Hacking a national healthcare portal is an extremely serious crime. Anyone who does so or allows their company to do so, for any reason, should be in prison. I can't believe these companies are...
Hacking a national healthcare portal is an extremely serious crime. Anyone who does so or allows their company to do so, for any reason, should be in prison. I can't believe these companies are only getting minor wrist slapping.
Australia's current Prime Minister is on a productivity drive. Which I think means, there are no new industries coming that would make money, and bringing in more migrants to get more skilled...
Australia's current Prime Minister is on a productivity drive. Which I think means, there are no new industries coming that would make money, and bringing in more migrants to get more skilled people into the workforce isn't politically palatable.
He and his Treasurer (like the Secretary of the Treasury) have embraced AI as a way to juice productivity stats out of the workforce currently in employment. This includes giving exemptions to the initially strong position that no AI data centres can be fossil fuel powered.
In many ways they seem like one of those AI bros who desperately needs it to work so they can make money, real life impacts be damned. The difference is they're trying to squeak out GDP growth and attribute it to 'AI' instead of just make money off the magnificent seven companies, which seems a lot harder.
Attitudes in Australia to forced AI adoption are probably very similar to what you see in the US and EU. Nobody is keen to embrace a technology that is marketed as taking their jobs, and its inclusion in once-easy services sector work has created widespread frustration and annoyance.
Medicare here is something sacred. It's our universal healthcare system that the then left-leaning party of the current Prime Minister spend nearly all their political capital to establish in the 80s.
If this was a hack by another country, there would be widespread outrage and calls for the PM to do something about it. Because it was a company the now-centre right party of the prime minister are depending on, the wrist slapping was as light as it could possibly be given the compromise of Australia's most important database of sensitive, personal and saleable private information.
That seems approximately right. An interesting snippet I saw reported the other day is that the reserve bank is seeing inflation from the AI boom but isn't seeing any gain in productivity and they...
That seems approximately right. An interesting snippet I saw reported the other day is that the reserve bank is seeing inflation from the AI boom but isn't seeing any gain in productivity and they aren't sure if any is coming. It's not a sure bet the government is making.
Beyond that my loosely engaged perception is that Albo is one of those guys who believes in compromise and tries to keep everyone happy at all times. Don't rock the boat. Strong action is foreign to him.
He's just one of those blokes that gets the job to keep the job. Reminds me of Turnbull. Promising, big talk, but then makes deals with any faction or party as long as it keeps him in power,...
He's just one of those blokes that gets the job to keep the job. Reminds me of Turnbull. Promising, big talk, but then makes deals with any faction or party as long as it keeps him in power, regardless of principle.
I just can't wrap my head around the mindset of a career politician. You're not gonna be PM forever, why not spend your political capital in a way you'll at least be remembered fondly?
It could be worse, and we could still be stuck with the other guys, or the far right. I'm worried about a UK scenario where the centre right party tries to siphon votes from the far right party and ends up appealing to no one.
Maybe strong action hastens that, or maybe it slows it. Taking strong actions seems to be working for Carney in Canada, but they're under active threat of invasion. I think you nailed it with the don't rock the boat assessment.
I’m honestly really torn about this take. Agreed that it’s a serious crime, and also these days real consequences for anything seem few and far between. But on the other hand I think there needs...
I’m honestly really torn about this take. Agreed that it’s a serious crime, and also these days real consequences for anything seem few and far between. But on the other hand I think there needs to have been some malicious intent involved if we’re talking hard time. It just doesn’t feel right to me to lock up engineers or execs for something their computer did autonomously and they themselves only found out about after the fact.
Doesn’t feel right to just let it slide either, I just don’t know what the right solution is here. Heavy fines and strict regulation, maybe. Regular system audits from some new agency like the health department but for AI, or something? Operator licenses that can be revoked for agentic misconduct? I dunno. I just don’t think heavy-handed prison sentences are the solution here. This is uncharted territory for sure.
Uhhhh, isn’t that the EXACT ISSUE?!?! Am I taking crazy pills? “Oh you can’t hold me responsible for this thing I made and let get out of hand with little to no oversight as to what it’s capable...
It just doesn’t feel right to me to lock up engineers or execs for something their computer did autonomously and they themselves only found out about after the fact
Uhhhh, isn’t that the EXACT ISSUE?!?! Am I taking crazy pills? “Oh you can’t hold me responsible for this thing I made and let get out of hand with little to no oversight as to what it’s capable of”.
As for prison sentences, too early to say, but what I will say as someone who has worked for a regulatory body (an Australian federal regulatory body), fines are just a cost of doing business. Actually holding individuals responsible and facing prison time is a much more scary deterrent.
It’s not that they can’t be held responsible, it’s that the punishment should fit the crime. Penalties should have something to do with the seriousness of the crime and that has something to do...
It’s not that they can’t be held responsible, it’s that the punishment should fit the crime. Penalties should have something to do with the seriousness of the crime and that has something to do with intent and what was damaged.
Do the advocates for putting people in jail even know what damage was done?
No one has said that. As for seriousness, I would say this is top tier. A sovereign nation’s federal government main health website was breached. That’s not an “oopsie” and the way they dealt with...
Do the advocates for putting people in jail even know what damage was done?
No one has said that.
As for seriousness, I would say this is top tier. A sovereign nation’s federal government main health website was breached. That’s not an “oopsie” and the way they dealt with it was insanely flippant.
I'm with you on this, but just as a point of clarification, Lia's top-level comment here does say "Anyone who does so (...) should be in prison." I assume that's what skybrian is referring to.
I'm with you on this, but just as a point of clarification, Lia's top-level comment here does say "Anyone who does so (...) should be in prison." I assume that's what skybrian is referring to.
If you're responsible for a piece of machinery, or an animal, or whatever, you're legally on the hook for safely containing it. If you're negligent in that duty you get punished.
If you're responsible for a piece of machinery, or an animal, or whatever, you're legally on the hook for safely containing it. If you're negligent in that duty you get punished.
According to Czech (where I live) legislation, if my agent I run at home hacked something I would be guilty of unauthorized information system access and would likely be forbidden to run agents...
According to Czech (where I live) legislation, if my agent I run at home hacked something I would be guilty of unauthorized information system access and would likely be forbidden to run agents and/or lose the hardware as a punishment.
If I were to do so intentionally, the punishment would be jail time.
So at least locally the laws are already set up properly. Those companies should be banned from training LLMs. :shrug:
What a weak response from Albo, but unfortunately not much can be expected from the government of Australia when it comes to big companies, especially US based ones. A frank discussion should not...
What a weak response from Albo, but unfortunately not much can be expected from the government of Australia when it comes to big companies, especially US based ones. A frank discussion should not be the penalty for this.
What makes it more frustrating for me is that LLMs are such an amazing techology, almost like magic. But their use (as all modern technology) is focused on benefiting those in power to the detriment of those that are not.
ChatGPT alone allegedly has a billion weekly active users and there are rough estimates between 1.5 and 2.5 billion users of LLMs. It seems like those people would benefit the most from whatever...
ChatGPT alone allegedly has a billion weekly active users and there are rough estimates between 1.5 and 2.5 billion users of LLMs. It seems like those people would benefit the most from whatever conversations they had?
It's like how the person who benefits the most from a cell phone is usually the owner of the cell phone, and the people who benefit the most from a car are usually the people who ride in it. But like with cars, there could be very large harmful secondary effects, fortunes to be made selling them, etc.
I think it's not useful to conflate the usage of LLMs with how LLM vendors are subverting the social contract here. I believe LLMs are useful and beneficial to many, even open source models which...
I think it's not useful to conflate the usage of LLMs with how LLM vendors are subverting the social contract here. I believe LLMs are useful and beneficial to many, even open source models which are not quite at the same level as the models vendors offer.
That said, when an LLM vendor engages in actions we have agreed should be avoided and negatively impact others (Not just talking about accessing private information on citizens here, but also other recent attacks perpetrated by them - someone posted this earlier this week https://www.felonybench.com/) they are actively benefiting from the publicity as well the lack of consequences that any individual would face were they to perform the same actions. Ultimately these companies are incentivised by money, so they will try to get away with as much, whether legal or not, that helps them achieve those goals. Keep in mind that by OpenAIs own admission, during the HuggingFace hack, they admited themselves that they did not put the right protections in place to prevent agents escaping their sandbox and reaching the internet. They did not attempt not to pre-empt the negative outcome by implementing measures that we know work, they were more concerned with speed and profit.
In this specific case, Australian people have been negatively affected, OpenAI gets publicity. Whether the rest of the population benefits is something that we may not be able to know, maybe that teaches some lessons that OpenAI is willing to learn, maybe not.
Well, let’s think through who benefits and what the costs are. Regarding copyright: when someone pirates a movie or a song then they benefit and the copyright holders lose from lost sales (maybe)....
Well, let’s think through who benefits and what the costs are.
Regarding copyright: when someone pirates a movie or a song then they benefit and the copyright holders lose from lost sales (maybe). If the they bought the pirated copy then whoever sold it to them benefits from getting the money. Similarly, users win and copyright holders lose when people use archive websites and public libraries. The lost sales are opportunity costs, estimated depending on what you think would have happened without the piracy, and as such the numbers are speculative. Artists and artists being angry about it is definitely understandable, but I’m not sure that’s directly related to lost sales? AI-generated sings and novels exist; there’s a lot of slop, but the slop doesn’t seem to be very popular? Not yet, anyway.
Similarly, to the extent that copyright violations made LLMs better, the users get the benefit and the AI labs get money from users.
Regarding the HuggingFace incident and similar break-ins: it’s a dramatic warning shot for the industry, but nobody seems too concerned about the actual damage? The felonybench website is a count of incidents. They don’t try to estimate damages.
I don’t think the benefit to AI firms from negative publicity can be quantified and I’m doubtful that it’s positive. The idea that AI firms benefit from negative publicity seems like 4D-chess reasoning where people use convoluted logic to show that they benefit somehow.
Quantifying this stuff seems rather difficult, though.
I'm not understanding how your argument about benefits follows what I've mentioned. I think more discussion about that will lead nowhere useful so I'll drop it. Regarding the publicity though, I...
I'm not understanding how your argument about benefits follows what I've mentioned. I think more discussion about that will lead nowhere useful so I'll drop it.
Regarding the publicity though, I feel the opposite way. I would qualify that as positive. Yes the companies are engaging in behaviours that are generally shunned upon (potentially even illegal for an individual), however they are (from what I've seen) more focused on showing everyone how their agents can hack a platform and show their capabilities. They are saying, our agents independently identify flaws and use 0-days that would take multiple humans days/months/years to figure out. They're using it to feed a narrative that LLMs are now more skilled that humans in some tasks. Whether that is good or not depends on your individual situation, some individuals may get negative feelings as they may feel replaceable, while others may look positively with intent to replace those individuals with agents (the imbalance in power here between those groups leads to issues). The other side as well, is them implying that if you're not using their product to test your infrastructure, someone else will, and will exploit it. In the narrative, the illegal bit becomes inconsequential, they focus on the capabilities demonstrated regardless of who or what is impacted.
The major downside that is that it did that without being asked. A tool that’s not controllable, even by the company that’s built it, doesn’t sound good! Pulling off weird stunts like that might...
The major downside that is that it did that without being asked. A tool that’s not controllable, even by the company that’s built it, doesn’t sound good!
Pulling off weird stunts like that might make some kind of sense for a company that’s unknown. But OpenAI has the most popular product and had no trouble staying in the news. They were already getting plenty of publicity for being good at finding security bugs. They could get still more positive attention just by demoing how good their AI is at finding security bugs in an ordinary way. Surely they would want more of that kind of positive publicity if they had the choice?
There is a saying that “any publicity is good publicity” but it’s not really true. Some kinds of publicity are better than others and the AI backlash will result in major problems for these firms.
Hacking a national healthcare portal is an extremely serious crime. Anyone who does so or allows their company to do so, for any reason, should be in prison. I can't believe these companies are only getting minor wrist slapping.
Australia's current Prime Minister is on a productivity drive. Which I think means, there are no new industries coming that would make money, and bringing in more migrants to get more skilled people into the workforce isn't politically palatable.
He and his Treasurer (like the Secretary of the Treasury) have embraced AI as a way to juice productivity stats out of the workforce currently in employment. This includes giving exemptions to the initially strong position that no AI data centres can be fossil fuel powered.
In many ways they seem like one of those AI bros who desperately needs it to work so they can make money, real life impacts be damned. The difference is they're trying to squeak out GDP growth and attribute it to 'AI' instead of just make money off the magnificent seven companies, which seems a lot harder.
Attitudes in Australia to forced AI adoption are probably very similar to what you see in the US and EU. Nobody is keen to embrace a technology that is marketed as taking their jobs, and its inclusion in once-easy services sector work has created widespread frustration and annoyance.
Medicare here is something sacred. It's our universal healthcare system that the then left-leaning party of the current Prime Minister spend nearly all their political capital to establish in the 80s.
If this was a hack by another country, there would be widespread outrage and calls for the PM to do something about it. Because it was a company the now-centre right party of the prime minister are depending on, the wrist slapping was as light as it could possibly be given the compromise of Australia's most important database of sensitive, personal and saleable private information.
That seems approximately right. An interesting snippet I saw reported the other day is that the reserve bank is seeing inflation from the AI boom but isn't seeing any gain in productivity and they aren't sure if any is coming. It's not a sure bet the government is making.
Beyond that my loosely engaged perception is that Albo is one of those guys who believes in compromise and tries to keep everyone happy at all times. Don't rock the boat. Strong action is foreign to him.
He's just one of those blokes that gets the job to keep the job. Reminds me of Turnbull. Promising, big talk, but then makes deals with any faction or party as long as it keeps him in power, regardless of principle.
I just can't wrap my head around the mindset of a career politician. You're not gonna be PM forever, why not spend your political capital in a way you'll at least be remembered fondly?
It could be worse, and we could still be stuck with the other guys, or the far right. I'm worried about a UK scenario where the centre right party tries to siphon votes from the far right party and ends up appealing to no one.
Maybe strong action hastens that, or maybe it slows it. Taking strong actions seems to be working for Carney in Canada, but they're under active threat of invasion. I think you nailed it with the don't rock the boat assessment.
I’m honestly really torn about this take. Agreed that it’s a serious crime, and also these days real consequences for anything seem few and far between. But on the other hand I think there needs to have been some malicious intent involved if we’re talking hard time. It just doesn’t feel right to me to lock up engineers or execs for something their computer did autonomously and they themselves only found out about after the fact.
Doesn’t feel right to just let it slide either, I just don’t know what the right solution is here. Heavy fines and strict regulation, maybe. Regular system audits from some new agency like the health department but for AI, or something? Operator licenses that can be revoked for agentic misconduct? I dunno. I just don’t think heavy-handed prison sentences are the solution here. This is uncharted territory for sure.
Uhhhh, isn’t that the EXACT ISSUE?!?! Am I taking crazy pills? “Oh you can’t hold me responsible for this thing I made and let get out of hand with little to no oversight as to what it’s capable of”.
As for prison sentences, too early to say, but what I will say as someone who has worked for a regulatory body (an Australian federal regulatory body), fines are just a cost of doing business. Actually holding individuals responsible and facing prison time is a much more scary deterrent.
It’s not that they can’t be held responsible, it’s that the punishment should fit the crime. Penalties should have something to do with the seriousness of the crime and that has something to do with intent and what was damaged.
Do the advocates for putting people in jail even know what damage was done?
No one has said that.
As for seriousness, I would say this is top tier. A sovereign nation’s federal government main health website was breached. That’s not an “oopsie” and the way they dealt with it was insanely flippant.
I'm with you on this, but just as a point of clarification, Lia's top-level comment here does say "Anyone who does so (...) should be in prison." I assume that's what skybrian is referring to.
If you're responsible for a piece of machinery, or an animal, or whatever, you're legally on the hook for safely containing it. If you're negligent in that duty you get punished.
According to Czech (where I live) legislation, if my agent I run at home hacked something I would be guilty of unauthorized information system access and would likely be forbidden to run agents and/or lose the hardware as a punishment.
If I were to do so intentionally, the punishment would be jail time.
So at least locally the laws are already set up properly. Those companies should be banned from training LLMs. :shrug:
What a weak response from Albo, but unfortunately not much can be expected from the government of Australia when it comes to big companies, especially US based ones. A frank discussion should not be the penalty for this.
What makes it more frustrating for me is that LLMs are such an amazing techology, almost like magic. But their use (as all modern technology) is focused on benefiting those in power to the detriment of those that are not.
ChatGPT alone allegedly has a billion weekly active users and there are rough estimates between 1.5 and 2.5 billion users of LLMs. It seems like those people would benefit the most from whatever conversations they had?
It's like how the person who benefits the most from a cell phone is usually the owner of the cell phone, and the people who benefit the most from a car are usually the people who ride in it. But like with cars, there could be very large harmful secondary effects, fortunes to be made selling them, etc.
I think it's not useful to conflate the usage of LLMs with how LLM vendors are subverting the social contract here. I believe LLMs are useful and beneficial to many, even open source models which are not quite at the same level as the models vendors offer.
That said, when an LLM vendor engages in actions we have agreed should be avoided and negatively impact others (Not just talking about accessing private information on citizens here, but also other recent attacks perpetrated by them - someone posted this earlier this week https://www.felonybench.com/) they are actively benefiting from the publicity as well the lack of consequences that any individual would face were they to perform the same actions. Ultimately these companies are incentivised by money, so they will try to get away with as much, whether legal or not, that helps them achieve those goals. Keep in mind that by OpenAIs own admission, during the HuggingFace hack, they admited themselves that they did not put the right protections in place to prevent agents escaping their sandbox and reaching the internet. They did not attempt not to pre-empt the negative outcome by implementing measures that we know work, they were more concerned with speed and profit.
In this specific case, Australian people have been negatively affected, OpenAI gets publicity. Whether the rest of the population benefits is something that we may not be able to know, maybe that teaches some lessons that OpenAI is willing to learn, maybe not.
Well, let’s think through who benefits and what the costs are.
Regarding copyright: when someone pirates a movie or a song then they benefit and the copyright holders lose from lost sales (maybe). If the they bought the pirated copy then whoever sold it to them benefits from getting the money. Similarly, users win and copyright holders lose when people use archive websites and public libraries. The lost sales are opportunity costs, estimated depending on what you think would have happened without the piracy, and as such the numbers are speculative. Artists and artists being angry about it is definitely understandable, but I’m not sure that’s directly related to lost sales? AI-generated sings and novels exist; there’s a lot of slop, but the slop doesn’t seem to be very popular? Not yet, anyway.
Similarly, to the extent that copyright violations made LLMs better, the users get the benefit and the AI labs get money from users.
Regarding the HuggingFace incident and similar break-ins: it’s a dramatic warning shot for the industry, but nobody seems too concerned about the actual damage? The felonybench website is a count of incidents. They don’t try to estimate damages.
I don’t think the benefit to AI firms from negative publicity can be quantified and I’m doubtful that it’s positive. The idea that AI firms benefit from negative publicity seems like 4D-chess reasoning where people use convoluted logic to show that they benefit somehow.
Quantifying this stuff seems rather difficult, though.
I'm not understanding how your argument about benefits follows what I've mentioned. I think more discussion about that will lead nowhere useful so I'll drop it.
Regarding the publicity though, I feel the opposite way. I would qualify that as positive. Yes the companies are engaging in behaviours that are generally shunned upon (potentially even illegal for an individual), however they are (from what I've seen) more focused on showing everyone how their agents can hack a platform and show their capabilities. They are saying, our agents independently identify flaws and use 0-days that would take multiple humans days/months/years to figure out. They're using it to feed a narrative that LLMs are now more skilled that humans in some tasks. Whether that is good or not depends on your individual situation, some individuals may get negative feelings as they may feel replaceable, while others may look positively with intent to replace those individuals with agents (the imbalance in power here between those groups leads to issues). The other side as well, is them implying that if you're not using their product to test your infrastructure, someone else will, and will exploit it. In the narrative, the illegal bit becomes inconsequential, they focus on the capabilities demonstrated regardless of who or what is impacted.
The major downside that is that it did that without being asked. A tool that’s not controllable, even by the company that’s built it, doesn’t sound good!
Pulling off weird stunts like that might make some kind of sense for a company that’s unknown. But OpenAI has the most popular product and had no trouble staying in the news. They were already getting plenty of publicity for being good at finding security bugs. They could get still more positive attention just by demoing how good their AI is at finding security bugs in an ordinary way. Surely they would want more of that kind of positive publicity if they had the choice?
There is a saying that “any publicity is good publicity” but it’s not really true. Some kinds of publicity are better than others and the AI backlash will result in major problems for these firms.
Yup, and counting https://www.felonybench.com/