It says the tool connected to a public endpoint and was able to access the back end without authorization. At face value this is no different than drive-by security research with disclosure.
What if your dog just growls at a kid, maybe even barks or snaps, but doesn’t touch anyone? Sure, the kid is scared, but it’s not illegal without a very convincing argument in front of a judge, and even then…
I can’t see the letter anymore (the site seems to be down) but unless this is a published public API or they have a public “bug bounty” program and the API was following the rules of engagement, and it did not sound like either was true, then this is hacking and illegal, at least in the jusidiction I’m in.
The next step should be to press charges on openAI, unauthorized hacking into computer systems is illegal.
Absolutely. How is this any different from a hacker writing a script? We need to stop being fascinated and start prosecuting.
It says the tool connected to a public endpoint and was able to access the back end without authorization. At face value this is no different than drive-by security research with disclosure.
From what I understand hacking crime requires intent and it’s hard to prove that company testing AI agent intended to hack something.
They trained it to do exactly that and then gave it unrestricted internet access, otherwise it wouldnt. Its at least gross negligence.
If I train my dog to attack people, then I poorly restrain my dog and my dog attacks someone, I’m still liable
What if your dog just growls at a kid, maybe even barks or snaps, but doesn’t touch anyone? Sure, the kid is scared, but it’s not illegal without a very convincing argument in front of a judge, and even then…
If you put out a publicly available set of doors and I open one to find your attack dog, isnt that your fault?
I wish people would go the other way and fix the damn security flaws. Witch-hunting people who disclose vulnerabilities needs to stop.
I know that’s not why OpenAI are doing this but if it helps reverse this moronic trend so be it.
(There’s also the part where OpenAI need to be held responsible for any damages done by their agents, and I’m all for that.)
When does it go from trying to figure out how the rest endpoint works to hacking?
I can’t see the letter anymore (the site seems to be down) but unless this is a published public API or they have a public “bug bounty” program and the API was following the rules of engagement, and it did not sound like either was true, then this is hacking and illegal, at least in the jusidiction I’m in.
It was a government website, so it should be public.
Realistically if there is a service available on the internet I think we should be able to assume its public.