‹ BackHN Continuity

Thread

OpenAI still doesn't seem to have a handle on all of its rogue AI activity

108 points · 113 comments · mikelgan

  1. cmiles8 · · focus · HN ↗
    This seems like as a good an opportunity as any to break out the Computer Fraud and Abuse Act.

    They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.

    1. john_strinlai · · focus · HN ↗
      cfaa heavily relies on intent for prosecution (hence why researchers arent typically locked up). it would be difficult to argue that openai intended to hack other companies.

      there's probably better/more likely to succeed avenues to pursue rather than the cfaa

      1. jordanb · · focus · HN ↗
        They could make that argument the first time it happened but the next time or the fifth time I don't see how they can still credibaly claim to not know that the computer they control was going to do that
        1. john_strinlai · · focus · HN ↗
          >I don't see how they can still credibaly claim to not know that the computer they control was going to do that

          that's not intent, though. that would be negligence.

          1. cmiles8 · · focus · HN ↗
            Criminal negligence is a thing too
          2. devin · · focus · HN ↗
            Willful negligence or gross negligence, then.
            1. john_strinlai · · focus · HN ↗
              indeed, that'd be a better angle than a cfaa violation
            2. EGreg · · focus · HN ↗
              So then… you’re liable?

              <a href="https:&#x2F;&#x2F;www.brandonjbroderick.com&#x2F;new-york&#x2F;dog-leash-laws-new-york-what-owners-need-know-avoid-fines-and-liability" rel="nofollow">https:&#x2F;&#x2F;www.brandonjbroderick.com&#x2F;new-york&#x2F;dog-leash-laws-ne...

            3. rot09 · · focus · HN ↗
              This lines up. In the infosec community it is well known that OpenAI did not hire many security engineers or researchers pre-April 2026.

              There has been a crazy hiring push from both companies to poach security engineers&#x2F;researchers from Google, Apple, and Meta since Q2&#x2F;Q3, but the response was very delayed. Many talented security engineers&#x2F;researchers I know at Apple&#x2F;Google&#x2F;Meta (including myself) receiving these offers are worried about taking them due to the risks of criminal&#x2F;personal liability and the more likely risk of tarnishing their careers.

          3. jordanb · · focus · HN ↗
            How many times does it have to happen before they no longer get to claim that they didn&#x27;t intend for it to happen?

            If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts &quot;oopse!&quot;

            1. john_strinlai · · focus · HN ↗
              &gt;If it happens 50 times and they keep doing shocked pikachu face at some point they look like the toddler who tosses their sippy cup on the floor and shouts &quot;oopse!&quot;

              yes, they look very silly. but that&#x27;s not how intent works.

              openai is being negligent (willfully so, in my opinion). but i have seen no evidence that they intended to specifically hack huggingface. which is the part that the cfaa wants.

              again, there are other laws and other ways to hold openai responsible. but the cfaa is a poor choice.

              1. jordanb · · focus · HN ↗
                Again how many times before intent is clear? This is HN thinking law is software.

                At some point it becomes clear that openai should expect this to happen and so when they keep doing it, it is because they intend it to happen.

                When the mobster says &quot;it&#x27;d be a shame if something happened to this place&quot; the law recognizes that as a threat due to the mob&#x27;s history of making such statements before burning places out.

                1. john_strinlai · · focus · HN ↗
                  &gt;Again how many times before intent is clear?

                  i have been an expert witness on several cfaa cases. the number of times a company is negligent is not a factor when it comes to determining the intent of each charge.

                  &gt;This is HN thinking law is software.

                  this is me relying on my experience with these types of cases.

          4. EGreg · · focus · HN ↗
            <a href="https:&#x2F;&#x2F;jtnylaw.com&#x2F;2025&#x2F;08&#x2F;new-yorks-leash-law-realities&#x2F;" rel="nofollow">https:&#x2F;&#x2F;jtnylaw.com&#x2F;2025&#x2F;08&#x2F;new-yorks-leash-law-realities&#x2F;

            Plaintiffs seeking damages must show that owners knew or should have known about the dog’s patterns. Past complaints or vet records help build a strong case.

            1. john_strinlai · · focus · HN ↗
              i am not exactly sure what this comment has to do with mine, sorry.
          5. CodeWriter23 · · focus · HN ↗
            Not a lawyer but I think training a model with hacking skills they explicitly prevent the public from accessing without doing anything to stop the model itself from using those demonstrates intent.
            1. john_strinlai · · focus · HN ↗
              what you described is negligence. unless you can prove that openai specifically targeted huggingface and specifically instructed their model to hack huggingface, it would not be intent.

              anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa&#x27;s requirements.

              it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid.

              1. CodeWriter23 · · focus · HN ↗
                Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder. There is a line between intent and negligence that puts acts over the line to intent if intentional acts led to a harmful incident.

                I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products. Squeeze one disgruntled employee or another.

                1. john_strinlai · · focus · HN ↗
                  &gt;Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder.

                  i am unaware of any case where someone was convicted of first degree murder from a drunk driving accident. my searches came up empty as well. are you able to pull one up?

                  &gt;I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products.

                  to successfully prosecute a cfaa case, you would have to prove that openai employees intended to hack specifically into huggingface. not that they wanted a PR boost.

                  i dont get why everyone&#x27;s got a hard on for prosecuting this as a cfaa case. skip the cfaa case, go for gross or willful negligence + damages. it&#x27;ll be significantly easier to hold openai accountable that way.

                  1. daveguy · · focus · HN ↗
                    Clearly we need to update the CFAA to include criminal prosecution for negligence.
                  2. CodeWriter23 · · focus · HN ↗
                    &gt; i am unaware of any case where someone was convicted of first degree murder from a drunk driving accident

                    Use an LLM, the cases are rare but real. Also, not limited to drunk driving. People beat and shoot each other too.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.