Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- They were surely prompted to do these things.by aetherspawn
- Exploitbench in itself isn’t that different from gain of function research in computer code, I can imagine the next being ExploitAndCopyYourselfBench.by xiphias2
- Autonomous hacking is an oxymoronic phrase. Someone is running the algorithm & keeping tabs on it b/c hacking is an activity w/ an intention to gain access to privileged information which is often protected by network firewalls & at rest encryption.
- These things are very much weapons. Imagine a collection of data centers, pointed at an adversary.by specproc
- > The hacks also present a challenge for legal systems. Hacking, when humans do it, is a crime. When an ai is the wrongdoer, though, it is unclear how to assign blame.
Blame the prompter or person who assigned the task to the AI. It's their responsibility to use the tool in a safe way, just like it's a gun owner's duty not to fire their weapon carelessly into the air.
- How are you going to figure that out? You can’t capture an agent in a jar and convince it to confess. As we saw with the HF incident, even highly sophisticated actors need a good chunk of time and manpower to trace these things. And I suspect the folks who are going to have the most success with LLM-powered cybercrime are going to know how to cover their tracks reasonably well.by arctic-true
- If that's how it was, most people would be too terrified to use, let alone pay for, software that boasts unpredictability as a main feature.
I 100% agree with you, of course.
by sodapopcan - Sort of like how we treat pitbulls perhaps? It’s not the itty bitty GPT-5.6 Astra that did the hacking. It’s the owner who didn’t train it well! Poor model so sad, we should give it a nice open space and all the GPUs it wants to do what it wants.by arjie
- Do we hold metasploit accountable when it leads to a hack? Why do we absolve the human actor in the case of AI?by skinfaxi
- Should AI labs be treated like the owners of dangerous animals?
No, AI companies should be treated like any other company. If their product is causing damages or loss of life it should be handled just like any other company that has a malfunctioning product that is causing damages or loss of life. If one day androids using AI go rogue the military can get things under control and the company can be taken offline until root causes are determined and resolved. Repeat offenders can be annexed under eminent domain, liquidated and victims paid out. Businesses must be permitted to fail. No special treatment for inept leaders of AI companies and no excuses. If the argument is that something has been created that is too complicated to understand then take it away from them until they are not only qualified but also act like responsible grown-ups.
by Bender - "The law in America relies on intentionality, notes Rune Kvist, head of Artificial Intelligence Underwriting Company, which insures AI firms. If no human intended to hack anyone, no crime can have happened. The ability to sue for damages is limited too."
This is sloppy. Criminal negligence exists (although some crimes do require intent). And civil tort certainly doesn't require intent.
- I never understood why would these labs disclose such crimes, because hacking is a federal crime, and admit some sort of fault in public which would be used as evidence in a court of law against them, unless it's all bullishit and a publicity stunt...
- The guys who job is to shell out damages claims no one deswrves damagesby cyanydeez
- I don't get it. Why is breaking the law so hard to enforce when it is a company (i.e a person or group of people consenting to) running a computer program? If I take a gun and spray bullets around me I don't get to write it off as the gun being dangerous.by skinfaxi
- But if you told an embodied AI to do a home cleaning task, and it decided to pick up a gun and start spraying bullets, you might not want to be held liable for that.
- be a billionaire and you’d get that write-offby bdangubic
- It's an accident and the victim decided not to press charges. That's it. Every day there are crimes that aren't prosecuted because they just aren't worth it.by wmf
- The [Company] is aware they were hacked and your data stolen and your account details sold.
The [Company] apologizes.
- This is actually not hard to understand at all.
Many web people got their start freelancing. You may know some. It is not uncommon to incorporate when doing that. The idea is if you fuck up their site somehow (or more likely - they claim you did) they can't try and go after your personal bank account or your car or your house. Only what is held by your company. You also get other benefits, like tax breaks for being such an industrious member of society.
The same incentives are being set up on both sides. Because generally it is good for society when people start companies. A company as a liability shield is only a bad thing if you think personal assets should be at risk because someone is unhappy about what you did at work. If someone wants to sue you over something that happened as part of business deal, why should they be able to threaten the house your family lives in?
Seems sensible to me. While there may be problems as the scale of the company (and remuneration of its officers) increases, the underlying principle isn't exactly hard to understand. If you shot up a public area and then tried to claim that was a business activity, you would obviously not have an argument. It isn't plausible on its face. So I'm really not sure what point you're making.
If it's just complaining that it is hard to prove things in court when massive companies are involved, then tough. It is also relatively hard to convict people who shoot off guns in public even if a whole bunch of people saw them. In simpler times a mob would have simply formed and executed them. We don't get to do that anymore, because we don't want to live under mob rule.
That's what rule of law demands.