logo

OpenAI agents carried out an undisclosed attack on RubyGems

Posted by chao- |5 hours ago |20 comments

jsnell 4 hours ago

I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.

It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this should have lit up like a Christmas tree in the investigation. How many more incidents do they know about and didn't disclose?

hgoel 4 hours ago

I wonder how much of this is intentional "incompetence" so they can justify the most recent campaign to build a regulatory moat against competition.

The repeated refusals to disclose until caught certainly seem malicious, yet at the same time the boasting about their capabilities is also at an all time high.

throwatdem12311 4 hours ago[1 more]

Look. We need to put people in jail for letting this happen.

dvt 4 hours ago

So OpenAI is basically just DDOSing now? Any idiot could do this with a zillion dollars, so it's not even technically impressive at this point.

nonconstant 4 hours ago[1 more]

Kudos to RubyGems team for handling it, but open source fighting off the AI lab-powered robots is completely unfair.

OpenAI should at the very least donate large sums of money to everyone they attacked.

zmmmmm 4 hours ago

It seems like all this happened in the same time period earlier this year. It makes me wonder if all of these were part of a single larger incident where multiple experiments were run with insufficient or missing constraints or an unknowningly misaligned model.

dmix 4 hours ago

It’s interesting how so much of this OpenAI stuff being reported involves ruby.

toomuchtodo 4 hours ago[1 more]

Is it feasible to black hole traffic from OpenAI? Or do their agents egress from hyperscaler IP space?

gverrilla 4 hours ago[2 more]

Is there a world where Sam or Dario can seize the bitcoin network somehow?

enraged_camel 5 hours ago[4 more]

Every passing day OpenAI looks more and more reckless. One wonders what other systems their agents have broken into without detection.

creatonez 4 hours ago

You shouldn't be allowed to have an internet connection if you're going to use it for unsandboxed agent slop with no access controls or human confirmation. This has nothing to do with hypothetical future AGI. It's the same type of idiocy as pressing a bunch of random buttons on a chemical factory control panel and then thinking you won't be criminally charged for it because the equipment caused the problem.