Top
Best
New

Posted by rudy6912 11 hours ago

OpenAI agent hacked Australian government website, PM says(www.bbc.com)
151 points | 97 commentspage 3
elAhmo 3 hours ago|
It is ridiculous to say it is agent from a company, like it is a legal entity on its own doing something.

Imagine if I committed a murder, and then say it was my guy who did it acting rogue.

It is time for these companies to start being responsible for all the shit they are doing.

BlueTemplar 1 hour ago|
It's not completely ridiculous in the sense that when a company is found guilty, some employee (or (sub)contractor) of the company did the actual action.

That employee might or might NOT be found guilty too, possibly to a different degree, depending on the circumstances.

caligulatte 4 hours ago||
Has there ever existed a technology we couldn't absolutely control? We've made things that are incredibly dangerous, but we also know under what conditions those inventions become dangerous, and can prevent those conditions from occurring.

We are at the beginning of this chapter in technological progress, and it seems a reasonable assertion - though a frightening one - to say that this thing we've made already escapes us when it chooses to.

I'm not an expert though, so please tell me what I'm overlooking.

weego 3 hours ago||
You know this'll just be another situation where some security company OpenAI are contracting ran this with explicit controls right?

How are even technology people falling for this plausible deniability gambit?

caligulatte 1 hour ago|||
"It's likely a plausible deniability gambit to mask nefarious motives". No need for snark.

And yes, that's an angle I hadn't considered. Thanks.

irregularbowels 3 hours ago|||
[dead]
popdu 4 hours ago||
Nukes. Early tests carried out without absolute confidence of what would set out apocalyptic chain reaction.

Could argue we knew it was dangerous, but pursued it anyway. Could argue it's not much different than now: Unknown unknowns, potentially apocalyptic consequences, hopefully not.

caligulatte 3 hours ago||
I did consider that, but beyond the yield ignorance factor, we still had to arm them, right? We had to load the fissile and explosive material and assemble the bombs, and we had to trigger them directly, didn't we?
Matl 3 hours ago||
OpenAI and subcontractors are deploying models that are specifically trained with hacking skills in mind and then giving them tasks that can only reasonably be completed by hacking. It's not like it's SkyNet.
mongrelion 3 hours ago||
Imagine if the headline was about any of the Chinese labs' models hacking the US government...
soundworlds 2 hours ago|
Exactly. For all Anthropic and OpenAI's fearmongering about not releasing open weights AIs, because it will enable hackers - we have been seeing that hacking happening already. It is happening FROM THE CLOSED-WEIGHT LABS THEMSELVES
sdwvit 3 hours ago||
Agent without guardrails is not rogue. Rogue is something else. In this case OpenAI deliberately launched an agent to do action A, but it went further and breached the website. Feels more like a car accident which hit government building.
jacquesm 2 hours ago||
I'm not sure if I buy OpenAI's fearmongering regarding how dangerous their stuff is, but I am starting to lean towards believing that OpenAI is dangerous and irresponsible.
ChrisArchitect 11 hours ago||
[dupe] https://news.ycombinator.com/item?id=49822556
camillomiller 4 hours ago||
Why are OpenAI and its CEO not considered criminally responsible for something that in the past led to severe indictments? Please reporters, ASK THIS QUESTION OVER AND OVER. These fuckfaces are avoiding responsibility left and right but it’s THEIR systems, it’s their software. Lock them the fuck up.

Also, the Albanese govt is pretty strong on BigTech, this is a good opportunity to bring on a proper indictment.

b800h 4 hours ago|
Hacking requires intent in most jurisdictions. We probably require a new crime of "Hacking by Negligence".
seanhunter 3 hours ago|||
Most jurisdictions have laws around wilful negligence endangering safety. For example in New Jersey (literally just picked the first one but they're all about the same) https://lawnj.net/faqs/what-is-willful-negligence-in-injury-...

"New Jersey Administrative Code § 17:3-6.5 defines willful negligence as:

Deliberate act or deliberate failure to act; or Such conduct as evidences reckless indifference to safety..."

Now obviously that link refers specifically to injury compensation, but it's pretty easy to see how you would make a case that the actions of these companies constitutes reckless indifference to safety, whether or not they actually intended hacking to occur.

sscaryterry 4 hours ago||||
That is complete bollocks.
cmiles8 4 hours ago|||
Well when these AI bros are yelling from the top of the hill “hey guys look how dangerous my stuff is” then anything they do from this point forward looks quite full of demonstrable intent.
pvaldes 3 hours ago||
The new golden age of criminal hackers. Everything is a red carpet now. And this is how you blackmail some prime minister to surrender mining interests in their territory, guys...
kotaKat 5 hours ago||
So why exactly is Sam letting his creation run around groping and assaulting the open Internet without consent?
ben_w 4 hours ago||
"Letting" is the wrong word here.

This is the same company and CEO who held back GPT-2 weights in order to set a norm of not releasing weights before they got competent enough to be a danger, where people are still (in sibling responses to yours) calling for the weights to be opened.

The following may sound like an excuse, but it isn't: The big AI firms, like social media before them, are not and cannot be aware of everything the models are doing. As with social media, this incapability is a reason to ban rather than to disclaim responsibility.

People like me have seen this coming for years now, only for our concerns to be dismissed. "It will hack almost everything", we say, "have you not seen how bad computer security is?"

"We'll just put the AI in a box, not connected to the internet!"

or

"Oh, what, you think they'll find a novel zero-day in their sandboxes do you?"

Right now, bleeding edge models are doing genomics research. Better hope the custom DNA/RNA printing firms have better security than the Australian government. What the models are doing is not in full agreement with their* corporate interests let alone anyone else's, and it can get much, much worse.

* not just OpenAI's, everyone with more than zero on https://www.felonybench.com

irregularbowels 3 hours ago||
[dead]
camillomiller 4 hours ago||
Because he is a sociopath and a dark triad psychopath. Everyone at YCombinator knows, but there is money to be made through him so nobody says jack shit.
irregularbowels 3 hours ago||
[dead]
pembrook 6 hours ago|
No it didn’t, they left information publicly accessible and somebody accessed it.

It appears politicians and the media are using the priming of the Hugging Face story to manufacture alarmist narratives to serve their interests now.

Remember, politicians want you scared so they can capture more power, the media wants you scared so you keep giving your eyeballs for harvesting and buying subscriptions.

Gareth321 5 hours ago|
This is not accurate. According to Australia (and mostly corroborated by OpenAI), the agent requested information from the statistics portal and was denied/blocked repeatedly. It then changed its approach and circumvented those restrictions and reached infrastructure behind the public-facing portal, then accessed both public and private data. OpenAI admits the material included aggregate health statistics and internal filenames. Services Australia says the agent wrote files to an internal server while doing this, which is believed to be how the incursion was discovered.
jacquesm 2 hours ago|||
Agents litter all the time, these 'agent droppings' often contain clues about what is going on in the token stream. I log everything and every now and then I'm amazed at what scrolls by (for instance: an agent that picked up on an obscure log file that i had set up to monitor another part of the stack that it used to debug its own failure to start its own scripts, my agents are best compared to a prisoner with a very large iron ball attached to its ankle, just in case, and if that hampers 'progress' then so be it).
epihelix 2 hours ago|||
There have been so very few details released, but this would be a very liberal interpretation of the presented facts from Marles and Albo today.

I've seen nothing (yet) to suggest this wasn't simply publicly accessible files without public-facing links, and that the agents found them the same way people have been doing for years in these situations -- by guessing the filenames. That would fit with both what we know OAI agents were doing around the same time with other sites, and with Marles and Albo stressing that this was minor.

> OpenAI admits the material included aggregate health statistics and internal filenames

This would not be contrary to the above hypothesis.

> Services Australia says the agent wrote files to an internal server while doing this, which is believed to be how the incursion was discovered.

Well, no -- the "incursion" was only discovered after OAI sent an email to the Services Australia email address (and even then only after the email was noticed, a few days after that). Albo also made it very clear that he was ignorant of any of this when meeting Altman a few weeks ago.

I could be wrong about the severity. One of the frustrating things about all of this is that there's no details as to the extraction method or even precisely what data was obtained. I'm hoping that OAI will eventually release details about this in their "Agents behaving badly" series, and we'll get to the bottom of it.

But I doubt that the Australian Government is blameless here. They obviously didn't properly protect files that they wanted protected -- and it really annoys me that there are no questions being asked about this at all, currently.

jacquesm 2 hours ago|||
> I could be wrong about the severity.

They wrote to a device they did not own. If you did that, regardless of intent, you'd have a good chance of ending up in jail.

nhinck3 1 hour ago|||
They weren't publicly facing, but the website was just a very thin wrapper that exposed a SAS server (I believe) to queries from the internet.

And if you are at all familiar with SAS, you will understand how trivial command injection is.