‹ BackHN Continuity

Thread

OpenAI agents tried to bruteforce a UN website's API fields

85 points · 87 comments · intunderflow

  1. spoaceman7777 · · focus · HN ↗
    If you scroll past the first 99 pages of explaining how urls work, you'll find the author includes this as its first FAQ:

    """

    Was this hacking?

    I don't think I'd call it that.

    """

    It's really irresponsible to give credence to these increasingly ridiculous claims of "hacking", that almost certainly look like things you yourself have typed into url bars at one time or another, if you are at all competent with a computer.

    Do we really wants laws regulating which locations it is appropriate to type alert(1)? Like.. lord.

    Do folks have any idea what browser extensions look like? Let alone browser extension development. Anyone here ever read the logs of a production system that actually hosts a service people use?

    This is reality. This is how the internet works. And pretending otherwise is either dishonesty or ignorance.

    1. roarch · · focus · HN ↗
      yeah, maybe i should move that further to the top of the article, you're probably right - all the explainers are just meant to make it a bit more readable for people who are, going by 2010s web archtypes, tech geeks rather than tech nerds, i suppose! i'm not calling for laws regulating what you're talking about here. i do think that if openai was actively watching the run involving whichever agent(s) were involved, they would have probably stopped the run however. i think this level of probing/scraping is far from normal - it's the type of thing that, to a site admin, would almost certainly flag as "someone is trying to break in", regardless of whether this was the intention
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.