logoalt Hacker News

cmiles8 • today at 5:50 PM • 8 replies • view on HN

This seems like as a good an opportunity as any to break out the Computer Fraud and Abuse Act.

They want “regulation” but we already have it. Hacking is illegal. Start locking up those responsible for this mess and I assure you they’ll “have a handle on it” quite quickly.


Replies

i2talics • today at 6:29 PM

IMO: The inability to prosecute OpenAI for these things is proof that the AI industry is already "too big to fail". Why didn't HuggingFace try to seek legal liability against OpenAI when it had explicit confirmation that they had been hacked? Because HF understands that it needs OAI and the rest of the AI industry to continue to exist and be in good legal standing, for the interest of HF's own self preservation. This is what it means for something to be too big to fail.

➕ show 7 replies
john_strinlai • today at 6:15 PM

cfaa heavily relies on intent for prosecution (hence why researchers arent typically locked up). it would be difficult to argue that openai intended to hack other companies.

there's probably better/more likely to succeed avenues to pursue rather than the cfaa

➕ show 3 replies
semiquaver • today at 6:59 PM

> Hacking is illegal

I am not a lawyer, but I seriously doubt the feds could win a CFAA conviction on the Hugging Face fact pattern, even if they wanted to charge it.

CFAA has specific intent requirements, and unlike some laws, negligence does not suffice. The agents can not have legally cognizable intent and it’s unlikely there’s anyone at OpenAI who intended for the hacking to happen (if there was, the case is easy).

Existing laws don’t contemplate AI agents that have independent goals. We need new ones, the existing laws are not remotely sufficient.

➕ show 2 replies
eurekin • today at 6:23 PM

I still can't fathom my company application security decision. Found pretty damning requests in our logs. Escalated. Expected it would result in at least reporting the TOS break from the originating place (one of cloud providers). Instead of that, they just went: "yeah, but we don't have logs". Provided them. "Yeah, but that ip doesn't resolve". I matched real ones from the load balancer. "There could just be many of them". There was one. When I had all the evidence gathered, they looked at me and finally told:

- It's just an Independent Security Researcher.

- So that's it? You will do no action?

- Correct

nickff • today at 7:54 PM

There is almost no will to prosecute big-business shenanigans until the scheme or organization collapses. See back-dated options during dot-com, SBF-FTX, Libor scandal, etc.

egillie • today at 5:56 PM

can we legally treat ai companies like parents of children? if a child drives a car into a storefront, the parent is responsible for the damage, and at some point you might even criminally charge the parent if there was gross negligence

➕ show 2 replies
meowface • today at 6:16 PM

That would require mens rea. This may be criminal negligence, but it wouldn't be more than that. (I am basically 100% sure none of the employees or execs are intending or desiring any of these outcomes, regardless of the very large number of people who believe in conspiracy theories about regulatory capture and other sinister motives.)

I'm totally on board with treating it as gross negligence requiring hundreds of millions or billions of dollars paid in fines and compensation to victims, but don't act like this is more than what it is.

➕ show 1 reply
cyanydeez • today at 6:14 PM

But wouldnt that be bad for the shareholders? Why wont anyone think of the economic impact to the vulner billiinaire minority?