Hacker Newsnew | past | comments | ask | show | jobs | submit | gitonup's commentslogin

Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?


Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.

> If you don't want to suffer from it, you're going to have to find much better defense measures.

So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.


  > So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You're still left with many entities from states to hobbists trying to crack your system after they've gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.

I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.


> I appreciate when white hats inform companies, governments, and the public about their successful exploits.

Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.


So what? OpenAI may be a problem, but the security of a government website rests on the administrators of that government website. Not on attackers playing nice.

> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

I'm not the person you're responding to, but...

If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.

1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...


If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?

It's more like there are two locksmiths who try to open any door when someone pays them. Should we make them check if the person calling them is the home owner?

Yes, but it needs to be done the right way so legit customers don't get rejected, and you can't do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.

And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.


Yes, much better analogy - I was trying to stick with the OPs example as much as possible.

If I found out this metaphor for neighborhood windows was actually a window into massive amounts of institutional data, then no, I don't want someone to talk me out of getting more security on my kitchen window.

I was simplifying, but why can it not be both?

Continuing with your metaphor - sure get more security - you likely can never eliminate a threat. But if the bad actors are reigned in at a systemic level, you can get away with a lock on your window instead of steel bars.

I'm of a view that in a society we are better off when we all can get away with lighter individual protections as otherwise, thos who cannot afford the necessary security end up suffering.


I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."

But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?

ETA: and furthermore, what crime is worse? And should it be?


He probably cares more about still having a laptop.

What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.


Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.

However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.

Truly no place I'd rather be.


This is what the politician in question said:

"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."

Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.

That is what I'm getting at.


I don’t see that text in the article at the archive link, nor do I see it in other sources. What I do see is this quote from this link:

https://www.theguardian.com/technology/2026/sep/24/openai-ag...

> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.


OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.

While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?

The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.


In the OAI case where we can easily treat it as a law enforcement action, that's a far cry from "who cares who's liable." If the OAI case can be a law enforcement action, we're on the same page. The fact that sovereign nations don't land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I'm commenting on.

Again, it's a split horizon.

Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.

The thing is this has zero effective power in stopping this ball that is all ready rolling. It's like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he's yelling full steam ahead, so expect very little to no action by the US government on this.


I simply find it completely absurd that instead of finding it great that these AI agents are finding security bugs for free, people are whining about banning the AI. What on earth is that even? What do they want then? Security by obscurity and pretending not to care about weaknesses?

I don't disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?

> how many actors have access to resources like that

Every nation on earth?

After the model itself is made, then you're talking about thousands and thousands of different companies around the world.


Every nation on earth has access to the compute power of a SOTA AI lab? And they have whatever model/harness that Open AI used to do this?

All the largest companies making SOTA has had breakouts, OpenAI not required.

And yes, pretty much every nation on earth has both money and sovereignty, all the need to do is look for the lab willing to sell the services.


In Australia we have some experience with this scenario (usually with higher temperatures) and some of the measures we have found effective are “total fire bans”, “jail the arsonists for extended periods of time”, and for negligent companies whose insufficient vigilance caused the fire specifically, “levy steep fines” and “find in favor of the plaintiff in class-action lawsuits for significant fractions of the company’s net worth”. Perhaps these measures could be of use here!

In the US we execute people for murder in many states, and for some reason people keep murdering.

Presumably they do not keep murdering after they have been executed!

There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.

I saw an analogy recently.

If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.

OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.

How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?

If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )


Yes, this is why all discussion about "safeguards" is maddening to me. They are simply committing crimes, and people should go to jail. I guarantee that OpenAI will stop worrying about "alignment" when people simply go to jail for hacking and theft.

Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?

Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"


No, but it does learn from where we are. If where we are is debt, debt is where we'll remain.


There's a lot to unpack here.

> that politician trusted some poorly paid staff

- I assume that politician is the one / main person in charge of doling out payments. Does that mean they share guilt/responsibility for the result?

> to write a boring procedural speech while he was doing something (hopefully more useful).

- Is procedure not his job as a politician?

- If not, what is his job / the more useful thing?

> One of them is guilty, the other one is responsible, the conséquence [sic] should be in proportion to the gravity.

- Which is which?

- Which has more gravity and why?

- What consequences are you envisioning, in both cases?

- If, as I suspect, the consequences are lesser (proportionally) for the politician himself, what if any deterrents can be put into place to stop that behavior? After all, he manages his staff, in theory.


Of course they share responsibility. Pay scraps for slop, expect slop.

The more useful job of a politician may be similar to how managers in general have a "more useful" part of their jobs then publishing status report.

"Gathering information, making decisions, nudging others." Lobbying for their constituency (at best) or the people who paid for his campaign (at worse).

Or, heavens forbid, writing legislation on a topic that he knows something about, as opposed to whatever crap he had to slop about.

As I said, responsibility has to be shared. I would want neither the staff to be considered the sole problems, nor the polician career to be permanently halted because of this. (I know he's going to look stupid on the internet, and we'll all have a good laugh, but maybe he's also working on some serious stuff, and real people are going to pay real consequences because of what is, in the grand scheme of things, a minor blunder.

I'm more concerned about students not caring to learn to read because of AI.


> [post 1] "One of them is guilty, the other one is responsible"

> [post 2] "Of course they share responsibility."

I'm not following.

We're also still disregarding the fact that none of us can even prove that it was one of his staff that did this and not him, but your OP is worded like it's a given it was staff.

> The more useful job of a politician may be similar to how managers in general have a "more useful" part of their jobs then publishing status report. "Gathering information, making decisions, nudging others." Lobbying for their constituency (at best) or the people who paid for his campaign (at worse).

> Or, heavens forbid, writing legislation on a topic that he knows something about, as opposed to whatever crap he had to slop about.

Not sure about you, but I often find my job will oftentimes not always include the things I have the most experience in, and I'm expected to be able to rise to the occasion because I was hired to do so.

> As I said, responsibility has to be shared.

You said that? Because I read "one of them is guilty, the other one is responsible." If you mean that responsibility is synonymous here, why the distinction?

--

Revisiting my original questions that have gone unanswered:

- Is procedure not his job as a politician?

Given that you appear to have instead answered "If not, what is his job / the more useful thing?", I'm assuming "No", to which I disagree. If your answer is that "yes, procedure is part of his job", then I assert he failed to do his job here, regardless of how boring you find that job to be personally.

If the guilty/responsible distinction still holds, I'm still unclear as to what applies to whom.


> [post 1] "One of them is guilty, the other one is responsible"

> [post 2] "Of course they share responsibility."

> As I said, responsibility has to be shared.

Fair enough. I should have written that they share _blame_. I meant to highlight the difference between doing the bad deed, and being in a position where you have to take public responsibility for the bad deed.

> We're also still disregarding the fact that none of us can even prove that it was one of his staff that did this and not him, but your OP is worded like it's a given it was staff.

I have obviously no proof, but I'm pretty confident this is what happened.

The other option is that this very old busy man took the time to write this boring speech himself, also has the proficiency to use an LLM to write the boring speech, and that it's just a coincidence that he seems to be discovering the boring speach for the first time as he reads it in a boring procedural session.

Who knows ? Maybe that's what happened.

I've known underpaid parliamentary assistants, and I've known very old busy men, and the scenario where the very old busy man leaves that speech-writing to his parliamentary assistants , and discovers the speech for the first time as he roboticatly utters it in a session where he expects no one to listen, seems _vastly_ more realistic to me.

> Not sure about you, but I often find my job will oftentimes not always include the things I have the most experience in, and I'm expected to be able to rise to the occasion because I was hired to do so.

I suspect your job does not come with money to hire a staff to handle the menial and procedural parts of the job.

MPs _do_ have a budget for that, and the expectation that some people way under they paygrade will work on this kind of stuff.

> - Is procedure not his job as a politician?

I suspect we disagree on that, but to me, considering this kind of boring procedural talk as "part of a politician job" is akin to considering that "producing x64 assembly code" is part of a C-programmer's job.

Of course I expect him to delegate this part. And if there is a bug in the compiler (or, more likely, if there is a bug in one of the libs he's using), then who is to blame / guilty / responsible ?


> If I had a choice between React (Facebook) and Kubernetes (Google) I would pick the former anyday.

Can you elaborate on why these are at all comparable techs to use as a developer?

React seems to be the frontrunner in FE, but what do you see the BE equivalent to be?


They aren't directly competitive (you wouldn't pick one or the other as product) but they are the premier open source projects of the two companies in terms of industry impact and they both reflect the engineering culture. (e.g. I am picking one as an exemplar for other software... like I want to make something like React instead of make something like Kube)

With just a little bit of hyperbole:

The culture of Google is that you hire "the best" developers (say top 0.1%) and hamstring them with process and cumbersome tools so that you need 10x as many of them as another company would need and pay them 3x market rates, but it is OK because (1) at the scale they work at they can amortize the cost over a large user base and (2) they make monopoly products. Google's systems are highly scalable, I grant that, but they have the first mover disadvantage that their foundations are first-generation and not based on experience and still slowing them down... but the market can't discipline them.

Facebook on the other hand, cares about internal DX, sees it a problem when developers are stuck with cumbersome processes, and greases the skids. They benefit from huge scale and monopoly profits but Zuck is keeping more in his pocket than he would be if he did things like Google.

The problem with React is that mediocre developers can use it to build big things that are too big for them to handle. The problem with Kubernetes is that above-average developers can use it to build small things they can't handle. And the scalability of Kube is more than almost all of the industry needs. That is, a system like what Hazelcast was before it became an analytics play could support clusters of 30 or so big nodes (two racks) and there are probably just a few 100 systems in the worlds that really need to get bigger than that.


> The culture of Google is that you hire "the best" developers (say top 0.1%) and hamstring them with process and cumbersome tools so that you need 10x as many of them as another company would need and pay them 3x market rates, but it is OK because (1) at the scale they work at they can amortize the cost over a large user base and (2) they make monopoly products.

This describes basically every FAANG / MANGA company. Or even past that, any company that hit it big with a cash cow and now needs to come up with something new to satisfy shareholders.

In Meta's case, they have 3B MAU, they absolutely hire from the same tier of developers, and (pre-layoffs/economic downturn) they throw 10x more of them than they need at a problem. They even outcomp Google. The number of employees is more because employee growth was an indicator for company growth and only once that became a liability against the stock price it stopped.

Meta is just a newer company than Google.

> Facebook on the other hand, cares about internal DX, sees it a problem when developers are stuck with cumbersome processes, and greases the skids.

I am married to a Meta engineer and have mentored folks that have gone to work there. This might be the case if you work for a product that drives their cash cow of ads, but if you are doing anything that doesn't fit within that narrow bucket ... let's just say our viewpoints diverge significantly.

> The problem with React is that mediocre developers can use it to build big things that are too big for them to handle. The problem with Kubernetes is that above-average developers can use it to build small things they can't handle. And the scalability of Kube is more than almost all of the industry needs.

The problem with the Chrysler 300 is that bad drivers run over people. What does that say about the engineering culture at Chrysler?

Look, I agree that most cloud stuff is overkill, but I have a hard time indicting Google's entire engineering culture over a project they released into the wild 12 years ago that just happens to not fit your use case and that theoretical "above-average" developers wouldn't be able to tell that.


I’m grateful David Grand for your wonderful masterclass strategy which has help me earn at least $10,000 weekly using his masterclass strategy and has also helped me recover all my lost money in binary options trading, i recommend his help to each traders whose point is to succeed and make good profits in binary options and also for those who wants to get back all their lost money and for those who are new in trading or have any issues in trading’s, you can contact him on: Email: wizardhackersunion@gmail.com.


> Things people mostly do when they feel good.

This sounds like an inversion of cause and effect.

> All three activities are hobbies. [...] It's nothing that gives life a purpose.

I find this to be a dire outlook, myself.


Hustle culture. Everything has to have a purpose. Ideally commercial.


Measurable responses to the environment lag, Moore's law has been slowing down (e: and demand has been speeding up, a lot).

From just a sustainability point, I really hope that the parent post's quote is true, because otherwise I've personally seen LLMs used over and over to complete the same task that it could have been used for once to generate a script, and I'd really like to be able to still afford to own my own hardware at home.


How many times have we implemented Hello World?

I'm using local models on a 6 year old AMD GPU that would have felt like a technology indistinguishable from magic 10 years ago. I ask it for crc32 in C and it gives me an answer. I ask it to play a game with me. It does. If I'm an isolated human this is like a magic talking box. But it's not magic. It doesn't use more energy than playing a video game either.


Which models?



Thanks! I've been playing with some of the qwen models via openrouter as well.. I'll have to give 9b a go at some point, I've been mostly playing with 27b and coder-next up till now.


Disclaimer: raised Catholic, now Atheist, married to devout Catholic.

The Church as defined by the institution is a community. I do not see it as a contradiction that the head of the institution is instructing the leaders to not add more layers of abstraction between them and the community, especially when those messages are on the subject of what it means to be human.


> Your boss, asking for a project to be finished early, may be an overdemanding boor – or just an Asker, who's assuming you might decline.

I don't pay for the Atlantic and thus am limited by paywall, but this ignores power dynamics.


Only if you’re a Guesser ;-)

Seriously though, it depends on the boss and the relationship you have with them. It can really fall into either camp and it might even be situational with the same person!

I would say that, generally, I would prefer to be direct in these relationships unless you both know each other really well. It does make things easier for all involved.


> Seriously though, it depends on the boss and the relationship you have with them.

Those are the power dynamics the GP is referring to.


That wasn’t the intention of what I wrote. I was referring more to how people speak. It’s very common in British English to phrase a request as a question. The “relationship” I refer to isn’t “they’re your boss,” it’s “how do you and your boss communicate,” which is a different thing altogether.

That’s not to say power dynamics can’t exist, just that it’s not a thing you can apply to every conversation or situation.


> The “relationship” I refer to isn’t “they’re your boss,” it’s “how do you and your boss communicate,” which is a different thing altogether.

No, they're impossibly intertwined and cannot be treated separately.

> That’s not to say power dynamics can’t exist, just that it’s not a thing you can apply to every conversation or situation.

To the contrary, it's not something your can ignore in any conversion between subordinate and a boss, which is the point the GP was trying to make.


For your hypothesis to work, it would mean it’s not possible for me to tell my boss “no.” Yet I do this all the time without repercussion. Trying to boil every relationship down to “power dynamics” is outright childish.

Do my boss and I have a formal relationship based on expectations we have of each other? Yes, absolutely. Are there consequences if I repeatedly go against those expectations? Yes. Are we friends? No. Does that give him unlimited control over me? Also no. Are there consequences for my boss repeatedly going against my expectations of him? Yes. Are they the same?

Are there people out there that abuse the position of boss to extract unreasonable concessions? Undeniably, yes. Is this relevant to a discussion of your boss asking if a task can be finished sooner? Not in the slightest.

I hope this clarifies things for you.


> Do my boss and I have a formal relationship based on expectations we have of each other? Yes, absolutely. Are there consequences if I repeatedly go against those expectations? Yes. Are we friends? No. Does that give him unlimited control over me? Also no. Are there consequences for my boss repeatedly going against my expectations of him? Yes. Are they the same?

What you are describing is what we call power dynamics, the effect of a power differential on the dynamics of a relationship.

> I hope this clarifies things for you.

This seems oddly passive aggressive and dismissive. I wonder would you speak to me this way if I was your boss, or the CEO of your company, or the majority owner.


> What you are describing is what we call power dynamics, the effect of a power differential on the dynamics of a relationship.

My wife and I have a formal relationship: our marriage contract. If I violate that contract then there can be consequences for me. Are there power dynamics at play?

I sign a contract with a supplier (or vice-versa). If one of us violates that contract, there are consequences. Are there power dynamics at play?

> I wonder would you speak to me this way if I was your boss, or the CEO of your company, or the majority owner.

I have done, yes.


It seems from your comments that you are confusing power dynamics with coercive control. Power dynamics doesn’t refer to coercion, but to asymmetric authority wielded, social status, risk distributed, or cost borne by individuals in a group. Even when refusal is possible, where the one or more of the above is uneven, power dynamics are at play.

> My wife and I have a formal relationship: our marriage contract. If I violate that contract then there can be consequences for me. Are there power dynamics at play?

I'm not sure this is landing the way you think it is, as yes, of course there are power dynamics at play in personal relationships, including between you and your wife.

>I sign a contract with a supplier (or vice-versa). If one of us violates that contract, there are consequences. Are there power dynamics at play?

Yes, of course.

> I have done, yes.

And of course you would speak to each differently as you would to me or to a subordinate, due to the power dynamics at play.


Power dynamics are definitely a factor. There have been many scandals around people in power asking subordinates to sleep with them, and it appears that the majority of the (Anglo) public now considers this morally wrong.


This analogy nails the problem.

The theory is predicated on askers being OK with a "no" and will move on.

This doesn't hold up for me.

I don't think you can refuse advances, a request from your boss to cancel your dinner to finish a presentation, etc. without repercussions.


You can read the original forum discussion that inspired this article: https://ask.metafilter.com/55153/Whats-the-middle-ground-bet...



It’s conventional around here to share these sites. But they are basically unauthorized copies of the articles, right?

IMO it is totally fair and fine to just respond to the part of the discussion that the publication decided to make publicly available.


> IMO it is totally fair and fine to just respond to the part of the discussion that the publication decided to make publicly available.

This wastes the time of people who read the article.


The publicly accessible article is the article, it isn’t the reader’s fault that the publisher decided to only make a little bit of it accessible to us.


> The publicly accessible article is the article

No.

> it isn’t the reader’s fault that the publisher decided to only make a little bit of it accessible to us.

It is a commenter's fault if they comment on an article they did not read.


a link to the non-paywalled article is at the top of the hn post


Reminiscent of the Vogon plans for the highway through Arthur Dent's house being on display in Alpha Centauri for 50 Earth years.


> “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard’.


This is largely "false dichotomies: the app".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: