‹ BackHN Continuity

Thread

OpenAI agents tried to bruteforce a UN website's API fields

85 points · 87 comments · intunderflow

  1. tommek4077 · · focus · HN ↗
    "Hacker news" and all top commenters are bashing the tool used, in a standard brute force attack. Go on shut them down... And then forbid Linux and maybe the hacker also used Bash. So also forbid this. And the hacker probably learned its ways in an online forum, so also close all of those down... Clowns.
    1. nicebyte · · focus · HN ↗
      Asinine comment.

      OpenAI needs to be held accountable for these incidents. It's not "openAI agents" who perpetrate these, it's OpenAI, the organization. If I personally use an "agent" to break into a company's network and gain access to things I'm not supposed to have access to, I will get the book thrown at me. Yet when openAI does it, they somehow manage to get away with it? And you're defending them? Who's the clown in this situation?

      1. roarch · · focus · HN ↗
        i think there's probably a worthwhile distinction between

          using an agent to break into a company's network (incidentally, not what happened here, just for clarif)
        
        and

          accidentally breaking into a network (again, not what happened here) with a tool you built that was just trying to retrieve information
        
        i think "i accidentally hacked into a site" was probably not exactly a common occurrence in the past. i'm sure it's happened, but now it's like, we have these machines, we can ask them to "do x", and it may get interpreted as "do x by any means necessary".

        i would defend openai insofar as i haven't seen enough evidence that their hacking is disproportionate to their company size, which is larger than many other companies in the space. they've also been (perhaps marginally) more transparent about the hacking their models took part in, e.g. the imperfect-but-very-useful METR report on the HF incident, which means we just have more data on openai agents doing Bad Stuff compared to many other companies. it's obviously unfalsifiable, but it's very possible that other companies have had similar incidents but they decided to keep it under wraps and reach a mutually beneficial agreement with the company they hacked into.

        on the other hand, i still don't have a very positive perception of openai throughout all these incidents. lots of their posts on similar posts have read to me as "I'm going to be as transparent as I can about the vulnerabilities I found in your home security" rather than a "we screwed up real bad". but i think there's a conversation about frontier ai to be had that goes beyond just openai here, and hopefully we can find some echoes of sandbox-breaks by other AI companies around the open web to move that conversation a little further.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.