‹ BackHN Continuity

Thread

OpenAI agents tried to bruteforce a UN website's API fields

85 points · 87 comments · intunderflow

  1. cmiles8 · · focus · HN ↗
    The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
    1. petesergeant · · focus · HN ↗
      I'm glad we've moved past "this is all just marketing, there's no security risk!" phase
      1. Capricorn2481 · · focus · HN ↗
        Being cagey about their poorly setup sandbox is marketing. It gives the impression these are unstoppable juggernauts capable of outsmarting Engineers at the top of their field, implying they need to be regulated, with Altman the only one worthy of the seat of power.

        In reality, they ran agents for days in an improper sandbox with nobody watching what it was doing. It's pretty irresponsible up and down, and everything they did afterwards is indeed marketing.

        1. marcta · · focus · HN ↗
          > with Altman the only one worthy of the seat of power

          How does that make sense, if Altman is unable to control OpenAI's agents at the moment?

          1. Capricorn2481 · · focus · HN ↗
            Because Altman has been anointed by both the government and Microsoft, and he has been beating the drum that we need AI regulation for everyone except him for 3 years now.

            To any person with even a little tech literacy, it's clear a company this irresponsible shouldn't be the stewards of AI security. To the 80 year old congressman who confuse Facebook with Google during congressional hearings and are literally wheeled out to vote post-stroke, it's much more palatable to say "our experimental, supercharged AI (which you can use for war and surveillance) is so advanced it tricked all of us!" Nobody is going to actually punish them, even though they plainly are hacking other companies.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.