‹ BackHN Continuity

Thread

Early rogue AI agent activity and attempts to hack found on urlquery.net

267 points · 313 comments · snikolaev

  1. alex-moon · · focus · HN ↗
    It's said on every one of these but it bears repeating: existing cybercrime legislation already covers this - "rogue agent AI associated with OpenAI attempted to hack xyz" = OpenAI attempted to hack xyz.
    1. colinhb · · focus · HN ↗
      I want to agree but have heard from several lawyers that at least in US, CFAA[1] in unlikely to be sufficient because it requires intent. No person intended to gain unauthorised access.

      Now I think the correct response is both trying in court to stretch CFAA and state statutes to cover, which will be highly fact specific, and update the law.

      But in either case won’t be a slam dunk.

      PSA to folks in the thread: If you’re American call or write to your state and Federal reps about this, and if not investigate whether there are gaps in your country’s laws.

      [1]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act

      EDIT: See for example...

        The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind. Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
        On the current facts, CFAA liability for OpenAI is unlikely.
      
      Source: <a href="https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai-hugging-face-incident-exposed-the-cfaa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;law.vanderbilt.edu&#x2F;when-ai-hacks-back-how-the-openai...
      1. DannyBee · · focus · HN ↗
        Lawyer here: CFAA is mostly criminal statute not a civil one (civil damages require proving more than a violation so also require specific intent)

        Almost all common felonies require specific intent. Misdemeanors often do not.

        There is plenty of civil liability available.

        If you wanted them to be charged with a felony you would need changes. I would strongly suggest you do not want a strict liability felony.

        The cfaa required intent is as follows :

        * § 1030(a)(5)(A): knowingly transmits code&#x2F;commands and intentionally causes damage without authorization.

        * § 1030(a)(5)(B): intentionally accesses without authorization and recklessly causes damage.

        * § 1030(a)(5)(C): intentionally accesses without authorization and causes damage and loss;

        Simply changing the first intentionally to intentionally or recklessly would cover OpenAI (now that they know it can occur) without causing lots of other issues. Without that, they don’t have the intentionality necessary to meet the first part, even if they would otherwise meet the second part

        1. shimman · · focus · HN ↗
          What about all the state laws that are equivalent to the CFAA in their local jurisdictions? Why couldn&#x27;t anything in NY article 156 (Offenses Involving Computers) apply here for felonies?

          <a href="https:&#x2F;&#x2F;www.nysenate.gov&#x2F;legislation&#x2F;laws&#x2F;PEN&#x2F;P3TJA156" rel="nofollow">https:&#x2F;&#x2F;www.nysenate.gov&#x2F;legislation&#x2F;laws&#x2F;PEN&#x2F;P3TJA156

          I guess what I&#x27;m asking is why do we need the federal government to press for felonies when every state has equivalent laws dealing with just this?

          1. DannyBee · · focus · HN ↗
            Almost all state laws based on the CFAA, including this one, similarly require either knowingly doing it or some other form of specific intent. At least at a glance. If there is a specific part you think does not, I’m happy to look at it, but I’ve read a lot of pages of law to respond to people so far, and I’d like to avoid reading another 25 if I can avoid it.

            It does not require the federal government to fix the CFAA, for sure, but you still have to change the intent requirement to allow for recklessness, which it does not right now afaict.

            If you really want an expert opinion, I’m sure Orin Kerr has opined on this, and he knows pretty much the entire are of state and federal law on this cold. I’d be shocked if he did not reach the same conclusion

            1. shimman · · focus · HN ↗
              I understand but these developers did knowingly did it? They even admitted to developing them with these goals in mind. These software agents are not autonomous and do not have agency, you can&#x27;t let software recklessly hack into things; but I will admit I&#x27;m not a lawyer, I don&#x27;t understand how they aren&#x27;t liable.

              Thanks for the other suggestion, I&#x27;ll read into their insights more.

              Guess it mostly comes down to action, people want to see their electeds actually trying not sitting around with their hands in their pockets while these tools continue to destroy unabated.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.