‹ BackHN Continuity

Thread

OpenAI bots meddled with multiple US Government agency sites

132 points · 196 comments · Betelbuddy

  1. gizajob · · focus · HN ↗
    Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:

    OpenAI meddled with multiple US Government agency sites.

    The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.

    1. 20k · · focus · HN ↗
      Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?

      It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?

      In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this

      This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem

      >"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.

      This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up

      1. Kim_Bruning · · focus · HN ↗
        > Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?

        They didn't allow any of that. As far as openai knew the agents were sitting a fairly humdrum exam/test sequence in a sandbox farm run by a company in Tel Aviv.

        Meanwhile, they managed get out through a single weak point common to the sandboxes, and then ran wild compiling cheat sheets for themselves.

        > every time one of these incidents happens

        This happened in june-ish, and there have been multiple HN stories about this already. It's mostly/all the same hugging face and wiki hacks that happened back then.

        We're just slowly learning the extent of the damage.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.