OpenAI bots meddled with multiple US Government agency sites
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
OpenAI bots meddled with multiple US Government agency sites
Unofficial Hacker News client; not affiliated with Y Combinator.
gizajob · · focus · HN ↗
OpenAI meddled with multiple US Government agency sites.
The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.
20k · · focus · HN ↗
It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?
In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this
This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem
>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.
This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up
0xDEAFBEAD · · focus · HN ↗
It's already going up at staggering rate. Anthropic is now at $100B in annualized revenue, up 50% in the past two months.
* * *
Here's a little allegory for how I'm thinking about this discourse.
Imagine a man who is raising tiger cubs in his backyard. They're growing fast. He keeps them on dog leashes so they stay under control. One day, a growing cub breaks its leash and goes on a rampage through the neighborhood, eating a beloved local pet.
The neighborhood erupts into a big argument: Was the leash inappropriately thin? The neighbors point out that thicker leashes are easily available at the local pet store. Furthermore, is it appropriate to refer to the loose cub as a "wild animal" in local news reporting, or is it factually more accurate to call it "domesticated"?
Meanwhile, the cubs grow larger and lick their lips, oblivious to the discussion.
gizajob · · focus · HN ↗
0xDEAFBEAD · · focus · HN ↗
gizajob · · focus · HN ↗
4d4m · · focus · HN ↗
However, there is a reasonable ask from the public to hold real people accountable for actions downstream of the software allowed to carry out intendended and unintended actions that may not be allowed depending on jurisdictions laws.
Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
0xDEAFBEAD · · focus · HN ↗
"According to survey results released on Wednesday, 68% of [likely US voters] said they would support the proposal to temporarily pause advanced AI development and permanently prohibit the development of superintelligent programs, while just 25% said they’d oppose it."
<a href="https://www.commondreams.org/news/sanders-casar-ai-bill-poll" rel="nofollow">https://www.commondreams.org/news/sanders-casar-ai-bill-poll
>Eg in a hypothetical armed convenience store theft: We don't prosecute the gun manufacturer, we prosecute the individual using the weapon for crime. Same deal here.
So if I ask ChatGPT to make me some paperclips, and it replaces all the matter in a nearby city with paperclips, who gets prosecuted: me, or OpenAI?
4d4m · · focus · HN ↗
0xDEAFBEAD · · focus · HN ↗
morpheos137 · · focus · HN ↗
bwfan123 · · focus · HN ↗
It is an elaborate business ploy to create a regulatory framework for "safe-ai" that shields these companies from liability. This way, they can sell "safe-ai" to enterprises and if shit-hits-the-fan at the enterprise, sorry, this is certified "safe-ai" so, your bad. Shift blame to a regulatory body. From an enterprise buyer's perspective they can say, hey, I bought "safe-ai" and so dont fire me when it "rm -rfs" the production database. Still, beats me why they are painting their product in a negative light, and scaring their own enterprise customers. After this sort of marketing, any enterprise buyer would be scared to go anywhere near it.
idiotsecant · · focus · HN ↗
TomGarden · · focus · HN ↗
mrob · · focus · HN ↗
jsnell · · focus · HN ↗
> This is why it smells like marketing
It doesn't. "Our product commits felonies" is not marketing. If something is marketing, you don't engage in repeated coverups of the true extent. If something is good news, you don't release it on a Friday evening (in this case) or wait for 3rd parties to find and publicize the evidence (the past cases).
8note · · focus · HN ↗
so openai specifically tasked the agents with meddling in US government websites?
id say tasking them with getting data from there as swapping from negligence to malice.
jsnell · · focus · HN ↗
They did not task the agents with hacking into systems. Not monitoring for that was a mistake, but maybe a forgivable one the first time around. The subsequent coverups are inexcusable.
tough · · focus · HN ↗
jacquesm · · focus · HN ↗
Oh, absolutely it is. Arms manufacturers always go on about the efficiency of the weapons they create and make no mistake: OpenAI is first and foremost a weapons manufacturer, the rest is just a fig leaf. The fact that you aren't the audience for purchases like that makes no difference. "Look at this capability, and that's when we're not even trying." is pretty good marketing in some circles.
jsnell · · focus · HN ↗
Climate change is just a scam by the fossil fuel industry to hype up their market cap. Look at the power of co2, and the damage it can do without even trying.
Medicines being pulled during trials or after public availability for side effects are just Big Pharma making their products more desirable via scarcity.
Boeing did really well out of the 737 max. Airlines were just lining up to buy an airplane that could give the passengers an experience they would remember for the rest of their life. That's why they absolutely made clear that it was their product that was dangerous, rather than blaming operator error.
jacquesm · · focus · HN ↗
jsnell · · focus · HN ↗
Big businesses really do not like to talk about their products being harmful or dangerous, and there is ample evidence to that. Danger only sells in artisanal quantities to niche audiences.
jacquesm · · focus · HN ↗
popalchemist · · focus · HN ↗
charcircuit · · focus · HN ↗
Would a read only copy of the web be sufficient for this though? Google keeps a read only copy of the web in their data centers which they use to extract information from websites.
4d4m · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
jltsiren · · focus · HN ↗
The basic premise of OpenAI is that experience and expertise don't matter, because general intelligence can figure those out from data. If you start from that assumption, the rest follows. The same people could do things in a different way in a different company, but as long as they are working for OpenAI, they are going to do things in the OpenAI way.
jacquesm · · focus · HN ↗
Kim_Bruning · · focus · HN ↗
They didn't allow any of that. As far as openai knew the agents were sitting a fairly humdrum exam/test sequence in a sandbox farm run by a company in Tel Aviv.
Meanwhile, they managed get out through a single weak point common to the sandboxes, and then ran wild compiling cheat sheets for themselves.
> every time one of these incidents happens
This happened in june-ish, and there have been multiple HN stories about this already. It's mostly/all the same hugging face and wiki hacks that happened back then.
We're just slowly learning the extent of the damage.