‹ BackHN Continuity

Thread

OpenAI agents tried to bruteforce a UN website's API fields

85 points · 87 comments · intunderflow

  1. dmzxnico · · focus · HN ↗
    I think that they really should force AI Labs to publish what the agents do. All the industry can learn from it and protect against it.

    Im sure a lot more happens under the hood that we don't know about and I'd be very curious to see where agents ran by those labs can go :)

    1. roarch · · focus · HN ↗
      I wonder if there's something to be done on the end of companies that get hacked too. At the moment it seems very feasible that a company could get hacked by an AI company, and reach a mutually beneficial agreement where the AI company doesn't admit their agents hacked a thing and the compromised company doesn't have to admit that an autonomous frontier model can bypass their security. It's unclear whether the rubygems attack would have been discovered to be the result of OAI agents if not for rubygems announcing they got attacked in the first place, and I wonder how many more incidents have been found by defenders but not announced. wonder if there's room for some mandatory disclosure stuff there, but i'm not a lawyer and in practice i have no idea how that would work or whether it'd even be useful
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.