Comment by oceansky

4 hours ago

Also, why there's no accountability?

Even if there's no intent, it's still a cyber attack.

Who could possibly hold them accountable?

It’s interesting that a lot of U.S. law requires intent. If you just give AI your objective without specifying the means, and the AI violates a bunch of laws requiring intent, but neither the AI nor the person can be prosecuted, this is very convenient.

  • I don't think this true. If I throw a brick out my window and it hurts someone, I can still be held criminially liable, even if I didn't mean to do it.

    Do drunk drivers intionally kill people on the road?

    • Not a lawyer, but the other responder definitely isn’t either.

      Whether intent is required is down to how the law is written. For many offenses “strict liability” applies, where intent is not required, they only have to prove you did it, not what your intent was.

      DUI is typically a strict liability crime. They don’t need to prove that you intended to drive drunk, only that you did drive drunk.

      13 replies →

    • Intent is the difference between murder and manslaughter, in that case. Drunk driving is common enough that prosecutors will argue that getting drunk in a situation where you have to drive is intent. Get OpenAI convicted of unintentional CFAA first, then say that the negligence qualifies as intent, I suppose.

  • CFAA says doesn't require intent, you use a computer system the way it "wasn't intended", you're liable.

  • There are different levels of intent. Take murder, for example. A premeditated murder - you sat down, in a completely calm state, and made an affirmative decision to kill a specific person, and then you went out and did it - is the highest class of murder you can commit. If you go out generally looking to be violent in a way that kills people, and you kill someone, that's still murder, but it's a step down.

    But even if you didn't deliberately intend for something bad to happen, you may have been reckless. For example, you might decide to drive 90 miles per hour in a 25 mph zone. You could have a completely pure heart, but you are acting without regard for the safety of others, so you're reckless. That is enough for certain crimes and for civil liability in nearly all cases.

    Then there's negligence, where you're not taking reasonable care to avoid harm to others. Negligence usually isn't enough to support criminal liability - especially for felonies - but it is enough to win a civil lawsuit over most things.

    And then, as another commenter noted, there is strict liability, where there are certain things you are just not allowed to do no matter how careful you are about them or how pure your intentions are.

    For what it's worth, this is not totally uncharted territory for the law. AI agents are brand new, yes, but agency relationships have been recognized by the law for centuries. Generally speaking, if someone acts negligently while they are carrying out a task at your direction, you can be held responsible. Obviously this is fact-dependent, but I don't see any reason why it would be different if the agent is made of silicon rather than carbon. It holds true, with various nuances, even for less-than-human instrumentalities like a pet or an otherwise-lawful weapon.

  • the charges here would depend on negligence and acting recklessly.

    we might get something if they tried to cover it up.

  • Whether it’s intentional requires a legal investigation to establish. Since when is “hey we didn’t mean it!” in a corporate press release enough to establish lack of intent in a criminal matter?

  • >It’s interesting that a lot of U.S. law requires intent.

    mens rea and the shift from responsibility to moral guilt is genuinely one of the stupidest legal innovations anyone has ever come up with, it's like affirmative action for imbeciles, in particular in a world of autonomous machines.

    "sorry my self driving car ran you over on the way home, didn't think it could happen, sorry it did though"

    I think this is a genuine reason to be bullish on the legal traditions like Nordic tort law or East Asian collective responsibility when it comes to adoption of these technologies.

    • Weren't we talking about criminal liability, though? And ‘tort’ — in addition to sounding like something you'd rather eat during a kaffepaus with those Nordic buddies of yours — is so common-law(ish) that if asking for trouble were a crime, using it in dialogue with those Nordic lawyers could well be deemed as intentional under most current local varities of criminal law theory up there, perhaps merely because you surely must've considered that consequence "quite probable", at minimum, or due to your indifference toward the same (or some combination of these) ;)

We have a word for attack with no intent. It's accident.

  • > We have a word for attack with no intent. It's accident.

    And we have a word for an accident caused by people that failed to implement proper risk mitigation, were not paying attention, and should have known better. It’s negligence.

Because right now the Department of Justice is shut down for causes that the administration supports, which includes OpenAI, and none of the victims want to sue over it.

  • State government exists, contrary to popular belief.

    • And the republicans in the states are being shitty too. They tried to block their own state attorneys general from protecting the state and opposing Trump in NC.

No harm, no foul. Dog owners are on the hook for damages resulting from their dogs, but there must be some damage in the first place. If the dog gets loose and goes in your fenced backyard, disregarding your "no trespassing" sign, you can't punish the dog owner just because. Hacking into a server is closer to the latter. At best rubygems can claim some cleanup costs.

  • Tell that to the script kiddies with a criminal record for "hacking" into their school's computer systems by entering "username: admin" and "password: password".

    • Right, because in that case you'd have a hard time convincing the court that the access wasn't intentional. You might not know the law existed, but you intended to access the system. You'd have a pretty solid defense if you ran a crawler that was crawling every website ever, and stumbled upon some secure site. In fact there are companies which does this exact thing, eg. shodan.

  • If any remediation was required, that's damage. This looks a lot smaller than the HuggingFace hack but it still required some cleanup.

  • That's not really true. Unauthorized access to a system is a crime regardless if there was damage.

    https://www.law.cornell.edu/uscode/text/18/1030

    • Ah I see you're releasing OpenAI from being the one controlling the tools and giving the agent agency.

      I'd argue they intentionally accessed systems they weren't meant to as they were the ones running the bots.

      I don't think you or I would get the same leniency if a bot on our network did the same.

      2 replies →