logoalt Hacker News

gizajob • today at 5:36 PM • 9 replies • view on HN

Getting bored of these framings where the superintelligent sentient beings running freely inside OpenAI are doing things that the company has no control over. The headline should be:

OpenAI meddled with multiple US Government agency sites.

The bots are acting neither properly nor improperly, they’re acting as they’re being allowed or coordinated to act.


Replies

20k • today at 6:29 PM

Yep. You have to ask - why did OpenAI allow these bots unrestricted access to government sites? Why is security being done in seemingly such a haphazard way?

It isn't difficult to block certain kinds of network traffic, eg restrict the kinds of requests the bots are able to make. They also mention that the bots used developer only tools - why were they even installed on the machines that the bots were running on? Why aren't they reviewing network traffic, to make sure that incidents aren't occurring?

In this case, userdata was transferred to third parties by the bots - why do they have the ability to pass data to a third party? It is not complex to prevent this

This is literally the most basic kind of sandboxing and security, and the fact that OpenAI isn't doing it is clearly intentional. It is quite literally not believable that this hasn't been brought up internally as a problem

>"We have yet to understand the extent of existing incidents, and future rogue AI scenarios could be catastrophic," Krueger said.

This is why it smells like marketing, every time one of these incidents happens it reinforces the false notion that AI is sentient or acting on its own. Its intentional negligence by the AI companies to make the models seem more capable than they are to make line go up

➕ show 1 reply
Aurornis • today at 6:29 PM

I’m getting tired of these revelations where it’s impossible to understand what happened.

There’s a line down in the story that says all of the data accessed was public. Then something about how it used “tools intended for developers” to access it, which they think is a problem? I would expect an LLM to use tools available to access public data when they can rather than do heavy web page loads and parsing.

There’s not enough info in the story about the “meddling” to even know what happened.

➕ show 1 reply
0xDEAFBEAD • today at 6:32 PM

My impression was that these hacks occurred during some sort of cybersecurity benchmarking? We can hold OpenAI liable, sure. But if the point of the benchmarking was to give us a preview of what's to come, let's keep our eye out for that bigger wave on the horizon.

theptip • today at 6:28 PM

Curious, why do you find it so objectionable to state that OpenAI has out-of-control agents?

➕ show 3 replies
baxtr • today at 6:38 PM

Or:

OpenAI let their agents break out of their sandbox to meddle with multiple US government agency sites

➕ show 1 reply
mossTechnician • today at 6:21 PM

I agree this is better framing.

When I read the title, my initial thought was "did someone besides OpenAI use their product?" Then I opened the article to find out OpenAI was responsible.

qarl • today at 6:09 PM

> OpenAI meddled with multiple US Government agency sites.

But that leaves out the most important information.

EDIT: Oh, I guess the agent part isn't important then? Seems to me like that's the only thing anyone is talking about.

➕ show 2 replies
api • today at 6:27 PM

This is their fear mongering push for regulatory capture.