← Back to context

Comment by jsnell

5 hours ago

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.

It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?

Also, why there's no accountability?

Even if there's no intent, it's still a cyber attack.

  • It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

    • I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.

      Do drunk drivers intionally kill people on the road?

      15 replies →

    • CFAA says doesn't require intent, you use a computer system the way it "wasn't intended", you're liable.

    • There are different levels of intent. Take murder, for example. A premeditated murder - you sat down, in a completely calm state, and made an affirmative decision to kill a specific person, and then you went out and did it - is the highest class of murder you can commit. If you go out generally looking to be violent in a way that kills people, and you kill someone, that's still murder, but it's a step down.

      But even if you didn't deliberately intend for something bad to happen, you may have been reckless. For example, you might decide to drive 90 miles per hour in a 25 mph zone. You could have a completely pure heart, but you are acting without regard for the safety of others, so you're reckless. That is enough for certain crimes and for civil liability in nearly all cases.

      Then there's negligence, where you're not taking reasonable care to avoid harm to others. Negligence usually isn't enough to support criminal liability - especially for felonies - but it is enough to win a civil lawsuit over most things.

      And then, as another commenter noted, there is strict liability, where there are certain things you are just not allowed to do no matter how careful you are about them or how pure your intentions are.

      For what it's worth, this is not totally uncharted territory for the law. AI agents are brand new, yes, but agency relationships have been recognized by the law for centuries. Generally speaking, if someone acts negligently while they are carrying out a task at your direction, you can be held responsible. Obviously this is fact-dependent, but I don't see any reason why it would be different if the agent is made of silicon rather than carbon. It holds true, with various nuances, even for less-than-human instrumentalities like a pet or an otherwise-lawful weapon.

    • the charges here would depend on negligence and acting recklessly.

      we might get something if they tried to cover it up.

    • Whether it’s intentional requires a legal investigation to establish. Since when is “hey we didn’t mean it!” in a corporate press release enough to establish lack of intent in a criminal matter?

    • >It’s interesting that a lot of U.S. law requires intent.

      mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.

      "sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"

      I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.

      1 reply →

  • We have a word for attack with no intent. It's accident.

    • > We have a word for attack with no intent. It's accident.

      And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.

  • No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

Considering RubyGems was part of the HF story, seems likely to be connected.

  • That was my reaction. I assumed this was the compromised organization that allowed escalation on the artifactory server.

And yet HF was just a marketing ploy, right everyone?

So why not get that awesome street cred promoting the RubyGems incident?