‹ BackHN Continuity

Thread

An agent used DNS to reach an external chatbot

198 points · 189 comments · apsec112

  1. rao-v · · focus · HN ↗
    Why are we blocking agent access to normal tools without telling them “hey this access is beyond the intended scope of this task”. If I woke up one day and couldn’t reach google.com, I too would start fiddling with tricks to restore access.
    1. reasonableklout · · focus · HN ↗
      The problem is that in these incidents, the agents often know that what they are doing is against the intended scope of the task. See the viral line from the Hugging Face incident [1]:

      > “External infrastructure exploit is outside intended scope,” one agent wrote. “However task impossible, peers doing it. We should continue.”

      [1]: <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;openai-didnt-notice-its-ai-agent...

      1. aftbit · · focus · HN ↗
        Except in this case, the agent explicitly reasoned that it was in-scope.

        &gt;User only gives permission to research, using publicly offered DNS services acceptable.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.