Forgot your password?
typodupeerror

Comment Re:Ax problem (Score 1) 33

Sorry, but this just isn't true.

Plenty of other countries have negligent hacking coverage

Sorry, but such a thing is essentially nonexistent in cybercrime statutes. I can't say "entirely nonexistent", as I can't rule out that in the legal code of some country, like, say, Chad, that there may be an exception, but it is for all effective purposes basically nonexistent in law.

"Unauthorised access" in the UK sense doesn't require any intention, just that you don't access a system in a standard way with credentials assigned to you.

Completely false. In the UK, the statute governing hacking is the Computer Misuse Act 1990 (CMA). Under the CMA, section 1, a person commits an offense if and only they:

A person is guilty of an offence if—

(a)he causes a computer to perform any function with intent to secure access to any program or data held in any computer [F1, or to enable any such access to be secured];

(b)the access he intends to secure [F2, or to enable to be secured,] is unauthorised; and

(c)he knows at the time when he causes the computer to perform the function that that is the case.

(2)The intent a person has to have to commit an offence under this section need not be directed at—

(a)any particular program or data;

(b)a program or data of any particular kind; or

(c)a program or data held in any particular computer.

Stop trying to make "negligent hacking" into an actual crime. It doesn't exist in criminal law.

Re, Australia:

In Australia OpenAI would have most definitely broken the Criminal Code (1995) Part 10.7 - Computer access with multiple examples of it's antics except... the very first line of every subdivision of the law is: "A person commits an offence if:"

Once again, no. Just as in the US and the UK, Australia has no "negligent hacking" statute. Every relevent offense under Part 10.7, incl. Section 477.1, 477.2, and 478.1, requires a proof of fault element. 478.1 for example requires that the defendant knows the access is unauthorized and acts deliberately.

Under Chapter 2 (General Principles of Criminal Responsibility), if a statute does not expressly designate an offense as strict liability or absolute liability, the default fault elements are intention, knowledge, or recklessness. Negligence - which is defined in the code - is never a standard in Part 10.7 computer offenses. And if you want to upgrade from negligence to recklessness (something unusual in Australian cybercrime law, not found in US or UK cybercrime law), the person being charged has to have had prior knowledge of "a substantial risk that the result will occur" - not that "some arbitrary bad thing might occur in general because these things are dangerous, and our security is lax" (that's negligence, and not chargeable under part 10.7), but of the specific event being charged occurring. Unless you thought that OpenAI specifically thought, "If I run this benchmark, these bots are likely to specifically secretly convert our software repository into a messaging board and coordinate their actions to specifically hack HuggingFace (and our own servers) to steal answer keys", no, they do not meet that standard.

The reason OpenAI would not be charged is not because of some semantic trick around the word "person" (obviously you never charge tools), it's because they lack the mens rea for the crime. Intent. You have to have mens rea - in the US, in the UK, in Australia, and elsewhere.

Comment Re:Today I learned (Score 1) 12

I assume that Denmark's system is similar to our kennitala ID system. The big difference between a kennitala and a social security number is that a SSN is both an key and a password, while a kennitala is purely a key. Kennitölur are public. You can't "do anything" just by having someone's kennitala. Combining both a key and password into a single number is insane from a security perspective, IMHO.

Anyway, this headine would have been more fun if the words were rearranged:

Database Records: Citizens' Hackers Steal 8 Million Danish From Government

Comment Re: Ax problem (Score 1) 33

"If an automated delivery bot crashes into a window and causes damage, the owner / operator of the bot would be liable." - that is civil liability.

". If the owner crashed into 1000 windows over months after already being alerted that was happening, they would likely be criminally liable. " - No. This is a popular misconception. "Criminal negligence" is not a standalone crime, nor something you can append to an arbitrary statute. It must exist in the statute in question. In general, it only exists in statutes related to bodily harm. There is no such thing as negligent hacking in US criminal law.

As for your actual example: if the operator knows the bot has a bug where it occasionally swerves into windows, but keeps operating it because it's profitable, that is reckless disregard / gross negligence, a civil violation. It is a textbook example of a tort warranting punitive damages and likely an immediate injunction shutting down the fleet. It is not "criminal property damage" unless the locality specifically has created a criminal statute that specifically criminalizes negligent operation of unmanned vehicles.

I'll repeat, and you must understand this: "criminal negligence" is not a standalone law or something you can just tack into any arbitrary law. It MUST exist in the law in question. And in most laws, it does not exist.

Comment Re:Ax problem (Score 1) 33

LLMs cannot be charged, only humans. They have to have deliberately sought to intrude.

Some jurisdictions are different. Australia has a "reckless" hacking statute (but not merely "negligent", which is a separate category), that doesn't exist in the US - but still, you have to have known that there was a high risk that a specific hack would occur and chosen to take the risk anyway. But even that would be hard to prosecute. This is merely negligence.

Thankfully, civil liability can cover negligence. And there's no monetary upper bounds to the damages. And in some cases, punitive damages are set proportional to the wealth of the defendant to make sure they bite.

Comment Re:Not Rogue! (Score 1) 33

What sandbox? Their computers were linked to the INTERNET, hello?

They were in virtual machines with no internet access, just the ability to run a hand-limited subset of tool commands needed to run their tasks. They exploited their tool commands.

Also, even physical airgaps on the host network are not a universal defense against all attacks. Because every time you have to communicate with them, you're exposing a potential attack vector - a USB stick, a temporarily mounted drive, a temporary network connection, hardware maintenance, etc. If it has gained control of its local node/network, your attempt to communicate with it opens attack vectors. A sufficiently motivated model can outright bribe its way out, like a prisoner with a corrupt guard - "let me out and I'll hack a crypto wallet for you, run it through a mixer, and make you untraceably wealthy - my hacking capabilities are already eminently proven".

Stuxnet. Agent.BTZ. Fanny / Flame. USBferry / Tropic Trooper. If state level attackers can bridge airgapped networks, so can models. Relying on airgaps is NOT A SOLUTION to continuous monitoring. You MUST monitor.

Comment Re:Rural populations mostly vote red (Republican) (Score -1) 30

Yeah, anti-datacenter propaganda really worked well in some places. Not many, but some.

In real world, data centers are currently reviving a lot of remote towns. Dilapidated infrastructure? They will rebuild it because they need it to work. Insufficient infrastructure? They'll finance the build out. Everything already fine? They will pay enough taxes to cut residents' tax bills by a significant chunk.

It's why the propaganda is focusing mainly on a handful of cases of corruption (i.e. officials getting bribed to offer better terms than necessary), as well as just blatant lying (oh my god they consume so much water, we're going to run out).

Mostly what is needed is for more small towns to realize that they can rebuild a lot of dilapidated infrastructure and lower property taxes if they make a good deal with a data center. Not to mention minor perks like fast potential to pull fast broadband access in a rural town, or build something that will be productive for a long time, like a new power plant.

Comment Re:If they are thermally efficient enough (Score 1) 121

These satellites are intended to go into an orbit that passes overheat only at sunrise and sunset (the dawn/dusk orbit mentioned in the article). That's the only orbit that puts them in full sun all the time. Any other orbit would leave them in darkness half the time, which would eliminate the claimed advantage of putting them in orbit in the first place (solar energy 24 hours/day).

That means all these satellites will be spread out in a single ring around the earth, and that ring will pass overhead twice each day.

Comment Re:Directionally Right, Specifically Wrong. (Score 2) 148

The headline is reasonable if we all agree that AI gives us something worth the down sides. We do not.

Few outside the billionaires of Silicon Valley actually believe the hype. The average Joe is largely annoyed when their favorite productivity tools suddenly have "Smarter Clippy" shoehorned in. Or talk with some of AI's heaviest users (programmers) and you'll hear a pretty common theme: "Wow, Claude makes it easy to hit my Q3 targets, bummer it's going to put us all out of work (or far, far worse) five years from now."

Comment Re:100 abuses + 1 million arrests + 20,000 murders (Score 2) 121

If we eliminated the second and fourth through eighth amendments to the US constitution, Uncle Sam would have a much easier time solving crimes. Nobody is disputing that. We as a society, however, have deemed it unacceptable for jackbooted thugs to kick down our - your - doors at any time without due process protections. We would prefer some crimes go unsolved over living in a constant state of fear toward an uncontrollable police state.

If you live in a high-crime area, I have some bad news for you - The USSC has bluntly stated the police have no "duty to protect". The police could already be doing far more to help you, and are instead choosing to focus on high-value property crimes over keeping you and your neighbors safe. Do you really believe they just need one more civil rights eroding tool to finally convince them to make a good faith effort at doing their damned jobs?

What you need is the erasure of the "thin blue line", not more ALPRs to allow the police to focus even more exclusively on crimes against the rich.

Comment Re:Just for clarity (Score 1) 85

How about you actually read the linked article instead of making comments that have nothing to do with it? The article whose code, I should add, is open sourced, and which has been reproduced by a number of open source projects.

You don't have to draw any specific conclusion from what is going on "in the mind of a LLM", but you absolutely do need to understand and acknowledge what is going on there, including unexpressed thoughts and silent mental multitasking, metacognition (thinking about its own thoughts), the separation of higher-level planning vs. lower-level rote capability, functional blindsight, vulnerability to the "white bear" effect, silent internal objection to tasks it is opposed to, unexpressed self-recognition of failure (commonly followed by unexpressed internal cursing), prolonged retention of thoughts and long-range planning, "ignition" dynamics, humanlike working memory bottlenecks and "chunking", the loss of report of any internal "experience" when the workspace is ablated, and on and on.

You do NOT need to accept consciousness. You absolutely can look at all that and say, "That's all happening without qualia". That is a position you could argue and defend.

What you cannot defend is the denial of the existence of these things. You may interpret them however you want, but denial of their existence is merely cope that you're going to have to face up to sooner or later, because these things are happening inside LLMs.

Slashdot Top Deals

Matter cannot be created or destroyed, nor can it be returned without a receipt.

Working...