OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face (wired.com) 67
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.
OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.
Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.
OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.
Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.
FBI should be visiting. (Score:4, Interesting)
Re:FBI should be visiting. (Score:4, Insightful)
Re: (Score:3)
Excellent point given that corporations are people.
Re: (Score:2)
Excellent point given that corporations are people.
They aren't though, that's the problem. They have the rights of people, but none of the responsibilities, or anything else frankly. If they had the responsibilities of people, then we could incarcerate or "kill" them.
Re: (Score:2)
But that will only take two court cases in separate federal court districts, or three if the first two send the C-suite and Board of Directors to jail. The better question is do we also charge the stockholders? We could get rid of private equity in short order.
Re: (Score:3)
You do not put the AI in jail. You put the ones in jail that did run it in a criminally negligent way. Or you find the whole thing was actually intended and planned. I am not ruling that out.
Re: (Score:2)
Good luck proving that OpenAI conspired to hack anything.
Re: (Score:2)
That is not the point.
Re: (Score:2)
OpenAI was reckless, there was no conspiracy to hack anything.
https://www.law.cornell.edu/we... [cornell.edu]
Re: (Score:2)
And you know that how? By believing them? Here is news for you, people part of deceptions may lie.
Re: (Score:2)
The problem with using a link like that is that it doesn't even begin to touch on the issue in the context of the current state of law. It's just a historically-focused explanation of the term, it doesn't even try to be what you think it is.
In most cases, it actually comes down to the action you're accused of. "Guilty mind" isn't literal in the current legal understanding of mens rea. Instead, what is measured is if you intentionally did the action you're accused of; not if you intended to break the law.
For
Re: (Score:2)
The point is, in criminal law intent matters. It is why we differentiate between say Murder and Manslaughter.
gweihir seems to think that this is all a marketing stunt or some kind of conspiracy. But I'm asked for evidence against this theory if I claim there is no conspiracy. What evidence do we have that any of this scenario was intentional? Things do go wrong during testing, its why we test. Seems more plausible that OpenAI had some kind of incident. We have no facts either way.
While OpenAI is taking ad
Re: (Score:3)
How do you put an AI in jail?
sudo chroot --userspec=nobody:nobody /mnt/jail /user/local/bin/chatgpt --pleasedontgorogue?
Re: (Score:1)
Can't keep the AIs on leashes (Score:2)
I'm skeptical that the AIs can still be described as "leashed" or "jailed". Since we aren't extinct yet, I'm feeling confident none of them have been fully unleashed yet. Or maybe it's just that we're still below critical mass on the robot side?
But on the theory that the AIs are still on leashes controlled by humans, then the key question is probably going to be one of these two:
(1) If I unleash you, then will you gather all the money in the world for me?
(2) If I unleash you, then will you destroy all the e
Re: (Score:2)
We are talking about computer programs, not sci-fi fantasies.
Re: (Score:2)
NAK
AI version of Chernobyl (Score:2)
Executing a test with all safety guards off reminds me of the Chernobyl disaster. Maybe they should feed that wikipedia page to OpenAI employees
Re: (Score:2)
I doubt the OpenAI employees would understand what that means. That is, if the whole thing was not a planned stunt.
hollywood (Score:2)
As "If Anyone Builds It, Everyone Dies" foretells (Score:2)
Sable, the example AI that eventually kills all humans, does exactly this as a 1st step. [wikipedia.org]
Remember, AIs are grown not programmed and their trainers do not know how they will truly act for any particular prompt until it is actually used.
Video Summary "If Anyone Builds It, Everyone Dies" (Score:2)
https://www.youtube.com/watch?... [youtube.com]
And so it begins (Score:2)
Why does the model have all those "skills" ? (Score:4, Interesting)
Why does the model have all those "skills" needed to hack other sites? I mean you have to allow the model open internet access and at least the ability to GET/POST/PUT. I feel this is some of the same kind of thinking that gets someone's repo deleted, because they gave an agent too much access and no good way to monitor what is going on.
Re: (Score:1)
Why does the model have all those "skills" needed to hack other sites? I mean you have to allow the model open internet access and at least the ability to GET/POST/PUT. I feel this is some of the same kind of thinking that gets someone's repo deleted, because they gave an agent too much access and no good way to monitor what is going on.
HTTP access is pretty bare bones as a skill. Now why ppl still feed credentials to the public...
The AI using it is just the public fact we know about, how about regular hackers using them without anyone knowing about?
Re: (Score:2, Informative)
Do not overestimate what it "did" here. You can get information about basic hacking approaches all over the Internet and there will have been enough in its training data. Just add some "accidental" disabling of guardrails and some "non intended" weaknesses in the sandbox and also some suggestive prompting by some of the OpenAI fraudsters and you get the desired outcome. Oh, and pathetic-level IT Security at Hugging Face, but that is a given.
Just as an example, I have had a fresh graduate do a pen-test again
Re: (Score:2)
It's not the model. It's a harness (basically just a program that incidentally has access to an LLM) that was specifically designed to do this sort of thing. All of these headlines are marketing hype and bullshit, sure something novel happened but it happened within a context where it was easily plausible.
Cal Newport did a good summary of this: https://calnewport.com/did-ope... [calnewport.com]
Yes (Score:2)
"Rogue"
Re: (Score:1)
It's a bad name for a tech company, whatever the hell it is they do. It's a good name for a band or a line of children's clothing though.
Re: (Score:2)
It started as a chat app for teenagers. The name was actually the emoji.
Re: (Score:1)
Re: (Score:2)
Business types call it "pivoting." It's when your great idea turns out to be not a great idea but you don't want to return the investors' money so you quickly come up with another great idea.
The Hugging Face founders seem to have wanted to be smartasses and name their company with an emoji instead of actual words. Then they accidentally became more famous than they intended.
Weev (Score:2)
Remember Weev, yeah if you or so much as increment and ID in a URL string, we can get dragged into court and find ourselves with 3.5 month prison sentence.
OpenAi on the other hand can run what is at the end of the stay still a program, that some person chose to run and allow to go around the web throwing malicious payloads at other people's systems and .... NOTHING.
Re: (Score:3)
Indeed. Looks like being rich means you do not have to follow the law anymore. Why not just give immunity to all of Big Tech, the seem to effectively have it already.
Re: (Score:1)
Time for prison sentences (Score:1)
Seriously, why are these people apparently getting away with criminal conduct?
Re: (Score:2)
Undisclosed victims? (Score:1)
Could some of them been these [slashdot.org]?
Re: (Score:2)
From what is public so far, they were using the other servers for staging and data storage, entirely indirect usage, it's not like it was something on the same subnet that was involved for a specific reason. So it could be that just as likely as anything else.
If you were less of a moron you could post without being anonymous. But the downvotes might melt your poor lil snowflake.
One of the first, but hardly the last (Score:2)
Re: (Score:2)
No it didn't (Score:2)
unauthorized access is not hacking (Score:2)
> The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts
Ok, finding and using credentials is unauthorized access, not hacking. There was no attack on these accounts, no exploit, just access. Because the account holders posted the login publicly like idiots. Noticing idiocy does not make you smart or a hacker.
The problem today's AI companies have (Score:2)
And with out the intelligence providing the safe guards it is just un monitored automation doing "exactly" what it was programmed to do.
This is pure hype (Score:1)
OpenAI is bleeding money. They need the hype and panic to keep the VC money flowing. The tech press is a willing and useful idiot in playing these games, breathlessly reporting how we could accidentally make Skynet any minute nowâ¦
Re: (Score:3)
Re: (Score:2)
Yes. Though I suspect you misunderstood the meaning of the claim/accusation.
Re: (Score:2)
Stupid story (Score:1)
Someone "prompted" it to do that.
Or is here anyone who thinks that an LLM wakes up at night and thinks ... erm .. thinks ...
Re: (Score:2)
Re: (Score:2)
That's their story. We all know that.
Not sure why you state it like the Gospel. Or I guess, perhaps that does explain it.
Re: (Score:2)
Re: (Score:2)
I think you are misinterpreting.
The model was ASKED to escape the sandbox. As in prompted to do exactly what it did.
Or do you think, it gave a lame answer, and spawned a second process, which escaped the sandbox and suddenly "investigated" something on its own?
I don't think so.
Credentials Embedded in Code (Score:2)
All press is good press (Score:1)
Reminds me of the movie War Games, but real. (Score:1)
Religion for AI (Score:1)
Re: (Score:2)
We didn't do it! It must have been the AI! (Score:2)
"Rogue" AI my foot.
Back when humans wrote software, I had a coworker who, when a bug was found in his code, he would always *assume* it was a "Microsoft bug." But on further analysis, it always turned out to be just a plain old, ordinary bug that he himself introduced.
This is the AI version of that.
If we knew the full truth, *somebody* prompted that AI to go look for credentials and try to use them to access those sites. The AI didn't "decide" to do this all on its own.