Comment by gitonup

19 hours ago

> If you don't want to suffer from it, you're going to have to find much better defense measures.

So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.

  > So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You're still left with many entities from states to hobbists trying to crack your system after they've gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.

I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.

  • > I appreciate when white hats inform companies, governments, and the public about their successful exploits.

    Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.

    • So what? OpenAI may be a problem, but the security of a government website rests on the administrators of that government website. Not on attackers playing nice.

> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

I'm not the person you're responding to, but...

If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.

1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...

  • If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?

    • It's more like there are two locksmiths who try to open any door when someone pays them. Should we make them check if the person calling them is the home owner?

      Yes, but it needs to be done the right way so legit customers don't get rejected, and you can't do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.

      And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.

      1 reply →

    • If I found out this metaphor for neighborhood windows was actually a window into massive amounts of institutional data, then no, I don't want someone to talk me out of getting more security on my kitchen window.

      1 reply →

  • I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."

    But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?

    ETA: and furthermore, what crime is worse? And should it be?

He probably cares more about still having a laptop.

What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.

  • Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.

    However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.

    Truly no place I'd rather be.

  • This is what the politician in question said:

    "The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."

    Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.

    That is what I'm getting at.

OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.

While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?

The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.

  • In the OAI case where we can easily treat it as a law enforcement action, that's a far cry from "who cares who's liable." If the OAI case can be a law enforcement action, we're on the same page. The fact that sovereign nations don't land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I'm commenting on.

    • Again, it's a split horizon.

      Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.

      The thing is this has zero effective power in stopping this ball that is all ready rolling. It's like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he's yelling full steam ahead, so expect very little to no action by the US government on this.

  • I simply find it completely absurd that instead of finding it great that these AI agents are finding security bugs for free, people are whining about banning the AI. What on earth is that even? What do they want then? Security by obscurity and pretending not to care about weaknesses?

  • I don't disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?

    • > how many actors have access to resources like that

      Every nation on earth?

      After the model itself is made, then you're talking about thousands and thousands of different companies around the world.

      2 replies →