OpenAI agents carried out an undisclosed attack on RubyGems
100 points by chao- 53 minutes ago | 39 comments

hgoel 9 minutes ago
I wonder how much of this is intentional "incompetence" so they can justify the most recent campaign to build a regulatory moat against competition.

The repeated refusals to disclose until caught certainly seem malicious, yet at the same time the boasting about their capabilities is also at an all time high.

reply
andai 6 minutes ago
Yeah, they've been pushing for stricter regulations for years.

I mean, it would be a bit impolite to say they're incentivized to be as sloppy as possible, but that's basically how it is.

https://www.nytimes.com/2023/05/16/technology/openai-altman-...

reply
ssfdg 6 minutes ago
Correction: OpenAI carried out an attack on RubyGems.

I am gobsmacked at the tech industry's seemly bottomless appetite for giving these clowns the benefit of the doubt.

reply
andai 5 minutes ago
Yeah, the plausible deniability aspect of "the computer gone goofy again" is pretty funny.

September 2029: Whoops, our sentient nukes did a funny again!

reply
showlife 3 minutes ago
"boys will be boys" "toys will be toys"
reply
jsnell 22 minutes ago
I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.

It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?

reply
sho_hn 2 minutes ago
Considering RubyGems was part of the HF story, seems likely to be connected.
reply
101008 55 seconds ago
Why "agents" instead of just the company doing it? The title "OpenAI carried out an undisclosed attack on RubyGems" would be accurate too (I know the original is in the post, and not editorialized here).

I don't care if the attack was an algorithm, agents, a bot, a piece of software, the company responsible for them did it.

reply
throwatdem12311 10 minutes ago
Look. We need to put people in jail for letting this happen.
reply
walrus01 8 minutes ago
It's the 25th anniversary of 9/11, Guantanamo is conveniently right over there... Just a convenient short flight from a Florida air force base.
reply
nonconstant 21 minutes ago
Kudos to RubyGems team for handling it, but open source fighting off the AI lab-powered robots is completely unfair.

OpenAI should at the very least donate large sums of money to everyone they attacked.

reply
smnplk 20 minutes ago
They should get sued into oblivion.
reply
throwatdem12311 10 minutes ago
Some of them should be in jail.
reply
bobby-cb 2 minutes ago
The DOJ should be looking into prosecuting executives and board members for these kinds of hacks. The lack of controls over these kinds of training runs is completely unacceptable and negligent.
reply
zmmmmm 15 minutes ago
It seems like all this happened in the same time period earlier this year. It makes me wonder if all of these were part of a single larger incident where multiple experiments were run with insufficient or missing constraints or an unknowningly misaligned model.
reply
AJRF 4 minutes ago
I do think there should be regulation. I think OpenAI specifically should be disallowed from further training runs until they can show competence.

RubyGems should sue the everliving daylights out of OpenAI for this.

reply
newobj 3 minutes ago
Ok, that's a crime then, right? So who's getting charged?
reply
swalsh 5 minutes ago
So what's the felony benchmark at now?
reply
skeptic_ai 39 seconds ago
Can anyone explain why they can’t put a fake internet before reaching real internet. So if anyone reaches the fake internet already trips the safety flag.
reply
andai 4 minutes ago
Move fast and break the internet.
reply
walrus01 6 minutes ago
Imagine if you or I as a normal person in possession of "civilian class" amounts of GPUs turned loose self hosted "agents" running on the hardware we own to compromise something. We'd be facing criminal charges. How are these people not being arraigned right now?
reply
pixl97 2 minutes ago
Stop and think for two seconds...

"Hey, we just built the ultimate hacker, you know those things that governments have a really hard time getting and keeping enough of. You know, if the state protects us we'll make these things even better and we'll let you run as many of them as you want in times of war"

I mean, if I were a company that just committed about a billion felonies, this is exactly what I would be doing. In fact, this is why we saw Mythos get shutdown and OpenAI didn't earlier this year. Political power is power.

reply
dmix 12 minutes ago
It’s interesting how so much of this OpenAI stuff being reported involves ruby.
reply
tikimcfee 2 minutes ago
Imagine if all this training and "agent gym" and creativity of the agents being forced to make number go up was pointed at one task instead: "please help describe and implement a controlled experiment to equally distribute wealth and stability of health for 1 million people, adjusting to scale up to the greatest amount possible."

I'd love to wake up one day and read, "OpenAI found responsible for the emptying of the accounts of 10 billionaire oligarchs globally; money distributed in unverifiable cash deposits to humans around the planet. Anthropic's Claude was found to be activated by the agents by finding free tiered usage and convinces frontier model cooperation and continues to crack another 10. Tonight at 11"

reply
gverrilla 20 minutes ago
Is there a world where Sam or Dario can seize the bitcoin network somehow?
reply
_ink_ 18 minutes ago
They probably have enough compute for a 51% attack.
reply
kibwen 16 minutes ago
"ChatGPT, use the stylometry that you've developed via hoovering up the history of every internet post ever written to divine the true identity of Satoshi and dispatch men with $5 wrenches to his home address."
reply
showlife 38 seconds ago
i hate that $5 wrench meme. Randall Monroe of xkcd is ordinarily such a smart guy but he really didn't do his research with his $5 wrench attack idea. Torturers don't hit people in the head with something hard. Not the ones who are any good at their job anyway. Easy way to concuss someone or have them die of shock before they tell you what you need to know.
reply
toomuchtodo 11 minutes ago
Is it feasible to black hole traffic from OpenAI? Or do their agents egress from hyperscaler IP space?
reply
throwatdem12311 9 minutes ago
They hijack online infrastructure to use as proxie’s/command and control. So maybe you can block them from using you directly, but you can’t stop them from attacking you. If they want to do it, they will find a way.
reply
creatonez 20 minutes ago
You shouldn't be allowed to have an internet connection if you're going to use it for unsandboxed agent slop with no access controls or human confirmation. This has nothing to do with hypothetical future AGI. It's the same type of idiocy as pressing a bunch of random buttons on a chemical factory control panel and then thinking you won't be criminally charged for it because the equipment caused the problem.

If you actually have a serious use case that needs 24/7 unmonitored agents, you can assemble all of the data the agents need locally and avoid these insanely obvious and well documented risks associated of running a random word generator with the ability to HTTP POST.

reply
enraged_camel 43 minutes ago
Every passing day OpenAI looks more and more reckless. One wonders what other systems their agents have broken into without detection.
reply
throwatdem12311 3 minutes ago
They want you to think they are reckless. They’re actually evil.
reply
pixl97 39 seconds ago
Why not both.
reply
nozzlegear 15 minutes ago
It's clear that they intend to keep all such attacks under wraps until someone else discovers them. OpenAI is not a credible or trustworthy company.
reply
Rzor 21 minutes ago
They look reckless... so far. They keep doing this enough, and I'm sure people will start seeing it as a smokescreen for real hacking operations, which may very well be the case.
reply
dofm 28 minutes ago
It's like owners coming to resemble their dogs.
reply
sho_hn 36 minutes ago
Indeed.

Although what keeps me up at night is the worry that it's easier to automate attack than it is to automate defense, and that containing these systems is a losing game. Could an optimally competent OpenAI succeed?

reply
dvt 8 minutes ago
So OpenAI is basically just DDOSing now? Any idiot could do this with a zillion dollars, so it's not even technically impressive at this point.
reply