Top
Best
New

Posted by gregnavis 6 hours ago

OpenAI bots knew about the RubyGems caching vulnerability(tenderlovemaking.com)
210 points | 211 comments
firesteelrain 22 minutes ago|
> If you have YARD installed, and you install this gem, then YARD will load and run whatever is in ./script.rb from inside the gem.

How is that not a security issue in of itself?

VyseofArcadia 5 hours ago||
How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Xirdus 5 hours ago||
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
stronglikedan 2 hours ago|||
There have been news stories where individual OpenAI users have been investigated based on their prompts. If OpenAI can point the police to specific users of their software, they can certainly point them to whichever of their own employees are involved in a crime. AI is just a tool, and the person prompting it is the one responsible for the outcome. No dilution there.
VyseofArcadia 5 hours ago||||
Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI?

Sorry if it is a stupid question, as mentioned above I am legally naïve.

elmo2you 8 minutes ago|||
As far as I know (IANAL) it is in fact the only "person" you can charge. To the best of my knowledge, the whole point these "limited liability" legal constructions exist in the first place, is to protect individuals within a corporation for whatever they do as part of the business of a company (barring exceptions that have clearly not been part of that business and obvious individually committed crimes), typically "just following orders". If a company commits a crime, or in a worse case runs a criminal enterprise, it is the company that is legally responsible, not its employees. That is, in principle.

This can get more complicated higher up the management tree, where decisions can also be prosecuted on personal little, but that's usually a far more complicated matter. Also, if a whole group of employees willingly conspires to commit crimes, they might also be prosecuted individually for those crimes (there are limits to limited liabilities). However, that usually only works under special conditions and it would e.g. require that there's an obvious criminal enterprise aspect to it, rather than individual cases of illegal conduct.

That said, with the track record of some of these companies, actually designating some of the AI companies as a criminal enterprises may eventually happen (in due time) in some jurisdictions outside the USA. Certainly if it ever turns out that these companies have been storing and (ab)using everything they ever had access too, while blatantly lying about that just because some particular (post 9/11) US laws gives them that opportunity (and impunity) as long as the US government somehow requested them to do so (covertly; with gag order). Might legally work withing US jurisdiction, but would still be very much illegal everywhere else.

yonatan8070 5 hours ago||||
I, too, have no idea about legal matters.

But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.

I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.

godelski 23 minutes ago||
Let's take a hypothetical example:

Suppose you're a firework company and your fireworks blow up, burning down the entire town. Could the company be sued? What is considered reasonable safety measures?

IANAL, but I'm pretty confident there would be a lawsuit. Who gets charged might differ, depending if it is the firework factory that didn't take adequate safety precautions or a chemical supplier or someone else. If there wasn't an ability to sue that would be fucking crazy and we should all get up in arms about it. And isn't insurance supposed to be there to help mitigate the damages, regardless of fault?

Personally, given how it seems OAI's agents have been getting through either pretty obvious places (e.g. /etc/hosts) or that there wasn't close monitoring of the most obvious places (e.g. DNS, artifactory), I'd imagine it wouldn't be hard to find them negligent. Even if a single employee is to blame then are they not to blame for not monitoring the agents regardless? Unless the story is that the employee intentionally circumvented defenses (why?) then it seems it would be on OAI. But again, IANAL, I'm just someone who think if we can't sue we can sure riot until we can

zdragnar 10 minutes ago||
There's a difference between being able to be successfully sued (civil liability, petitioned by a private entity) and charged (criminal liability, or petitioned by a government entity).

The thresholds for suing and charging differ greatly depending on the circumstances.

Another set of hypothetical examples that make things muddier:

- If I drive a fishing boat into a pier, I am liable, not the manufacturer of the boat

- If I drive a car over someone lying in the road, I am liable, not the manufacturer of the car

- If my life is in danger and I shoot a gun and kill my attacker, neither I nor the manufacturer are liable so long as I obeyed the relevant self defense laws and gun possession of whatever jurisdiction I am in

- If I fire a gun into a crowd indiscriminately, I am liable and several jurisdictions have used that to also hold gun manufacturer liable as well

That last example has been less successful as of late, but there are other variations too.

colechristensen 5 hours ago|||
The same concept that allows a corporation to sue and be sued allows it to be charged with crimes
brookst 5 hours ago||
Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.
VyseofArcadia 4 hours ago||
That may be true by the text of the law but there are plenty of individuals who have been sued or charged with crimes for accidental hacking.

https://arstechnica.com/information-technology/2016/05/armed...

https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb...

So what's the deal with these?

colechristensen 3 hours ago||
>Eaglesoft

CFAA: Intentionally accessing poorly secured data

>AT&T

CFAA: Intentionally accessing poorly secured data

>DJI

Civil suit for violating terms of license agreement

j2kun 37 minutes ago||||
Sounds like we need discovery to determine who to charge.
immibis2 1 hour ago||||
It doesn't need to be twisted to violate the DMCA anticircumvention clause because it is already just plain old hacking.
bix6 5 hours ago||||
How is the responsibility diluted? Charge the CEO…
brookst 5 hours ago||
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction.

Do you think there is evidence of this?

shakna 4 hours ago|||
> There are no negligent or stochastic hacking laws

I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".

You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count.

> knowingly accesses a computer without authorization or exceeds authorized access [1]

"Knowingly", not "intentionally", as in the other counts.

You only have to show that:

a) They trained a system to access without authorization (hacking)

b) The system that was trained exceeded authorized access

As responsibility falls to the operator with automated systems, the company becomes liable.

[0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res...

[1] https://www.energy.gov/sites/prod/files/cioprod/documents/Co...

nicce 1 hour ago||||
That is not how it works, at least in a civilized country. The charges are not about agents, it is about operational responsibility and negligence in the company itself.

CEO is responsible for letting this to happen, not enforcing enough supervision, if not intentionally, then being grossly negligent. More severe if encouraging and letting this kind of agent research and operations happen at scale, while knowing that it can damage other systems and businesses.

hallway_monitor 2 hours ago||||
So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.
Octoth0rpe 2 hours ago||
> There needs to be a single wringable neck.

Does there? Could be the whole c-suite/board.

ryandrake 1 hour ago|||
I'd settle for any number of necks. Currently, when a corporation fucks something up, breaks the law, or hurts or even kills people, there aren't consequences besides a tiny token fine and a strongly worded letter telling them to not do it again or they'll get another tiny fine and letter, and their CEO might even have to sit down in front of Congress to say a few words and look sad.
embedding-shape 1 hour ago|||
Whatever is easiest to legislate and most people agree on, as long as there is at least one wringable neck.
VyseofArcadia 5 hours ago||||
It would seem to me that the difference between the corporate world and organized crime is that a corporation can get away with, "the responsibility is too diffuse" but the mafia at least has to go to the trouble of finding a fall guy.
bix6 5 hours ago|||
Honestly yeah I bet there is and I hope to someday read about it if the government ever gets off its ass. Someone set up the “experiment”…
oliwarner 4 hours ago||||
A copyright law seems an odd place to start. This is computer misuse.
VyseofArcadia 4 hours ago||
The DMCA is a bit overly broad to be considered just a copyright law. For example, just breaking encryption on a DVD is technically illegal regardless of whether you then go on to do something otherwise illegal (make and sell bootlegs) or perfectly legal (make a space-shifted backup copy on your hard drive).

IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. They had to find a way to make doing the same with DVDs illegal.

oliwarner 3 hours ago||
Those provisions are specifically for the breaking or circumvention of technical measures designed to prevent copyright infringement.

I don't see a parallel here.

immibis2 1 hour ago||
They've been twisted to support almost anything, for example repairing your tractor is illegal because of this same law. But I agree this is just plain old hacking under a plain old reading of the CFAA and doesn't need any twists.
EMIRELADERO 11 minutes ago||
> for example repairing your tractor is illegal because of this same law.

No it's not. There has never been a case establishing that, and it's absurd on its face. The protection measures that the law makes illegal to break must control access to a copyrighted work, and you can't copyright functionality.

woah 2 hours ago|||
Issuing subpeonas, raiding offices, and dragging key employees into interrogation rooms as you would find in any normal criminal investigation would be more than enough to ensure "AI safety" without any new regulations, acts of congress, Bernie Sanders campaign speeches, or even charges filed.
Betelbuddy 2 hours ago|||
Any future computer criminal from now on, has their defense cutout for them...The AI Agents did it...we are very sorry...
ks2048 2 hours ago||
No. They don't say "sorry". They say - our technology is just that powerful - please consider that in next funding round.
skybrian 1 hour ago|||
Maybe, but do you need to prove intent? Of the people, not the AI.

Accidents often have penalties associated with them too, but usually there's a difference between accidents and purposeful actions.

gowld 1 hour ago|||
Criminal law may be lagging or inapplicable. (Crimes require "mens rea", a "guilty mind")

Tort law is very general: Contribute toward harming someone -> civil suit for damages $$$

shevy-java 36 minutes ago|||
They are too busy pulling Andre to court, so they have no resources going against OpenAI. Shopify wants to make profit, not waste time in a court case against TechBro bromance brother corporations.
tekla 5 hours ago|||
Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title.

I'm going to assume that this will never happen

simonwsimonwsim 5 hours ago|||
[dead]
howitworkslegal 4 hours ago||
[dead]
HelloUsername 5 hours ago||
Related

"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099

"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments

"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590

thomasjeff1 39 minutes ago||
Great time to be a criminal. Just have your bots do it.
senda 5 hours ago||
Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents?

Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

herculity275 5 hours ago||
I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.
sajithdilshan 1 hour ago||
How? Aren't all US frontier models ban the usage of AI for military purpose by parties other than US? I remember Anthropic even refusing allowing US government to use Claude for military purpose
TGower 1 hour ago||
Kimi / open models or jailbreaking frontier models. Your recollection of the Anthropic refusal isn't quite accurate, cyber hacking wasn't a sticking point, just domestic drag net surveillance and fully automated weaponry.
heaney-555 5 hours ago|||
These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled.

Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all.

As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign compute capacity.

valleyer 5 hours ago||
Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.
abathologist 54 minutes ago|||
I appreciate this line of questioning. It's really interesting to see how many excuses people need to reach for to avoid the conclusion that the "secret unheard of power" is B.S...
joinjune 5 hours ago||||
Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those.
senda 5 hours ago|||
The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available.

I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be littered Ai con-artists.

I'm just wondering, again, is this mostly bullshit?

fragmede 1 hour ago||
Why do you think they're not, and why do you think Russia cares about Reddit?
senda 22 seconds ago||
It’s an example of potential use by bad actors.
dgellow 5 hours ago|||
They don’t need to run their own DCs, just pay for a proxy somewhere in the world that has better access to the infrastructure. We know North Korea has been doing that in the US since years now
mcmcmc 5 hours ago|||
Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them
nradov 5 hours ago||
Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.
mcmcmc 5 hours ago||
And which of these neutral countries have the capacity to serve them and the lack of awareness that hosting an offensive Russian agent swarm would bring hell back to their doorstep? Best they can do right now is rented botnets
dgellow 5 hours ago|||
They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet
senda 5 hours ago||
I think this fails a lot of logical tests, it should be apparent in day to day life.
dgellow 4 hours ago|||
> In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center […], and which were used as "criminal proxies" and used spear-phishing schemes to target Russians living in the United States, nongovernmental organizations (NGOs), think tanks, and journalists according to Microsoft and United States State Department, Department of Energy, and Department of Defense officials, United States defense contractors, and former employees of the United States intelligence community according to the FBI. In some cases, the hackers were successful in obtaining information relating to nuclear energy-related research, United States foreign affairs and United States defense. According to Microsoft's Digital Crimes Unit from January 2023 to August 2024, Star Blizzard targeted more than 30 different groups and at least 82 Microsoft customers which is "a rate of approximately one attack per week."

https://en.wikipedia.org/wiki/Cyberwarfare_by_Russia

That’s just one thing that has been found. Are you actually familiar with the state of cyberwarfare and are you following its evolution? Because if not you won’t be aware of most of what is identified. And only a small portion of the ongoing attacks are identified.

senda 4 hours ago||
Yes.

I again am just shocked the sky is not falling, when thats the sales pitch.

lirolero 4 hours ago|||
[dead]
marginalia_nu 5 hours ago|||
Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities.
lenerdenator 5 hours ago||
He did not fall out of a window.

He fell out of the sky. After his plane exploded. Happens all the time. Is tragedy.

marginalia_nu 3 hours ago||
I was alluding to how people who fall out of favor with Putin have a tendency to have mysterious fatal accidents, more than 10 of them falling out of windows.
_verandaguy 59 minutes ago||
Sure, but it was unfortunate to pick the one dude who is well known, if for nothing else, for dying through means other than defenestration.
tokai 5 hours ago|||
Because they dont have the money for hardware or compute obviously.
micromacrofoot 5 hours ago|||
what do you mean? they're using AI to kill people directly in Ukraine

https://www.nytimes.com/2026/08/24/world/europe/russia-drone...

ur-whale 5 hours ago||
> How are we not seeing insane attacks on Ukraine via Agents?

You live on the wrong side of the fence to be able to read that kind of news.

Did you really believe you had access to an unmanipulated news stream in a time of war?

LOL.

senda 5 hours ago||
Please see other responses, I would expect to feel the effects not just read about.
tancop 1 hour ago||
Build scripts being able to run arbitrary code or access the network is always dangerous even if it was just local on developer machines. It's also more evidence that Docker/LXC is not a security boundary and all untrusted code should run in a Firecracker VM.

The problem with agents is not that we don't know how to defend. It's that defenders need to be more careful and work faster than ever. We can say now that wide scoped tokens should have been retired for years and it's all RubyGems fault but the reality is a lot of organization are not prepared for this.

Even if they take security seriously they don't have enough manpower or a good strategy to implement it, and sometimes you have no idea that something is a problem because it wasn't a problem for years.

oezi 2 hours ago||
What a time to be alive until the next agent waves hacks something really serious.

What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute.

It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?

motoboi 22 minutes ago||
I suppose you are not think big (or internet) enough.

A single data center is easy to solve. Just unplug it.

What about a botnet with decentralized command and control that we will never be able to eradicate? One with so many nodes and able to hack with zero days so that any machine connected to the internet will be instantly attacked?

One botnet so powerful that we will try to build another internet so that we can actually use it again.

It’s like Kessler Syndrome, but the rocks are malicious network packets honed to exploit the recipients.

stephbook 8 minutes ago||
Just let them communicate on the Bitcoin blockchain. "We" would have to freeze the chain and lose access to "our" billions of wealth, so not going to happen.

Sorry if that turns out the way they kill us.

tonyedgecombe 1 hour ago||
If it could upload its weights to other servers then it’s away and free. Nothing much OpenAI could do about that once it’s happened.
renjimen 1 hour ago||
I'm increasingly starting to think this is the end-state of AI. The internet becomes infected and fundamentally untrustworthy.

At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment becomes questionable.

timdiggerm 5 hours ago||
We need a legal structure to make companies liable for the actions of the agents they've made.
riskable 5 hours ago||
We already have it.

Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies.

It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

Schlagbohrer 4 hours ago|||
You may be disappointed in how little a democrat president (who will also have taken billions of dollars from the tech lobby) will be willing to go after these tech firms over crimes that are several years old (as of 2029) much less contemporary bad behavior.
2OEH8eoCRo0 5 hours ago|||
"To my friends, everything; to my enemies, the law"
kevincox 5 hours ago|||
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
immibis2 1 hour ago|||
It shouldn't actually take that much bravery. If your case isn't completely frivolous, isn't your maximum loss limited to the court filing fees and a lawyer payment that you know in advance and can decide when to stop paying? It's not the same as getting sued.
masfuerte 5 hours ago||||
If it's covered by criminal law they don't need to sue. They can call the FBI.
Schlagbohrer 4 hours ago||
Same FBI that prosecuted the Epstein crime ring so aggressively!
coffeefirst 5 hours ago|||
Uh huh.

It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact.

Had this gone after a bank or a government agency someone would be going to jail.

ahoka 5 hours ago|||
I'm pretty sure it's already illegal to hack others.
netdevphoenix 4 hours ago|||
Agent technology labs are likely exempted of this due to the significance ascribed to their work.
kstrauser 5 hours ago||
Ah, the infamous Crimson Wave.
PyWoody 1 hour ago||
If anyone is confused about this comment and similar others, the original title had "rouge Agent" instead of "rogue Agent."
riskable 5 hours ago||
Ah damnit, you beat me to it. Excellent sense of humor, friend :D
swiftcoder 5 hours ago|
> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info.

Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.

evgenysokov 4 hours ago||
The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access
swiftcoder 4 hours ago|||
Presumably the docker container has network access because something else in the build system requires it? I don't think sandboxing the entire build process is the right level of granularity here - one ideally wants to be able sandbox each package's build scripts individually.
chrisjj 2 hours ago|||
So, not a sandbox then.
citizen204 1 hour ago||
[flagged]
More comments...