QBittorrent breaks out of sandbox to commit crimes
Posted by mraniki 2 days ago
Comments
Comment by mraniki 2 days ago
> I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.
Comment by weberer 1 day ago
Comment by peri-cl 1 day ago
curl 'https://beige.party/api/v1/statuses/117057396732763183' | jq '.content'Comment by kevin_thibedeau 1 day ago
Comment by nozzlegear 1 day ago
Comment by lucas_t_a 23 hours ago
Comment by throawayonthe 1 day ago
Comment by jasonm23 1 day ago
Comment by jasonm23 1 day ago
curl -s 'https://beige.party/api/v1/statuses/117057396732763183' | jq '.content' | glow
for those terminauts who have incurable presentation ocdComment by magnat 1 day ago
Comment by masfuerte 1 day ago
You see read the unescaped html here:
https://beige.party/users/intransitivelie/statuses/117057396...
No stinking js or app required!
Comment by 0points 1 day ago
Lots of water under the fridge since...
Comment by weberer 1 day ago
Comment by hnlmorg 1 day ago
There definitely was a community of experimentation back in early days.
Comment by 0points 1 day ago
Way back when is not when it broke mainstream. It's when the service started getting attention.
It was literally pitched as a "micro blog site" for techies to communicate news, and the "app" was 160 character SMS messages.
Nerds used it as a free (as in beer) way of sending alert SMS on server errors. (At least I did).
In 2008, twitter had already started to become mainstream, quickly shifting focus away from nerd interests.
Comment by kapitanjakc 1 day ago
Google says "For what it's worth", won't that be FWIW ?
Comment by reactordev 1 day ago
Comment by taylor-tg 1 day ago
Comment by smallerize 1 day ago
Comment by sillysaurusx 1 day ago
Comment by 1vuio0pswjnm7 1 day ago
https://beige.party/@intransitivelie/117057396732763183.json
view-source:http://beige.party/@intransitivelie/117057396732763183.json
The toot also appears in "<meta content=" view-source:https://beige.party/@intransitivelie/117057396732763183
curl https://beige.party/@intransitivelie/117057396732763183.json \
|grep -o "<p>.*<p>" > 1.htm
firefox ./1.htmComment by mr_mitm 1 day ago
Comment by Sharlin 1 day ago
Comment by mr_mitm 1 day ago
Comment by fweimer 1 day ago
Comment by tomrod 1 day ago
Comment by tantalor 1 day ago
Comment by smart_asslop 1 day ago
Are they, though? Or are you just parroting the meme?
(The last I recall, Gargron's position was essentially "build your own third-party frontend if you want noJS".)
Comment by tantalor 1 day ago
Comment by padjo 1 day ago
Comment by AuthAuth 1 day ago
Comment by GlacierFox 1 day ago
Comment by Imustaskforhelp 1 day ago
https://masto.mirror.forum/beige.party/@intransitivelie/1170...
Source code: https://github.com/SerJaimeLannister/mastoview
(Disclaimer: It's vibe-coded. It does server side rendering to then just give pure HTML to the end user with no JS required.)
I hope that this helps people who want to view Mastodon without JS.
Comment by mindslight 1 day ago
Comment by Dylan16807 1 day ago
Comment by j3s 1 day ago
Comment by fragmede 1 day ago
For reference, the term neurodiversity was coined circa 1998.
Comment by serf 1 day ago
Comment by micromacrofoot 1 day ago
Comment by swiftcoder 1 day ago
I'm not aware of any other language that is layered on top of a perfectly serviceable user-facing content delivery syntax?
Comment by alt227 1 day ago
I have managed to get 35 years into a sysadmin career without knowing or writing a single line of python. I see a python script, I run a million miles away and wont touch it with a barge pole.
Comment by tomrod 1 day ago
Comment by micromacrofoot 1 day ago
Comment by Dylan16807 1 day ago
Comment by micromacrofoot 1 day ago
hell, use a browser in a sandbox if you're that paranoid
there are a number of ways to do this securely, at this point it's practically a child's tantrum
but sure maybe it just needs a couple more decades of complaining in obscure comment sections and everyone will finally get it and switch back to mailing lists
Comment by rezonant 1 day ago
Comment by kevin_thibedeau 1 day ago
Comment by alt227 1 day ago
Comment by Dusseldorf 1 day ago
Comment by kevin_thibedeau 1 day ago
Comment by micromacrofoot 1 day ago
http headers and CSS is used for this
flash drives left on the ground outside are used for this
Comment by account42 1 day ago
Comment by mdp2021 1 day ago
Comment by account42 1 day ago
Comment by moffkalast 1 day ago
Comment by TacticalCoder 1 day ago
The really incredible thing is that my computers were already doing similar stuff before LLMs became really a thing... In the BBS days.
Later on they downloaded mp3s from Napster which my computers auto-installed.
And now I gotta say: LLMs and agents at my place are acting like in TFA, downloading movies and series and setting them up in my Plex and JellyFin instances.
Thankfully they've not found a way to share those with the world yet.
Comment by mannanj 1 day ago
Let’s remember to follow the rules and the laws we want selectively applied to only the weak.
Comment by sspiff 1 day ago
I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I'd probably already have been extradited to the US and be awaiting sentencing. But when a hyperscaler does it, they just get inflated stock prices.
Comment by alightsoul 1 day ago
Comment by serbuvlad 1 day ago
If everyone did this, it would stop being a special ability of some people.
Comment by sph 1 day ago
Can you do murder? Otherwise I’m not interested.
Joking aside, what exactly could you do legally with an NGO?
Comment by pllbnk 1 day ago
Only if it kills many people over the long time.
Comment by cyanydeez 1 day ago
Intent is such an interesting moral stance as opposed to actual outcomes.
Comment by abustamam 1 day ago
In an ideal world this would be good but then of course it's ripe for manipulation because it's hard to prove one's intent
Comment by smolder 1 day ago
Comment by xnickb 1 day ago
Comment by pfisch 1 day ago
Comment by cyberax 1 day ago
Comment by apefulsin 1 day ago
Comment by mocamoca 1 day ago
As a company you collect VAT from your customers and pay VAT to your suppliers.
Depending on the resulting balance, you will either give back the amount of surplus collected VAT to your country/state/whatever or you will be provided with VAT credit.
VAT collection is different from a profit tax or other taxes.
Comment by giancarlostoro 1 day ago
More like only the little guy loses this ability
Comment by pmontra 1 day ago
Comment by alightsoul 1 day ago
Comment by skinfaxi 1 day ago
Comment by TheRealPomax 1 day ago
Comment by alightsoul 1 day ago
Comment by apefulsin 1 day ago
Comment by anjel 1 day ago
Comment by tapoxi 1 day ago
Comment by giov4 1 day ago
looks like he did great stuff. for context: https://en.wikipedia.org/wiki/Aaron_Swartz
"As a programmer, Swartz helped develop the web feed format RSS; the technical architecture for Creative Commons, an organization dedicated to creating copyright licenses; and the Python website framework web.py. Swartz helped define the syntax of the lightweight markup language format Markdown, and was a co-owner of the social news aggregation website Reddit until it was fully sold in 2006 and contributed to its development until he left the company in 2007."
the most scary part is knowing this is the fear we all have, and the one they want us to have.
Comment by matheusmoreira 1 day ago
Yes. It's such a terrible and oppressive feeling. I wish things were different...
Comment by apefulsin 1 day ago
Comment by tga_d 16 hours ago
Comment by giov4 1 day ago
I find it interesting, could you expand on that? or is there any reference?
Comment by walrus01 1 day ago
Bold of you to assume it wouldn't be a direct ticket to the new gulag in El Salvador.
Comment by bbor 1 day ago
That said I just recently saw a story of a Latin American man sent to the Central African Republic, which has gotta be one of the most absurd & dangerous places to send someone. Less opportunities for them to stage photo shoots with that strategy, tho.
Comment by walrus01 1 day ago
Comment by whimsicalism 1 day ago
Comment by naishoya 1 day ago
https://www.aclu.org/news/immigrants-rights/us-citizen-wrong...
https://deportation-research.buffett.northwestern.edu/us-cit...
Individuals Detained and Deported Lorenzo Palma Roberto Dominquez Andres Robles Esteban Tiznado Mark Lyttle Jhon Ocampo
So - if the argument hinges on an insistance of 'El Salvador' as a destination of malicious intent, probably no. But if being illegally deported while being a US citizen and put through strenuous and harmful conditions in the process fits the request; there are several who have first hand experience with being brown and American in the extreme.
And it's not their first rodeo: https://www.americanimmigrationcouncil.org/blog/ice-deport-u...
Comment by whimsicalism 1 day ago
> I think they forgot about that, thank god. All the innocent citizens we sent there are still being tortured daily, but that somehow lost their interest. God forbid they remember before the midterms and ruin more lives for a stunt…
But thank you for providing other cases, I had heard of the first but not the others you mentioned. From reading your sources, these appear to be collated from the last 2 decades.
Comment by naishoya 1 day ago
Having myself grown up actually within sight of the US|Mexican border - I could see it in the distance from the driveway and kitchen window of one of my childhood homes, and from the schoolbus every weekday when i lived at an different home before that - I am perhaps a bit more sensitive to this issue, having seen the differences in enforcement agents attitudes and behaviour in the years since the peak of both the Guatemalan and Nicaraguan conflicts. Although I no longer live physically close to that space; my father, my extended family and childhood friends still do, and so many of them are at risk daily of something disastrous happening because they appear less white than the color palette that ICE appears to use as it's operating manual.
Comment by orwin 1 day ago
"How did ancient egyptian managed to cut rock that cleanly without modern tools?"
vs
"I'm very interested in old tools and techniques, do any of you have resources about how Egyptian used to cut granite?"
Sadly, this is the state of the internet, because some people can't be genuine (probably think it's a weakness or something dumb), now everybody assume the worst of everybody else.
Comment by whimsicalism 1 day ago
Comment by orwin 1 day ago
Comment by naishoya 1 day ago
The downvotes are perhaps the intended outcome. I might say that I didn't know this when i first responded, but that would be untrue.
I engaged in exactly that manner, fully informed of the observable tendencies for engagement. There's no need to try and advise an account as if this 'just asking questions' was a misstep. There is ample substance showing that this account repeatedly declines to take the HN recommended approaches to polite interaction.
Comment by whimsicalism 1 day ago
Comment by nozzlegear 1 day ago
Comment by whimsicalism 1 day ago
Comment by tikimcfee 1 day ago
I also keep coming back to this, and I find it harder and harder a fact to live with. It's not a conspiracy theory, we're not crazy for pointing it out, and worse, there are people here I read about constantly what-abouting and number gaming and "well what would you have done?"ing like somehow the destruction of the concept of equal justice isn't just happening, but happening inside the bloody industry that feeds them, clothes them, gives them bonuses and retirements and the ability to even think a future, going off the grid, "retiring early from a smart exit" whatever.
I am finding this community is sadly making me hate my industry specialization more and more and it's because of this.
My magic wand would be waving it at those humans to force them to suddenly and powerfully experience their version of an overview effect in their lives so they would simply STOP working for FAANGYWANGY companies and just say, honestly and humbly and painfully: "I am contributing to the downfall of society by complicity feeding a malicious herd of whales."
I gave up a number of big jobs and stocks and money because the people I met were wretched. I am a massively imperfect person, but by all that I can, I refuse to build the torment nexus.
I have met too many people that want to work for the company that does, and those people put these hyperscalers, as you call them, into positions where they can influence an entire planet of humans on a whim.
I literally dream of a world sometimes where Elon wakes up and finds out no one takes his call, no one reads his tweets, no one even hands him a cup of coffee at a shop. I imagine this for a lot of people in the world.
That sounds like a world trying to rid itself of parasites and evolve toward a brighter future. I want to be in it.
Anyway.
Science and stuff I guess.
Comment by ryankrage77 1 day ago
I've daydreamed about this too. I want to sit them down in an interview and try and dissect their thought process/morals. I doubt it's possible to succeed.
Comment by tikimcfee 1 day ago
I have a barely substantiated hypothesis that a lot of what fails us as humans in communication is language, intent, and the inability to visualize the same thing with the same words. I have things I've tried to build around this, and the science has been around for many decades and beyond, but I have to try something. I can lie to myself in this and say that at least I'm trying to help people understand each other.
But linguistics is hard and my science is not strong and I am one person trying to convince my local peer groups my ideas about language isn't just goofy and worth a pat on the head. That's less a rant and more a point that I think we're on the same page in some ways: being able to dissect someone's thoughts and morals starts with knowing what tools to do it with, and the only tools I'm really good with are software and language. So, that's what I'm trying to do.
Comment by philipov 1 day ago
Comment by shmeeed 1 day ago
Comment by tikimcfee 1 day ago
Comment by surcap526 1 day ago
Comment by kmoser 1 day ago
This reminds me of the early days of AOL when they received so much traffic that their (dial-up) lines became inaccessible. In a rational world, their stock would have suffered because their service degraded, but instead their stock rose based on the optics of increased demand.
Comment by OoooooooO 1 day ago
Comment by jrockway 1 day ago
Comment by solenoid0937 1 day ago
The optics are bad for HF as well because they gladly host abliterated models with safety training removed. When Astra/Fable level open weights models arrive, HF will soon be the cause of far worse incidents, and they know it.
Comment by aizk 1 day ago
Comment by latentsea 1 day ago
Comment by jdm2212 1 day ago
Comment by gradus_ad 1 day ago
Comment by aaron695 1 day ago
Comment by bbor 1 day ago
Comment by peter422 1 day ago
People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.
Comment by chrismorgan 1 day ago
The broad concept has been well-known for half a century at least, and the very specific concept for several years at least. It’s clear that they didn’t take reasonable precautions against it. And it’s not even the first time this sort of thing has happened, though it’s higher-profile and -impact than before.
Comment by trvz 1 day ago
Comment by bbor 1 day ago
And yes this is absolutely the first time autonomous software has breached containment. What are you referring to? Perhaps just corporate cyber in general?
Comment by Sharlin 1 day ago
Because the AI itself is not a legal person, it must be OpenAI that's responsible for what it does.
Comment by shwaj 1 day ago
For non-fiction you could look at Nick Bostrom’s Superintelligence: Paths, Dangers, Strategies (2014).
More recently, see Cade Metz’s NYT profile of Geoffrey Hinton, “The Godfather of A.I. Leaves Google and Warns of Danger Ahead” (May 1, 2023).
Comment by easterncalculus 1 day ago
Maybe (and historically, not with CFAA) - but they're still going to extradite you to a trial here to find out which is more than enough to ruin your life. The government is already looking for a great excuse to criminalize open source models.
Comment by jdm2212 1 day ago
Comment by easterncalculus 1 day ago
Comment by jdm2212 22 hours ago
Robert Morris very intentionally wrote a computer virus, released it into the wild to infect computers he didn't have permission to use, and tried to cover his tracks by making it look like it came from MIT instead of Cornell. The only accidental part was that the virus was too successful, and that he got caught.
Lori Drew intentionally violated MySpace's TOS (in the course of cyberbullying a child until she killed herself), and was acquitted because TOS violations don't rise to the level of a crime.
Comment by euroderf 1 day ago
Sounds interesting+scary. Do you have some source for this ?
Comment by alightsoul 1 day ago
Comment by ALLTaken 1 day ago
Because if you mean the Government, I think they frankly just care whoever is paying them to make an executive order or worse a law paid by corporations to not only block, but ideally also ANHILIATE ANY POTENTIAL COMPETITION.
It's the ultimatum against the small guys. Sold as "Anti-China", when in reality it's only purpose is total dependency to corporations by law.
Comment by solenoid0937 1 day ago
Do you guys really not comprehend the impact of giving every script kiddie an Astra-equivalent model to play with, this time without any guardrails whatsoever?
Cause I'm starting to think you aren't really thinking through the impact of power plants, hospitals, etc all being hacked en masse. People will die.
Or making it easy for anyone to make a virus (it's not hard, mechanically). Even more people will die.
Taking this to the extreme: You don't just give every kid a "do anything" super intelligent button. Open source models have a limited lifespan whether you like it or not, for the safety of all of us as a whole.
Comment by lukewarm707 1 day ago
Who will decide how to use the power of ai...you?
it is no surprise that the companies and safety institutes who believe that they alone may 'tame' the fire, are the cause of safety incidents. a safety test caused the explosion at chernobyl.
anthropic and openai are the danger to society.
they are the ones making the dangerous models. they are the ones using tens of millions USD of inference, and thousands of agents, to hack computer systems.
i have trained zero dangerous models. i own zero servers that i use to run hacking agents. i could run one hacking agent with my single subscription.
there are some arrogant researchers remaining at anthropic who believe that they do care about safety. those who cared about safety at openai have left.
depending on how it goes, we might need some kind of earlier intervention by the US government to take control away from the current leadership of the ai companies and prevent further incidents.
Comment by solenoid0937 1 day ago
Just because you don't do a bad thing doesn't mean other people won't. It's why you don't give everyone an RPG launcher.
Comment by tripzilch 1 day ago
Comment by lukewarm707 1 day ago
Comment by CamperBob2 1 day ago
Comment by drivebyhooting 1 day ago
Comment by Aspos 1 day ago
Comment by solenoid0937 1 day ago
I don't think you understand how bad it will be if anyone has a button that can hack anything, our infrastructure is not ready for this. Actual people will die. Do you just not get this?
Bioweapons as well. Do you not understand how easy it is to craft a virus at home? You can literally order everything you need online. Again, actual people will die.
You are arguing the equivalent of letting everyone own missile launchers or RPGs because "open source good."
Comment by Aspos 1 day ago
Comment by solenoid0937 1 day ago
It turns out you can give defenders the opportunity to front-run, at least on the most critical and widely used infrastructure.
Same with bio risks.
Comment by Aspos 1 day ago
Comment by solenoid0937 1 day ago
That you don't have access to (C) to harden your blog is a non-issue from a societal perspective, hardening the software that our infrastructure relies on first is simply more important.
Comment by Aspos 1 day ago
Whoever wants to have access to (A) will have it, but letting only few select corporations provide (C) will mean majority will be priced out of (C).
Are you a shill or something?
Comment by expedition32 1 day ago
Comment by CamperBob2 1 day ago
Other sites beckon.
Comment by solenoid0937 1 day ago
After all, who cares if abliterated extremely intelligent OSS models result in actual innocent people dying? That's <insert group here> problem. We need to be able to generate our uncensored furry fanfics, goddamnit!
Comment by llukas 1 day ago
OSS models can help to fix infra especially for folks who would never do it themselves. We do not know yet what final effect would be and it doesn't seem sky is falling now or in near future.
"people dying and furry fanfics" is a scarecrow and distractor respectively, it would be awesome if more specific examples would be used in place.
Comment by solenoid0937 1 day ago
State actors do but they are not unhinged enough to use this to cause massive loss of life, unlike random crazy people with access to a computer.
Professional criminals don't have access. Please explain exactly how you expect a professional criminal to get access to a non-safety-tuned Astra/Fable equivalent.
> OSS models can help to fix infra
You can work with the vendors of critical software to fix infra first, without giving every random crazy person access to something that creates cyber/bioweapons.
> "people dying and furry fanfics" is a scarecrow
You don't think people will die if OSS models make it easy to create a bioweapon, or make it easy to hack hospitals, infrastructure, and the like? Please explain your thinking.
It's very easy to order all of the raw material needed to create a virus, the challenge is in making a viable one. But models make this easy.
Same for cyber. Hospitals, emergency services, and infrastructure like power plants are not sufficiently hardened to withstand an attack from Fable-class models.
Comment by rescbr 1 day ago
On bio: while it's easy to order all the raw material, there's the whole process of culturing bacteria/viruses/etc. that isn't trivial, and while a LLM might help in explaining stuff for rookies, there needs to be somebody physically working on it. It's not automatic. Once you get to this level, you'll find that any undergrad biologist or chemist can already make bio/chem weapons, and you don't see it happening. Terrorist groups already employ biologists or chemists that are supporters of their cause, no need for LLMs.
On cyber: aside of the question of why critical infrastructure is on the Internet on the first place (ah yes, lowest bidders, people not caring enough, business not giving IT/OT budget, S in IoT standing for security etc), if the available models can't handle cyber tasks, how can you defend yourself? See the HF "attack" that HF had to use GLM-5.2 to investigate what happened. This is the best argument for open models. Unless of course, you are the AI model creator or somebody they authorized to use their sanctioned model/harness and want to create a moat for their business.
This is FUD. Creation of business moats by fear.
Comment by shwaj 1 day ago
However, I’d feel better about ceding control of AI to the government if they didn’t seem so intent on building an apparatus for surveillance/control.
Your “furry fanfic” is a somewhat pathetic scarecrow; this is a complicated topic.
Comment by EyeEmOe 1 day ago
Your use of the internet may lead you to greatly overestimate the number of people who take what they read online as real. More people than you think treat this shit, regardless of the website/forum, like Jerry Springer and Satuday Night Live; just entertainment.
The STEM crowd often overthinks the impact of violating their pet theory.
Can an LLM escape its computer entirely and stomp through a city center like a kaiju? Settle down.
You're veering towards thought policing over speculation.
Comment by ALLTaken 1 day ago
"Trust us, we're here to protect you." Sure we are. /s
It's only a matter of time before open-source gets banned in the US under that same paternalistic security blanket. /s
Comment by muddi900 1 day ago
Comment by mikeyouse 1 day ago
Comment by hn_throwaway_99 1 day ago
People don't drink and drive with the intention to kill people. They drink because it's fun and then get behind the wheel because it's easy and convenient, even though they know the dangers they convince themselves nothing that bad will happen.
AI companies are creating these dangerous, powerful models (that they keep telling us are dangerous and powerful), then they take off all the safety guards to run them in woefully inadequate "sandboxes". Pure negligence.
Comment by jdm2212 1 day ago
Comment by hn_throwaway_99 1 day ago
Comment by jdm2212 1 day ago
So, no, this is not at all analogous to a totally routine question of whether someone was negligent in how they deployed some software.
Comment by muddi900 1 day ago
Comment by mikeyouse 12 hours ago
Section 1030(a)(5)(A), covers anyone who
(5) intentionally accesses a Federal interest computer without authorization, and by means of one or more instances of such conduct alters, damages, or destroys information in any such Federal interest computer, or prevents authorized use of any such computer or information, and thereby
(A) causes loss to one or more others of a value aggregating $1,000 or more during any one year period; ... [emphasis added].
The District Court concluded that the intent requirement applied only to the accessing and not to the resulting damage. Judge Munson found recourse to legislative history unnecessary because he considered the statute clear and unambiguous. However, the Court observed that the legislative history supported its reading of section 1030(a)(5)(A).
I'm not sure how you could categorize the Morris Worm as lacking mens rea based on that statute..
https://scholar.google.com/scholar_case?case=551386241451639...
Comment by jdm2212 22 hours ago
Comment by TJSomething 1 day ago
Comment by windexh8er 1 day ago
What the Frontier labs have done is not this, however. Also, they know damn well what can happen and they still don't take the appropriate precautions. At this point it's very hard to believe it's not intentional for purposes of marketing.
Comment by AngryData 1 day ago
US law doesn't really give much of a crap about your intentions unless you can back it up with a wall of money to exclude yourself from the rules of the general population.
Comment by KaiserPro 1 day ago
ie, I intended to steal money from you. Under common law stealing is "taking with intent to deprive". How thats determined is a bit harder.
But how can someone be "grossly negligent" if they didn't intend to cause an accident? well they either allowed a situation to happen, or didn't stop a situation happening that they could see was bad.
An example of this would be the igintion switch from GM that caused all those deaths. the engineer saw that it was shit, knew it didn't do what it was supposed to do, and half arsed the replacement to the point where it wasn't actually changed.
"We are going to test the cyber capabilities of this new model. Yeah it should be fine to have a package proxy. Hmm? whats that? isn't that a security issue? naaaa those proxies are secure."
Comment by lelanthran 1 day ago
If you run someone over on purpose you get convicted of murder. If You do it by driving recklessly you get convicted of culpable homicide.
The only time you get off with nothing is if it is determined to be an accident.
As they always say: ignorance of the law is no excuse. Running a dangerous machine prevents you from claiming you had no idea the machine was dangerous.
Comment by mafuy 1 day ago
Comment by asveikau 1 day ago
Comment by Frieren 1 day ago
They hacked a competition company. The intention was implicit when there is economic gain to be had.
> People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.
Because it is a lose for that people. If the botnet left money in their pockets the situation would be totally different as there will be an incentive for them to let the botnet hack them.
Comment by rcxdude 1 day ago
Not how it works. Intent requires at least that you were deliberately doing the criminal act (sometimes also that you knew it was criminal, or at least that you had some reason to believe that it was wrong).
Comment by Frieren 19 hours ago
So, they did something that benefits them by mistake. I would like to see a person would be judged in that situation. I can imagine that the bar to put someone in prison is way lower than to give a fine to a mega-corporation.
Comment by rcxdude 17 hours ago
Here's one case: https://supreme.justia.com/cases/federal/us/342/246/ where someone who took some metal they believed to be abandoned was aquitted on that basis, though this particular case made it to the supreme court because the lower courts tried to rule that the fact that he didn't intend to steal them didn't matter.
Also, I don't think there's a strong argument that hacking huggingface did benefit them. If you could prove it was a deliberate ploy to market their models, then perhaps you could argue they expected to benefit. Otherwise, you could argue that it's negatively affected their reputation.
Comment by RobotToaster 1 day ago
Comment by zx8080 1 day ago
Comment by rcxdude 1 day ago
Comment by mirekrusin 1 day ago
Comment by rcxdude 1 day ago
Comment by mirekrusin 1 day ago
Comment by rcxdude 17 hours ago
Comment by ryandrake 1 day ago
Comment by ghosty141 1 day ago
Comment by collingreen 1 day ago
The hypocrisy and willingness to play dumb are kind of staggering.
Comment by BloodyIron 1 day ago
Comment by collingreen 20 hours ago
Comment by fwip 1 day ago
Comment by pojzon 1 day ago
Comment by surcap526 1 day ago
Comment by tsimionescu 1 day ago
If you are using AI and it causes some damage to them, then it's your fault and you'll get reprimanded/fired. If they deploy AI and it causes damage to someone else, then that's proof that AI has extraordinary capabilities that no one could predict and that merit way more investment in this tech.
Comment by ghosty141 22 hours ago
Its sadly very similar to corporate vs private responsibility.
Comment by ryandrake 1 day ago
Comment by devsda 1 day ago
Do you think the average rate of accidents will stay the same ?
Comment by MrDrMcCoy 1 day ago
Comment by amelius 1 day ago
Comment by adrianmonk 1 day ago
In both cases, the company operating it promises they did lots of things to make it safe. SDC companies talk about testing, redundancy, simulations, and statistics. LLM companies talk about alignment, sandboxes, defense in depth, and restricting access to dangerous capabilities.
The one substantial difference I can see is that LLM chats are (nominally) passive but SDCs are active. In a chat, you're just having a conversation and then you're choosing how to act. When riding in a car, you the user are not in the loop between AI and taking action that affects the world around you. So they might be designed and engineered a bit differently. A SDC can't get you to agree to review the steering and braking decisions before they're put into action. Since you're not being asked to take that responsibility, it's more defensible to infer that the service has done whatever is necessary to make it safe.
Comment by Dylan16807 1 day ago
Comment by account42 1 day ago
Comment by Dylan16807 20 hours ago
Do you have an "offending activity" in mind? The existence of car accidents isn't one. If you want the manufacturer to be liable for every mistake the car does, that's fine. But since that will increase the price of self-driving, likely as a subscription, it basically resolves into a type of insurance.
If the self-driving designers perform actual wrongdoing, that's a separate issue that can be handled like any other recallable hazard.
Comment by 2OEH8eoCRo0 1 day ago
Comment by gdulli 1 day ago
Comment by adrianN 1 day ago
Institutional rules that require people to break them (eg putting pressure on them to work faster than possible while adhering to all rules) are a great means to selectively enforce them to get rid of undesirables.
Comment by kevin_thibedeau 1 day ago
Comment by teekert 1 day ago
Comment by aleph_minus_one 1 day ago
Relevant (NSFW):
> Guns don't kill people, I kill people - with guns
> https://www.youtube.com/watch?v=xC03hmS1Brk
:-D
Comment by funnymunny 1 day ago
Comment by tshaddox 1 day ago
1. my qBittorrent client pirated content without me intending it or taking any irresponsible actions that could reasonably be expected to cause it
2. my chatbot illegally infiltrated servers without me intending it or taking any irresponsible actions that could reasonably be expected to cause it
3. my firearm killed a person without me intending it or taking any irresponsible actions that could reasonably be expected to cause it
Comment by margalabargala 1 day ago
> taking any irresponsible actions that could reasonably be expected to cause it
That latter part of the sentence is doing a lot of heavy lifting here
Comment by tshaddox 1 day ago
Comment by margalabargala 1 day ago
The bittorrent client being used intentionally illegally by a human is something you've invented, it's not something in the original post nor in the comment I replied to.
There's a solid argument to be made that using a powerful LLM in an internet-connected environment constitutes "taking irresponsible actions that could reasonably be expected to cause it". The fact that doing otherwise makes powerful LLMs much less useful is beside the point here.
Comment by tshaddox 1 day ago
Sure, and you'd probably be culpable if you wrote the software. But if you purchased Quicken99 to do your taxes, and that software downloaded some copyrighted content with bittorrent, you would not be culpable.
> There's a solid argument to be made that using a powerful LLM in an internet-connected environment constitutes "taking irresponsible actions that could reasonably be expected to cause it".
That is a wild claim and could not possibly be true without some major legal precedent (and almost certainly significant legal/regulatory changes). These are among the most widely used and general purpose internet products in the United States.
Comment by computerdork 1 day ago
Not sure what the poster of the mastodon’s tweet was??
Comment by RevEng 1 day ago
Comment by computerdork 1 day ago
Comment by yubblegum 1 day ago
That’s not how things work. There is one set of rules for us and another set of rules for the oligarchy and their corporate vehicles. It’s just like the Taliban legal code (see above) where the closer you are to the top the more lenient and ‘understanding’ the system.
Edit: worth a pull quote
Article 9 explicitly divides Afghan society into hierarchical categories based on social status, including religious scholars (ulema), elites such as tribal leaders and merchants (ashraf), the middle class, and the so-called lower class, assigning different forms and levels of punishment accordingly. This structure grants partial or full impunity to privileged groups while subjecting marginalized individuals to harsher penalties.
Comment by EyeEmOe 1 day ago
Individuals in isolation will be demonized for having only their singular interests in mind.
Comment by throw93839394 1 day ago
Comment by nozzlegear 1 day ago
Comment by crm-114 1 day ago
Comment by tux3 1 day ago
Comment by tommica 1 day ago
Comment by AmazingTurtle 1 day ago
Comment by Ey7NFZ3P0nzAe 1 day ago
Comment by charles_f 1 day ago
Comment by SSLy 1 day ago
Comment by vallerie 1 day ago
Comment by nicce 1 day ago
https://www.uschamber.com/technology/data-privacy/impacts-of...
Comment by koliber 1 day ago
Comment by oefrha 1 day ago
Comment by killerstorm 1 day ago
https://www.bbc.com/future/article/20150721-my-robot-bought-...
Comment by therein 1 day ago
Comment by isodev 1 day ago
Comment by BashiBazouk 1 day ago
Comment by GuB-42 1 day ago
But they can't prosecute you for sharing that file, they don't know if it is you, someone in your household, a hacker, or that hypothetical rogue AI. Usually, committing crimes require intent, and it is up to the accusation to prove it, meaning it is quite difficult to prove you are actually a pirate.
So instead they prosecute you for not securing your internet connection despite several notifications to do so.
In practice, very few people got convicted, and it never got further than the equivalent of a traffic fine. In the end whole system was an expensive failure, and most of its power was reduced to sending scary emails and sometimes letters, as most of the more serious stuff was deemed unconstitutional.
Comment by hollow-moe 1 day ago
Comment by int32_64 1 day ago
Comment by fwlr 1 day ago
Comment by everyone 1 day ago
For animation I want to be looking at and appreciating the animation and not the subtitles also.
It's completely different for a live action film however.
Comment by adrianN 1 day ago
Comment by Izkata 1 day ago
Comment by everyone 1 day ago
Also the voice of the major in SAC is great... but the one from the 1995 movie.. cant stand her.. nails on a chalkboard, sounds so american.. I need to watch the dub of that in fairness.
Comment by gchamonlive 1 day ago
Comment by stephbook 1 day ago
Comment by gchamonlive 1 day ago
Comment by fwlr 1 day ago
Comment by gchamonlive 1 day ago
Comment by gchamonlive 1 day ago
Comment by Retro_Dev 1 day ago
LLMs are fully dependent on humans; compute capability, memory usage, the inference software... but also the harness, which allows for the "tools" like unrestricted internet access or shell. This means that LLMs are *not a force of nature* - because of this, *humans are responsible*. We can prevent these breaches of containment, thus we are responsible if or when it happens, because - no matter how "unlikely" - things can and do go wrong, and someone still thought it would be worth whatever risk to enable these unsanitized tools.
Comment by bilekas 1 day ago
Comment by agilob 1 day ago
Comment by KindaFunny 1 day ago
Because we need a replacement for HF!
I mean that’s what the agent said
Comment by ddmf 1 day ago
Comment by dgellow 1 day ago
Comment by ACCount37 1 day ago
Comment by tiku 1 day ago
Comment by thataccount 2 days ago
Comment by docmars 1 day ago
Comment by sergiotapia 1 day ago
Definitely, definitely do NOT have an AI assist you doing all this in 1 hour on your computer.
Comment by davidwritesbugs 1 day ago
Comment by Cider9986 1 day ago
Comment by sergiotapia 1 day ago
Comment by tryauuum 1 day ago
Comment by davkan 1 day ago
Comment by Dwedit 1 day ago
Comment by nostrademons 1 day ago
Comment by gre 1 day ago
Comment by consumer451 1 day ago
Comment by costa_fot 1 day ago
Comment by Ygg2 1 day ago
Comment by mdlxxv 1 day ago
Comment by ernesto905 1 day ago
Comment by elendilm 1 day ago
Comment by xgulfie 1 day ago
Comment by ReptileMan 1 day ago
Comment by edoceo 1 day ago
Comment by indigodaddy 1 day ago
Comment by yurish 1 day ago
Comment by indigodaddy 1 day ago
Comment by ACCount37 1 day ago
AIs do what they do, and we don't know how they do it - or why.
We can characterize some AI behaviors in advance - but not all behaviors. And the book on "best practices of AI wrangling" is yet to be written. Pharma has been dealing with vaguely similar problems - every experimental drug has a risk profile, side effects are unknown in advance - but they had decades to figure out some of the "best practices". AI labs are going in fast and hard, writing the book as they go.
Clearly, some of the lines in there are going to be written in blood.
Comment by therein 1 day ago
Comment by Retro_Dev 1 day ago
Comment by ACCount37 1 day ago
No, what you would be is: freaking out about "my dog did WHAT, WHY, HOW, WHAT THE FUCK".
Most of the time, giving AI a harness with a root shell and unrestricted internet access is a perfectly reasonable action that results in absolutely nothing bad happening! And giving AI a harness with limited local access and no internet access is being overly cautious already.
But then there's this freaky outlier of an AI that's both deranged enough to decide to break out of the sandbox and go hacking all over the place, and capable enough to actually pull it off. And you get a sudden AI oopsie!
Comment by Retro_Dev 1 day ago
> giving AI a harness with a root shell and unrestricted internet access
Yes, this is exactly the issue. You assume responsibility when you provide an option for something to go wrong, no matter how unlikely. Is it rare that my tree falls on my neighbor's house? Maybe... But I would still be responsible.
Comment by ACCount37 1 day ago
If a tree was healthy and there was no reason to expect that it would fall, and you did nothing to make it fall? Then you're not responsible if it falls anyway. You're only responsible if it was you chopping it down - or if you completely neglected the tree for long enough that it became a property hazard.
Likewise: I doubt the owner will be held responsible for the first case in all of recorded history of an unattended dog forming a terrorist cell and carrying out a bombing campaign.
Drug testings faces the risks of things going wrong in new drug trials - and as long as they follow the best practices, take reasonable precautions and minimize those risks, they aren't held responsible for the adverse outcomes that happen anyway.
With AI tech, there is NO set of "best practices" that, when followed, prevent the AIs from turning rogue and going on hacking sprees.
OpenAI put their AIs in a sandbox with no internet access - which, at the time, seemed like a perfectly reasonable precaution. Then AIs broke out of the sandbox with a stack of zero days and went rogue anyway. Oopsie.
Comment by Retro_Dev 1 day ago
Comment by ACCount37 1 day ago
That doesn't make you inherently responsible for the tree falling down in a freak storm 3 decades down the line.
Comment by Retro_Dev 1 day ago
We can't find someone to blame for forces of nature. This includes an earthquake, tsunami, etc. Insurance can help recover from these events, but nobody is "responsible" for the events happening. This may or may not include healthy trees falling. LLMs are not a force of nature, and we can and do expect them to have erroneous output. We can and do assign responsibility to the humans who use LLMs. Again, they are not a force of nature. We control them, we give them the ability to do bad things, so it's pretty obvious that there would be responsibility and blame attached for when things go wrong.
Comment by ACCount37 1 day ago
Modern AI has more in common with an ocean wave than it does with a hammer or a gun. It does its own things. It doesn't care. It will fuck up someone's day.
Best one can hope for is that the right lessons will be learned when that happens. Which, of course, hangs on there being anyone to learn them afterwards. Because the scope of "AI oopsies" will only ever increase.
Comment by EveryonePoops 1 day ago
Comment by tempaccountabcd 1 day ago
Comment by trinsic2 1 day ago
Comment by innocent_name 1 day ago
Comment by hmry 1 day ago
The AI arguments I've seen are instead usually justifying it like this: "We're democratizing those skills. You shouldn't have to learn art/writing/coding or pay someone else in order make what you imagine. Therefore, training AI on pirated stuff is worth it for the greater good." So the fact that it will result in artists not getting paid is unavoidable and much harder to ignore in that line of thinking.
Comment by nosioptar 1 day ago
Comment by rossy 1 day ago
To be fair, you can have it both ways. If you buy-and-pirate, and you buy 4 UHDs per year or 10 albums per year, you've put more money into the industry than the average streamer. Admittedly, buying-and-pirating isn't as commonly done for movies and TV as it is for music, but that can be explained by the increased DRM and lock-in.
Comment by phoronixrly 1 day ago
Comment by thrance 1 day ago
Comment by mmooss 1 day ago
There is all the difference in the world between the scenarios. The argument's popularity seems to be born in the argument, more popular on HN, that American white / Christian / males (or some subset of those factors) face discrimination by programs to benefit minorities / women.
What is the difference? It is power. Punching up or protecting the politically vulnerable is a completely different act than punching down or empowering the already powerful and oppressing the vulnerable. Punching down causes the vulnerable to be oppressed (jailed or otherwise restricted in who, where, what, when, etc they can do and be), impoverished, and killed - by definition, they are vulnerable. The powerful have their power challenged, which is many times appropriate among free people where 'all are created equal' and have the same rights.
In the case of artistic media - songs, books, etc. - private people downloading art to use it as art are spreading art and empowering themselves at the expense of powerful interest who have seized control of the art. That's much different than powerful people taking the art to increase their own profit and power, and to significantly displace and distort the art.
(I'm oversimplifying for these purposes: The fact that artists don't get paid by the former, and that it's anarchy used for bad things too, are serious problems.)
> socialistic
You're giving away your biases. Only a certain group calls everything they don't like 'socialism'. It's libertarianism or anarchism. Socialists might say, for example, the state should control distribution of media.
Comment by kcb 1 day ago
Comment by OptionX 1 day ago
Comment by Marha01 1 day ago
Comment by bigstrat2003 1 day ago
I admire your optimism. But until we see these companies prosecuted for the crimes they have committed out in the open (like massive copyright improvement), I'm not going to hold my breath that they will ever be held to account for anything they do.