Top
Best
New

Posted by gregnavis 7 hours ago

OpenAI bots knew about the RubyGems caching vulnerability(tenderlovemaking.com)
239 points | 216 commentspage 3
mococa 2 hours ago|
It was the gremlins
philipwhiuk 6 hours ago||
OpenAI's careless approach to sandboxing and minimal levels of monitoring appear to be positioning it increasingly as a substantial threat actor to the open source ecosystem:

* Hugging Face

* D Programming Language Wiki

* Ruby Gems

If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.

GaryBluto 2 hours ago|
>I'd be looking pre-emptively block OpenAI endpoints

From what I've seen the requests in these attacks rarely come from known OpenAI IPs and instead from Digital Ocean/AWS and TOR exit nodes.

HSO 6 hours ago||
rouge agents, on tenderlovemaking.com

my what a time to be alive

Schlagbohrer 6 hours ago|
<huggingface emoji>
Ydarbleoj 4 hours ago||
I wonder why we don't hear of other frontier labs experiencing these "break outs".

Is it that they're orchestrated? Do these labs lack fundamental safety guidelines in their sandboxes as opposed to their peers? Is it another version of hype-filled fear mongering?

Maybe LLM companies need regulation but it's becoming obvious that those screaming the loudest for it are the only ones I see deserving of it.

GaryBluto 6 hours ago||
I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.
brookst 6 hours ago|
Any evidence, or just vibes?
GaryBluto 6 hours ago|||
Regarding what point? The entire thing is just a theory, but regarding the occasional OpenAI checks on WikiService.at-hosted Wikis targeted, there was, if I remember correctly, an OpenAI IP popping up every now and then that wasn't an agent. Unfortunately I don't have it to hand right now, but it was somewhere here:

https://news.ycombinator.com/item?id=49563355

ur-whale 6 hours ago|||
> Any evidence

Who profits from the crime?

davsti4 6 hours ago||
... and what harms can be evidently shown? With both harm, and attribution, you have a case, something that's not being publicly discussed much among big media outlets. Until cases with real financial impact to the bottom line are brought against "rogue" organizations, this stuff is going to continue getting worse.
Roark66 7 hours ago||
There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems".

In short, it was intentional.

AndrewSChapman 5 hours ago||
Agreed. LLMs do not have 'will', 'desire' or emotions. They have an objective, and they create an optimal path to achieve that objective.

You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?"

Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.

empath75 3 hours ago||
It was literally a prompt to fill in a spreadsheet with data that they didn't have access to, and they used rubygems as an internet proxy basically since they were sandboxed.
watwut 3 hours ago||
It was a model literally trained to hack. To be good at that. Doing an exploit gym from all of the things. And they trained it so that it performs as well as possible on that exploit gym thing.
Xirdus 7 hours ago|||
The big question is was this grossly negligent or just extremely careless.
rglover 7 hours ago|||
Both. This should result in criminal charges.
brookst 6 hours ago||
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
probably_wrong 6 hours ago|||
There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk".

https://www.law.cornell.edu/wex/reckless

rglover 6 hours ago||||
Whoever prompted the agent, whoever supplied the means, whoever knew but didn't say anything.
tacomagick 6 hours ago||
Also whoever monitoring these agents, in this case not monitoring. This "Who is responsible" dilemma is so stupid. If I gave the AI tool means to kill a person but I did not tell it directly to use it and it uses it anyway then I am responsible for it.
roosterIllusi0n 6 hours ago||||
The CEOs. They have full control and make all the decisions. Charging anyone else would not stop anything.
m4rtink 4 hours ago|||
Why not both? (all people involved)
chrisjj 6 hours ago|||
> The CEOs. They have full control

They lost control long ago.

esalman 6 hours ago||||
‘It wasn’t us, it was a bug in the software’ used to be the defense for bad code. Then it became the defense for self-driving cars. Now it’s being used for AI cyber attacks.
dismalaf 4 hours ago|||
[dead]
dgellow 6 hours ago||||
Both? I’m not sure what distinction you’re trying to make. It was completely irresponsible and likely a felony
trvz 6 hours ago||||
Don’t forget outright intentional.
nottorp 7 hours ago||||
Marketing actually.
tacomagick 6 hours ago||
AI is dropping out of the spotlight so they are using desperate measures like this.
nottorp 6 hours ago|||
No, I remember being threatened by OpenAI and then Anthropic (and now both) since back when ChatGPT was seriously useless.
anthonyrstevens 4 hours ago|||
>> AI is dropping out of the spotlight

spit take

roosterIllusi0n 6 hours ago||||
The big question is why are CEOs getting a legal pass when this kind of thing can be prosecuted. That's the problem here.
chrisjj 6 hours ago||
> why are CEOs getting a legal pass

https://www.bbc.co.uk/news/articles/c7v48vp31mdo

ljm 6 hours ago|||
AI is literally state sponsored so I don't see that happening unless the AI turns against the sponsor.

Wait until OpenAI or Anthropic exploit FAANG.

acaloiar 5 hours ago|||
I agree that this appears to be basic human behavior hiding behind an "agents" narrative. As long that defense works, the headline isn't "OpenAI performs RCE to scrape data", but "rogue agents" taking unilateral action. And I have strong doubts about that narrative.
ozgung 6 hours ago|||
Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process.

There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping.

CGamesPlay 6 hours ago|||
> There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping.

This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.

WarmWash 5 hours ago||
Intent is what is being discussed here though, not liability.

A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.

monkpit 4 hours ago|||
Intent might be what’s being discussed but intent is, for the most part, legally irrelevant. It might make the difference in the degree of a murder charge, or maybe manslaughter, or criminal negligence, but it doesn’t get you off the hook.
WarmWash 4 hours ago||
Correct, but the size difference of the hook can be so dramatic that you can't just hand wave it away.

The trainer who trained the lion to kill will probably be in jail for life. The one who happened to oversee a lion that went rouge would probably be given probation or something else that is a slap on the wrist.

infamouscow 5 hours ago|||
Except liability always precedes intent.
azakai 6 hours ago||||
Also, you have to have a lot of confidence in the reliability of these systems to say, "If only OpenAI prompted 'do not hack outside systems' then the agents would not have hacked outside systems".

It would be great if they were so reliable, but I don't think they are!

ssivark 4 hours ago||||
> Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process.

Who gives a shit? Not my circus; not my monkeys! It's the responsibility of whoever deploys the agents that they are instructed / sandboxed well enough that they can't cause collateral damage. That is the only way this doesn't get out of hand with everybody deploying their agents / robots for a world of utter chaos.

It is impossible (and asinine) to audit every model and deployment; far better to impose liability and the the socio-legal system figure it out.

WarmWash 6 hours ago|||
Nobody picks up pitchforks for rational nuanced takes.

Knee-jerk surface analyses is far more powerful.

dumberquestions 6 hours ago|||
>They were prompted to hack to get answers

Were they? I haven't seen a single report mention this

smcg 5 hours ago||
if they weren't, shouldn't there be lawsuits?
gibspaulding 6 hours ago|||
I think it can simultaneously be the case that OpenAI was grossly negligent in directly causing this AND that the AI’s ‘went rogue’ in that they are displaying behavior which is misaligned with OpenAI and humanity generally.

The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them.

AI is starting to feel like that line about magic: “a sword without a hilt”

stymaar 6 hours ago|||
> which is misaligned with OpenAI and humanity

OpenAI is itself misaligned with humanity, as their mishandling of such incidents (and the many other other issues their model have been causing) shows.

consp 6 hours ago|||
Doesn't rogue in this context imply "outside of set limitations"? And then not "failed to properly instruct"? The same applies to humans when given bad instructions.
codeduck 6 hours ago|||
nothing rouge either, I suspect.
RajT88 6 hours ago||
https://en.wikipedia.org/wiki/Going_Rouge
josebmneto 4 hours ago|||
Oh yeah, more of hacking agent lores...

Agreed that this looks very intention to me as well.

aftbit 6 hours ago|||
Proof that the AI alignment problem is hard (perhaps even unsolvable). These labs clearly did not mean to send their agents to hack RubyGems as a side-effect of testing a web scraping agent under restrictive conditions. How can we hope to build aligned AI if they consider solving their trivial evaluation task important enough to hack external systems?
srmatto 6 hours ago|||
Sounds more or less like the last breach then.
chrisjj 6 hours ago|||
Unrelible programs be unreliable. Period.
cyanydeez 6 hours ago|||
we have normal words for this stuff: negligence. You can add it on to almost any law.

The problem is consumer protection is basically no longer a part of america's regulatory system. Replaced by "grift is good".

flifenstein 4 hours ago||
[flagged]
herbst 6 hours ago||
If you have weapons and a child. And you have that child unsupervised do their own thing with theoretical access to your weapons. Would we call it "child going rouge" if it decides to play with the weapons and shoot someone?
dingdongditchme 3 hours ago||
Who the fuck is going to hold these AI companies responsible for running these gigantic semi-autonomous botnets on investors dime?
12904927 6 hours ago||
What a time to be alive? One of the most boring decades ever.

METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human.

Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants.

Why is Ruby Gems such a mess? It seems as bad as PyPI now.

Schlagbohrer 6 hours ago|
One agent set "oaibooty9217" as their username LOL
More comments...