‹ BackHN Continuity

Thread

OpenAI bots meddled with multiple US Government agency sites

132 points · 196 comments · Betelbuddy

  1. gizajob · · focus · HN ↗
    Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:

    OpenAI meddled with multiple US Government agency sites.

    The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.

    1. 20k · · focus · HN ↗
      Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?

      It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?

      In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this

      This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem

      >"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.

      This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up

      1. jsnell · · focus · HN ↗
        These were evaluations or training runs dealing with the ability to do web searches. The entire reason the bots were targeting this site is that it had some of the data they'd been tasked with finding. Access to the internet is not really optional for that, and providing internet access doesn't demonstrate neglicence.

        > This is why it smells like marketing

        It doesn't. "Our product commits felonies" is not marketing. If something is marketing, you don't engage in repeated coverups of the true extent. If something is good news, you don't release it on a Friday evening (in this case) or wait for 3rd parties to find and publicize the evidence (the past cases).

        1. 8note · · focus · HN ↗
          > The entire reason the bots were targeting this site is that it had some of the data they'd been tasked with finding.

          so openai specifically tasked the agents with meddling in US government websites?

          id say tasking them with getting data from there as swapping from negligence to malice.

          1. jsnell · · focus · HN ↗
            No. They tasked them with answering questions by retrieving data from public sources. This obviously requires internet access. So the incredulity about "how could they fail to block internet access" is just inane. That was the task.

            They did not task the agents with hacking into systems. Not monitoring for that was a mistake, but maybe a forgivable one the first time around. The subsequent coverups are inexcusable.

            1. tough · · focus · HN ↗
              Usually also, and more so nowadays, a few of the public sources of data left, even after the recent USGov intention of defund and close as much of them as possible, im guessing would be precisely, government websites!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.