Comment by kadoban
16 hours ago
> I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.
They didn't break in. They found a key that their neighbor dropped and returned it.
> Is this legal?
Generally, yes (though ask a lawyer if you're going to do security work). Security researchers do occasionally get legal flak though, depending on which idiot they annoy by pointing out issues.
IAAL (not legal advice, consult a lawyer in your jurisdiction). You really do not want to pen-test a target without their permission. If you're identified as a culprit, the Feds will shove the CFAA so far up your ass you'll need a proctologist.
as a lawyer, can you speculate as to why anthropic/openai aren't facing many or any consequences for their agents? I'm not asking in a "grab the pitchforks" way. more out of genuine curiosity as my uninformed recollection of the CFAA is as you describe it.
The 9th Circuit Court of appeals recently published this that is somewhat related (Amazon v. Perplexity): https://cases.justia.com/federal/appellate-courts/ca9/26-144...
Look at pages 10-17 to see how the law is evolving here.
5 replies →
There is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes.
The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission).
Anthropic/OpenAI can reasonably claim that they had no intent and are trying to stop it. OP here did this explicitly and purposely.
2 replies →
> They didn't break in. They found a key that their neighbor dropped and returned it.
Ya, returned it after poking through all of the drawers and iterating through business information that they found.
There is a white-hat line that OP very clearly crossed here.