes, nuclear reactors, weapons manufacturers, etc
simoncion · · focus · HN ↗
You and I couldn't disagree more.
The major LLM manufacturers are begging for new laws and regulations so that they get a huge hand in writing them. Regulatory capture is absolutely their goal. Given that they claim to believe that they're working on WMDs [0] that they cannot adequately control, they'd just stop work if safety was their goal. Their collective cries for regulation demonstrate that they'll happily coordinate with each other if they think the issue is important enough to do so. I guess "preventing the extinction of the human race by way of weapons we built and let slip from our hands" isn't sufficiently important.
[0] See the second paragraph and associated footnote here for a justification for the use of this term: <<a href="https://news.ycombinator.com/item?id=49839682">https://news.ycombinator.com/item?id=49839682>
ambicapter · · focus · HN ↗
jagraff · · focus · HN ↗
In the AI case, no, because I think the engineers believe that there is a high probability of enormous upside as well, if it doesn’t kill us all.
bagacrap · · focus · HN ↗
jagraff · · focus · HN ↗
bagacrap · · focus · HN ↗
jagraff · · focus · HN ↗
I’ll admit I also just don’t understand the idea that someone saying their product is dangerous and could kill all of humanity is doing marketing - I just really don’t understand at all how that could be a marketing strategy. So I tend to believe they are saying it is dangerous because they think it’s true. But maybe I’m just naive.
bagacrap · · focus · HN ↗
It's telling governments, "this is so powerful it could cause grave harm to the consumer, please regulate so we can focus on extracting value from the economy instead of this expensive arms race."
I warrant it is quite possible that some in this space are worried they will overshoot the mark. The perfect outcome for them, of course, being fabulous wealth and a society that is otherwise not too much different from today's. What a shame it would be to be super rich and dead!
It does kind of feel like they are trying to ransom the future of humanity. These rogue AI stories are like getting a dismembered finger in the mail.
ambicapter · · focus · HN ↗
jagraff · · focus · HN ↗
ambicapter · · focus · HN ↗
jagraff · · focus · HN ↗
Also I'm not describing what I personally think is an acceptable job; just that I understand that sometimes people do jobs that they think are wrong because they need money
grafmax · · focus · HN ↗
jagraff · · focus · HN ↗