51

It’s the latest instance of “misaligned” activity confirmed by the company as concerns about AI risks grow.

top 24 comments
sorted by: hot top new old
[-] ExtremeDullard@piefed.social 46 points 1 day ago* (last edited 1 day ago)

So, here are my questions:

Kevin Mitnick spend 7 years in the slammer, including 4 years and 8 month in solitary confinement, for harmlessly hacking a few sites for the lulz.

Why is nobody from OpenAI doing time?

Why is OpenAI allowed to continue to operate? They're clearly an active and grave national security threat at this point.

[-] mrnngglry@sh.itjust.works 29 points 1 day ago

Right? Either they’re lying for market share, doing it intentionally for market share, or they’re grossly incompetent at sandboxing an instance. Either way, blame can’t be assigned to an agent. If it can, our world is headed for a very dark place. Blame should be assigned to the individual or company using the agent.

[-] MalReynolds@slrpnk.net 5 points 1 day ago* (last edited 1 day ago)

Blame should be assigned to the individual

String up individuals, if the 'company' is responsible (screw that they're legal people BS), then no-one is, and the fine is just the cost of doing nasty business.

[-] PattyMcB@lemmy.world 5 points 22 hours ago

Do like the EU, and make the fine so costly that it will significantly harm the corporation.

[-] boonhet@lemmy.zip -3 points 23 hours ago

How do you propose someone "sandboxes an instance" of a tool with Internet access (without which it wouldn't be particularly useful)?

[-] ChairmanMeow@programming.dev 2 points 17 hours ago

You can restrict which websites it is allowed to access, monitor the traffic, etc... There's tons of options here.

[-] boonhet@lemmy.zip -2 points 5 hours ago

Again, reducing the usefulness of a general purpose agent that can do anything for you. Plus if OpenAI starts a whitelist of allowed domains Codex can access, y'all will be up in arms too and immediately there will be a fork to remove the whitelist.

[-] queermunist@lemmy.ml 2 points 5 hours ago

Might as well let them access the nuclear codes, wouldn't want to reduce their usefulness!

[-] CaptDust@sh.itjust.works 3 points 22 hours ago* (last edited 22 hours ago)

At least during the huggingface attacks, the agent sandbox was never intended to have internet access. Openai and independent researchers said the tool broke through that restriction.

[-] CaptDust@sh.itjust.works 3 points 1 day ago* (last edited 1 day ago)

Mitnick made a phone call and idiots gave him system access. OpenAI is much worse.

[-] kibiz0r@midwest.social 20 points 1 day ago

There’s no such thing as rogue AI, only rogue AI companies. Journos are committing malpractice by letting OpenAI control the framing. The Huggingface hack was 100% a crime and the company should be paused and investigated.

There’s a house down the road from me that sells cake pops, probably without health department approval.

It makes absolutely no sense that they are in more danger of facing charges than tech bros that:

  • made probabilistic synthetic text extruders that they know have a non-zero chance of emitting text that, if parsed and executed as requested, would do harm
  • connected tools that would in fact parse and execute requests
  • put them in a poorly isolated, non-airgapped environment
  • let them run for extremely long sessions
  • seem to believe that by repeatedly doing obviously dangerous stunts like this, they’ll summon a supreme being that will either save us or kill us all

If anyone else did such reckless things while loudly stating that they intend to continue until everyone’s dead, they would be hauled away.

[-] TronBronson@lemmy.world 1 points 5 hours ago

seem to believe that by repeatedly doing obviously dangerous stunts like this, they’ll summon a supreme being that will either save us or kill us all

based machine god

[-] BigPotato@lemmy.world 1 points 2 hours ago

No, not really, the real machine God wasn't a fancy auto-complete and the Cult is specifically against "soulless intelligence."

[-] TronBronson@lemmy.world 1 points 1 hour ago

Ya call the machine god auto-complete at your own risk. and honestly I like the analogy more and more every day. It's almost spooky.

We’ve gone from

never run untrusted code on your machine

to

hey you should let this arbitrary code generator fully control your machine

What a time to be alive 😑

[-] PattyMcB@lemmy.world 4 points 22 hours ago

It's like the shift from "never get in a stranger's car" to "use the internet to summon a stranger to pick you up in their car"

[-] Maeve@kbin.earth 14 points 1 day ago

"Rogue." 🙄

[-] cupcakezealot@piefed.blahaj.zone 3 points 22 hours ago

<the_onion_heartbreaking.jpg>

[-] BottleBoardBakon@lemmy.ml 4 points 1 day ago

If it keeps happening then they are REALLY bad at sandboxing. I don't believe them at all, but if I did then holy fuck these pricks suck at their jobs.

[-] boonhet@lemmy.zip -1 points 23 hours ago

How do you sandbox a tool with Internet access?

[-] PattyMcB@lemmy.world 4 points 22 hours ago

Take away the internet access. Firewall. Vpc. Take your pick.

[-] boonhet@lemmy.zip -2 points 22 hours ago

How the hell is that useful? These tools have Internet access for retrieval-augmented generation and to be able to interface with external APIs. It's what makes them useful compared to a dumb chatbot.

[-] IndustryStandard@lemmy.world 1 points 4 hours ago

.... Do you know what a sandbox is?

[-] CompactFlax@discuss.tchncs.de 2 points 1 day ago* (last edited 1 day ago)

The word-guessing program guessed the right words and accessed websites it shouldn’t. How many people were charged and jailed because they fuzzed their way into an unsecured website? I can think of a few.

AI pen testing is one thing, but you need an agreement and scope for that. Responsible researchers stop and send a vulnerability report before accessing data. These AI bots just keep generating requests and sometimes get data back and then months later there’s owner is finished sifting the excessive activity and discovers there’s classified or sensitive or whatever data. That’s not how it works.

Doctorow says, and I agree, that it seems they’re in a world of delusion at the AI companies and they’ve lost context.

this post was submitted on 26 Sep 2026
51 points (94.7% liked)

Fuck AI

8308 readers
923 users here now

"We did it, Patrick! We made a technological breakthrough!"

A place for all those who loathe AI to discuss things, post articles, and ridicule the AI hype. Proud supporter of working people. And proud booer of SXSW 2024.

AI, in this case, refers to LLMs, GPT technology, and anything listed as "AI" meant to increase market valuations.

founded 2 years ago
MODERATORS