4 votes

OpenAI agents attacked RubyGems back in May

7 comments

  1. [3]
    Sheldon
    Link
    Seems either extremely negligent or intentionally malicious to allow or instruct semi-autonomous computer programs to hack other entities without their explicit permission. I wonder if there'll be...

    Seems either extremely negligent or intentionally malicious to allow or instruct semi-autonomous computer programs to hack other entities without their explicit permission. I wonder if there'll be any consequences for that.

    5 votes
    1. balooga
      Link Parent
      Consequences? In this economy?!

      Consequences? In this economy?!

      2 votes
    2. skybrian
      Link Parent
      All reports so far indicate that it wasn't intentionally malicious and they didn't instruct their agents to do any such thing. I don't know why you threw that in there other than to muddy the waters.

      All reports so far indicate that it wasn't intentionally malicious and they didn't instruct their agents to do any such thing. I don't know why you threw that in there other than to muddy the waters.

      1 vote
  2. LukeZaz
    Link
    With the way this keeps happening, I find it increasingly difficult to believe this is anything other than an attempt at orchestrating justifications for regulatory capture. The amount of...

    With the way this keeps happening, I find it increasingly difficult to believe this is anything other than an attempt at orchestrating justifications for regulatory capture. The amount of incompetence OpenAI would require for this to happen otherwise is staggering.

    OpenAI wants their technology to look like Skynet so that they can convince the law to prevent anyone who isn't them from having control over LLMs. All while ignoring the societal harms AI actually inflicts, which they don't care to stop. And since they're evidently not getting any real punishment for it, why not? It's cheap press.

    3 votes
  3. skybrian
    Link
    From the article: [...]

    From the article:

    OpenAI agents carried out an undisclosed attack on RubyGems is a new bombshell report from Spencer Kitts, Thomas Larsen, and Sydney Von Arx—three of the four authors of the report on the agent attack on disused wikis (previously) last week.

    This time they’re noting that it looks very likely that an OpenAI agent swarm was behind an attack against the RubyGems package repository first reported on May 12th by Maciej Mensfeld of the RubyGems security team[.]

    [...]

    Many of the packages were exploiting the RubyDoc.info documentation build process to exfiltrate (public) data from UK government websites, presumably as part of an information gathering task similar to the research tasks processed by the wiki-exploiting agents. [...]

    2 votes
  4. [2]
    teaearlgraycold
    Link
    I would love to see one of these companies criminally charged for this reckless behavior.

    I would love to see one of these companies criminally charged for this reckless behavior.

    2 votes
    1. JRandomHacker
      Link Parent
      Someone on lobste.rs threw out the comment of "Could OpenAI have RICO charges brought against them?" - and while I have to assume the factual answer is "no", it's a fascinating concept to think about.

      Someone on lobste.rs threw out the comment of "Could OpenAI have RICO charges brought against them?" - and while I have to assume the factual answer is "no", it's a fascinating concept to think about.

      1 vote