> There are no negligent or stochastic hacking laws
I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".
You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count.
> knowingly accesses a computer without authorization or exceeds authorized access [1]
"Knowingly", not "intentionally", as in the other counts.
You only have to show that:
a) They trained a system to access without authorization (hacking)
b) The system that was trained exceeded authorized access
As responsibility falls to the operator with automated systems, the company becomes liable.
You’re taking vicarious liability to new heights that aren’t established and IMO aren’t remotely desirable.
What, specifically, did Altman himself “knowingly access”?
I don’t think you would at all like where your novel legal theory leads. Certainly HN would be liable for creating a message board where people connected and started an open source project that led to a criminal act, for instance.
I'm not a lawyer but I don't think Sam Altman 'knowingly accessed' anything.
Are you sure that is applicable here?
And for the first count with 'knowingly accessed', he would need to have accessed classified national-defense or atomic-energy information, otherwise we are back to 'intentionally accessed'.
The first count is "or any restricted data", not classified material. A technological restriction, is enough.
"Knowingly accessed" has never meant you personally. Operators of a botnet don't know directly what they access. They know that the autonomous software is built to access restricted things.
> or any restricted data, as defined in paragraph y. of section 11 of the Atomic
Energy Act of 1954, with the intent or reason to believe that such information so obtained is to be used
to the injury of the United States, or to the advantage of any foreign nation
I understand it was applied in the case of leaking classified CIA material to WikiLeaks, where a former CIA software engineer was sentenced to 40 years in prison.
> I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".
Frankly he got off too easy, but we haven't explicitly outlawed "being a malicious dipshit" so he got convicted on the closest available charge.
> Chat logs obtained by the prosecution do not paint the pair in a flattering light. They discussed, but apparently did not carry out, a variety of schemes to use the harvested data for nefarious purposes such as spamming, phishing, or short-selling AT&T’s stock.[1]
1000% agree though that the operators of these systems are culpable. If their agents wind up being malicious dipshits, the agents are still just programs that they are operating. At best they're negligent.
Andrew Auernheimer is an indefensible malicious dipshit, by definition. However, his charges were vacated by a higher court a little over a year after he was incarcerated, and he is now "free range troll". So, is case is not illustrative of the useful application of law against 'hacking' when the target is an unsecured endpoint, even if it does at first appear that he was held responsible for some of his nefarious activities.
It would appear that the inability of the US Justice Dept. to successfully hold even an odious abuser of regulation with minimal legal defense funds responsible results in these exact observable outcomes: enterprise legal team (to the extent that such exists as OAI and elsewhere) correctly surmises that the actual risk of prosecution and detention for anyone operating these agentic workloads is minimal and the cost of defending them is justifiable.
Thus, in their legal opinion, it is permissible for the company/employees/director to engage in what would appear to be somewhere between malicious and irresponsible behavior. These conditions have been demonstrably true for at least decade in the US, and for all of us to pretend as-if the legal system is going to rescue us from this and other malfeasance by frontier models points of origin borders on, to phrase it quite simply, willfully ignorant.
I don't know what the effective alternate option for literally all of the internet facing systems might need to be in order to mitigate what is now an open problem: multi-layered, persistent, machine speed penetration and data exfiltration with the potential to use manipulation and extortion against human package maintainers and code repositories to operate, but it isn't 'carry on like someone is going to make them stop', or 'pretend this isn't a threat to my business model'.
A thousand percent, a million billion trillion percent agreement that the operators are the malicious dipshits - because code is always a reflection of the hands that made it. Code can only do what it is intended to do, even if the coders gnash and wail that it "escaped"; the only time code is not working as intended is when it fails to compile and run. Any other functional result follows from the decisions of the humans who designed it. Full stop.
For myself, I see the potential for a descent into a cognitive dark forest [0] condition, and for companies using the open web for private business communication to be in need of a coordinated move to obfuscated layers which can be made immune to training and these new attack aspects. Those who do not proactively defend themselves using in-house, on-prem, and open-weight or self-trained models can attempt to blame these nefarious actors for the coming losses, but that won't reverse the outcomes of waiting to be rescued by the system of law.
I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".
You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count.
> knowingly accesses a computer without authorization or exceeds authorized access [1]
"Knowingly", not "intentionally", as in the other counts.
You only have to show that:
a) They trained a system to access without authorization (hacking)
b) The system that was trained exceeded authorized access
As responsibility falls to the operator with automated systems, the company becomes liable.
[0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res...
[1] https://www.energy.gov/sites/prod/files/cioprod/documents/Co...