Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk.

OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
77 Indlæg 53 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

    OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

    Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

    Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

    kroppeb@tech.lgbtK This user is from outside of this forum
    kroppeb@tech.lgbtK This user is from outside of this forum
    kroppeb@tech.lgbt
    wrote sidst redigeret af
    #24

    @0xabad1dea ANTHROPIC DID WHAT?!?

    And they only noticed because they looked at logs from months ago AFTER the OPEN AI announcement??

    1 Reply Last reply
    0
    • evacide@hachyderm.ioE evacide@hachyderm.io

      @wdormann @0xabad1dea No. Intention matters when it comes to the CFAA, but the CFAA is not your only potential problem.

      lmk@infosec.exchangeL This user is from outside of this forum
      lmk@infosec.exchangeL This user is from outside of this forum
      lmk@infosec.exchange
      wrote sidst redigeret af
      #25

      @evacide @0xabad1dea Would be fascinating to read a synopsis of the legal reasoning.
      I do wonder if instead of an AI agent they asked the same task of a human pentester working in that same sandbox if the legal position differs.

      1 Reply Last reply
      0
      • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

        OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

        Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

        Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

        lmk@infosec.exchangeL This user is from outside of this forum
        lmk@infosec.exchangeL This user is from outside of this forum
        lmk@infosec.exchange
        wrote sidst redigeret af
        #26

        @0xabad1dea The attempts at positively spinning this become Onion-worthy parody [https://designingsecuresoftware.com/writings/ai-agent-parody/] and these events certainly normalize [https://designingsecuresoftware.com/writings/commonplace/] AI agents running amok in the future.

        rrb@infosec.exchangeR 1 Reply Last reply
        0
        • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

          OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

          Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

          Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange
          wrote sidst redigeret af
          #27

          I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

          advancedrubbish@hachyderm.ioA atax1a@infosec.exchangeA mirabilos@toot.mirbsd.orgM kevingranade@mastodon.gamedev.placeK smn@l3ib.orgS 6 Replies Last reply
          0
          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

            OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

            Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

            Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

            rejzor@mastodon.socialR This user is from outside of this forum
            rejzor@mastodon.socialR This user is from outside of this forum
            rejzor@mastodon.social
            wrote sidst redigeret af
            #28

            @0xabad1dea And I got contacted by national security institute because I was testing malware in sandbox and my ISP apparently detected "botnet running on my system". Few years later talking with AV-Comparatives guys, they had to make special agreement and exemption with ISP to be allowed to run live sandboxed malware on their networks. But these Ai companies can just do worse shit and no one does anything. WTF?!

            J 1 Reply Last reply
            0
            • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

              OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

              Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

              Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

              mcwabbit@tenforward.socialM This user is from outside of this forum
              mcwabbit@tenforward.socialM This user is from outside of this forum
              mcwabbit@tenforward.social
              wrote sidst redigeret af
              #29

              @0xabad1dea So less cool than the Terminator Skynet story. I am disappointed.

              1 Reply Last reply
              0
              • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

                advancedrubbish@hachyderm.ioA This user is from outside of this forum
                advancedrubbish@hachyderm.ioA This user is from outside of this forum
                advancedrubbish@hachyderm.io
                wrote sidst redigeret af
                #30

                @0xabad1dea to be fair to LLMs in this ONE case, I also do not believe what date it is

                1 Reply Last reply
                0
                • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                  OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

                  Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

                  Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

                  nullpo@masto.hackers.townN This user is from outside of this forum
                  nullpo@masto.hackers.townN This user is from outside of this forum
                  nullpo@masto.hackers.town
                  wrote sidst redigeret af
                  #31

                  @0xabad1dea the funniest outcome i've had so far from this is a client has done a full stop on AI tooling usage because after reading the openai stuff they're worried about it doing bad things without anyone noticing

                  1 Reply Last reply
                  0
                  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                    I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

                    atax1a@infosec.exchangeA This user is from outside of this forum
                    atax1a@infosec.exchangeA This user is from outside of this forum
                    atax1a@infosec.exchange
                    wrote sidst redigeret af
                    #32

                    @0xabad1dea we've got a great solution to this problem! it involves not using an LLM in any capacity!

                    rotopenguin@mastodon.socialR 1 Reply Last reply
                    0
                    • atax1a@infosec.exchangeA atax1a@infosec.exchange

                      @0xabad1dea we've got a great solution to this problem! it involves not using an LLM in any capacity!

                      rotopenguin@mastodon.socialR This user is from outside of this forum
                      rotopenguin@mastodon.socialR This user is from outside of this forum
                      rotopenguin@mastodon.social
                      wrote sidst redigeret af
                      #33

                      @atax1a nah, I'll just have a regex* swap 2026 and 2023 on data moving in and out of the LLM.

                      *the regex is actually another LLM

                      atax1a@infosec.exchangeA 1 Reply Last reply
                      0
                      • rejzor@mastodon.socialR rejzor@mastodon.social

                        @0xabad1dea And I got contacted by national security institute because I was testing malware in sandbox and my ISP apparently detected "botnet running on my system". Few years later talking with AV-Comparatives guys, they had to make special agreement and exemption with ISP to be allowed to run live sandboxed malware on their networks. But these Ai companies can just do worse shit and no one does anything. WTF?!

                        J This user is from outside of this forum
                        J This user is from outside of this forum
                        jameswidman@mastodon.social
                        wrote sidst redigeret af
                        #34

                        @rejzor @0xabad1dea well, their leaders _did_ contribute millions of dollars to trump's campaign, so

                        guillotine_jones@beige.partyG 1 Reply Last reply
                        0
                        • rotopenguin@mastodon.socialR rotopenguin@mastodon.social

                          @atax1a nah, I'll just have a regex* swap 2026 and 2023 on data moving in and out of the LLM.

                          *the regex is actually another LLM

                          atax1a@infosec.exchangeA This user is from outside of this forum
                          atax1a@infosec.exchangeA This user is from outside of this forum
                          atax1a@infosec.exchange
                          wrote sidst redigeret af
                          #35

                          @rotopenguin [subtitle: this is what LLM users actually believe]

                          1 Reply Last reply
                          0
                          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                            I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

                            mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                            mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                            mirabilos@toot.mirbsd.org
                            wrote sidst redigeret af
                            #36

                            @0xabad1dea I think that that may very well be unfixable

                            lanodan@queer.hacktivis.meL 1 Reply Last reply
                            0
                            • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                              I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

                              kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                              kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                              kevingranade@mastodon.gamedev.place
                              wrote sidst redigeret af
                              #37

                              @0xabad1dea weird it's like LLMs don't actually handle facts or knowledge but just contextualless strings of characters.

                              To be clear the sarcasm is only aimed at LLM boosters not you.

                              mathew@universeodon.comM 1 Reply Last reply
                              0
                              • mirabilos@toot.mirbsd.orgM mirabilos@toot.mirbsd.org

                                @0xabad1dea I think that that may very well be unfixable

                                lanodan@queer.hacktivis.meL This user is from outside of this forum
                                lanodan@queer.hacktivis.meL This user is from outside of this forum
                                lanodan@queer.hacktivis.me
                                wrote sidst redigeret af
                                #38
                                @mirabilos @0xabad1dea Well… at least without effectively using them as parsers rather than as text generators.
                                1 Reply Last reply
                                0
                                • deirdrebeth@mas.toD deirdrebeth@mas.to

                                  @evacide @outersystems @wdormann @0xabad1dea

                                  But as "you" are not a corporation backed by billionaires...

                                  outersystems@hachyderm.ioO This user is from outside of this forum
                                  outersystems@hachyderm.ioO This user is from outside of this forum
                                  outersystems@hachyderm.io
                                  wrote sidst redigeret af
                                  #39

                                  @deirdrebeth @evacide @wdormann @0xabad1dea « Selon que vous serez puissant ou misérable / Les jugements de cour vous rendront blanc ou noir ».

                                  https://en.wikipedia.org/wiki/The_Animals_Sick_of_the_Plague

                                  1 Reply Last reply
                                  0
                                  • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                                    OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!

                                    Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂

                                    Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠

                                    foolishowl@social.coopF This user is from outside of this forum
                                    foolishowl@social.coopF This user is from outside of this forum
                                    foolishowl@social.coop
                                    wrote sidst redigeret af
                                    #40

                                    @0xabad1dea They're promoting total incompetence as if it's a selling point.

                                    steve@social.coopS 1 Reply Last reply
                                    0
                                    • grwster@mastodon.socialG grwster@mastodon.social

                                      @evacide @wdormann @0xabad1dea Interesting re crime and intent. My initial thought was more along the lines of liability, like if your dog bites someone you are liable, right?

                                      jumpmed@mastodon.socialJ This user is from outside of this forum
                                      jumpmed@mastodon.socialJ This user is from outside of this forum
                                      jumpmed@mastodon.social
                                      wrote sidst redigeret af
                                      #41

                                      @grwster @evacide @wdormann @0xabad1dea That's what I would think. Like you keeping a vicious Doberman in the front yard with only a 3ft fence. An outside observer would (correctly) say that it's foreseeable that it could escape and maul someone. In that scenario you could be held criminally liable if it jumped the fence and mauled someone because most places have laws about dogs and fences. You'd also have civil liability to cover damages.

                                      jumpmed@mastodon.socialJ 1 Reply Last reply
                                      0
                                      • jumpmed@mastodon.socialJ jumpmed@mastodon.social

                                        @grwster @evacide @wdormann @0xabad1dea That's what I would think. Like you keeping a vicious Doberman in the front yard with only a 3ft fence. An outside observer would (correctly) say that it's foreseeable that it could escape and maul someone. In that scenario you could be held criminally liable if it jumped the fence and mauled someone because most places have laws about dogs and fences. You'd also have civil liability to cover damages.

                                        jumpmed@mastodon.socialJ This user is from outside of this forum
                                        jumpmed@mastodon.socialJ This user is from outside of this forum
                                        jumpmed@mastodon.social
                                        wrote sidst redigeret af
                                        #42

                                        @grwster @evacide @wdormann @0xabad1dea The difference is that we really don't have any laws on criminal liability for what software does. Up until the llm era, software was fairly predictable. An outside observer could tell if a package was designed to do something malicious. Now we need laws that essentially establish a "you should have known better" criminal liability for software.

                                        supermoosie@mastodon.auS 1 Reply Last reply
                                        0
                                        • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                                          I cannot get over that they STILL haven't figured out how to solve the problem that LLMs don't believe what date it is because all the good data cuts off a few years ago for some mysterious reason

                                          smn@l3ib.orgS This user is from outside of this forum
                                          smn@l3ib.orgS This user is from outside of this forum
                                          smn@l3ib.org
                                          wrote sidst redigeret af
                                          #43

                                          @0xabad1dea

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper