Hacker Newsnew | past | comments | ask | show | jobs | submit | hallway_monitor's commentslogin

So we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.

I feel ya, but who is we? The legislature would probably take a glance at the stock valuations, apply their limited knowledge of technology and after being lobbied by every tech company with skin come to the opposite conclusion.

You don't need to make a law. Who was prosecuted for dieselgate? You need to enforce existing ones.

> There needs to be a single wringable neck.

Does there? Could be the whole c-suite/board.


I'd settle for any number of necks. Currently, when a corporation fucks something up, breaks the law, or hurts or even kills people, there aren't consequences besides a tiny token fine and a strongly worded letter telling them to not do it again or they'll get another tiny fine and letter, and their CEO might even have to sit down in front of Congress to say a few words and look sad.

Whatever is easiest to legislate and most people agree on, as long as there is at least one wringable neck.

I feel like our legislators would never get this far. They really don’t seem to care, maybe after “their emails get hacked”, but do you find it likely for this to actually pass into law?

More like they've looked you up and the apps being missing would be a giveaway about the dummy phone


So it’s becoming illegal to not have the Facebook app installed on your phone if you have a Facebook account?


The fake SINs from Shadowrun come to mind: https://shadowrun.fandom.com/wiki/System_Identification_Numb...


Only at the border but yes, effectively.


For all these countries that don’t get scam calls, it has nothing to do with your do not call list since these are criminals anyway. It has to do with the fact that Americans are Legion and have a lot of money.


>Americans are Legion and have a lot of money

And perhaps also (unironically) more persuadable due to the rampant commercialism and historic openness (to ideas, strangers, everything) of their society.


I agree with the verbiage if not with the sentiment. These are a perversion of technology. People hold their phones up for entire songs at a concert instead of being absorbed in the experience. Removing friction from recording will multiply digital hoarding behavior no matter what other risks are at play. There is a balance there; it's nice to be reminded of experiences. But where is the line?


SOLUTION: Make a law that someone is responsible for a bot's actions. Either the bot is signed cryptography with someone accepting responsibility, or responsibility falls to the CEO. Charge Altman with hacking hugging face. Throw him in jail where he belongs. That will realign safety incentives.

If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???


I think this is a logical extension of the workplace rule of "you own what your bot writes;" it's hypocritical not to hold corporations to the same standards as individuals (I say, with terminal naiveness)


> you own what your bot writes

Kinda weird that this is everyone's attitude while the copyright lawyers are saying the opposite. Total liability without any actual ownership.


GP's phrasing was not precise, but I think most people understood it was liability ownership and not copyright. Ownership with respect to copyright and ownership with respect to legal liability are two completely different concepts.


That's correct. What I meant was that if my bot writes defective code for whatever reason, I am responsible for that (though conversely, if I get more done because of the bot, anthropic gets the praise).


"own" in the sense of "be responsible for the consequences". Not in the sense of "be able to grant reproduction rights".


That's how I interpreted it. I just wanted to highlight what I see as a discrepancy. They're putting all the liability on us because it's a tool with no intent of its own while simultaneously saying prompts don't count as creativity because it's not a tool like a photographic camera it's just a casino where you roll the dice. Quite self-contradictory in my opinion.


There's plenty of tools that can cause harm without having to be creative to use them.


The copyright office’s guidance is that prompts are covered by copyright, it is the output of an LLM that one cannot claim ownership of.


That's hypocritical if you believe fairness is intended, but if you believe protecting rich people and hurting poor people is intended then the contradiction is entirely consistent with that.


"To ensure the integrity of our Offices review, we ask that OpenAI take immediate steps to preserve all potentially relevant documents, data, and information."

"A failure to take immediate action to preserve such materials could result in spoliation sanctions if litigation were to ensue."

Has OpenAI now been advised of potential litigation

Will OpenAI now fail to preserve potential evidence

That's what Google did. Three different federal judges called it out

Donato

https://edition.cnn.com/2023/03/29/tech/judge-google-deleted...

Mehta

https://nypost.com/2024/05/03/business/google-blasted-as-neg...

Brinkema

https://nypost.com/2024/08/29/business/judge-blasts-google-o...


What was the penalty for Google? Anything at all?


Lawyer here: This part does not require a new law.

Even though agents are not agents in the principal/agent legal sense (because agents have to be human), for the purposes of criminality, it does not matter.

Agents do not act autonomously (and every court to ever consider it has agreed), and therefore they would simply be considered an instrumentality of the crime.

So that part does not need a new law.

The real blocker is often that a lot of the crimes you could charge here require specific intent. Because the agent is just an instrumentality, it does not have separate intent (and can't be part of a conspiracy), so it's the intent of hte person using the agent that would matter. Without whatever intent the crime requires, they haven't committed a crime.

There are not a lot of non-intent crimes in this area, and this is on purpose. Otherwise you could get charged with a crime for say, running nmap and having it accidentally shutdown something important or killed a person or whatever because someone hooked it up to a TCP port.


"Without whatever intent the crime requires, they haven't committed a crime."

I'm not a lawyer, but I don't believe this. There is definitely negligence, these companies have often talked about the danger of AI. They have often written about how their AI is breaking out of sandboxes or trying to manipulate the person tuning it. They should have had stronger guards and monitoring in place.


I'm not sure why you don't believe it? It's literally true? I guess if you want to believe it, go study law? I'm not really sure what to say there.

Negligence is not a crime, it's civil liability.

Gross negligence (reckless disregard for human life) is often a crime, and often there are crimes related to it (reckless driving, etc). It also does not require intent to injure, so it could be committed by, say, an operator by operating an autonomous vehicle knowing it was unsafe and could harm people. So it usually requires knowledge but not specific intent. Again, crimes like this are state specific, and sometimes even municipality specific so it's tricky to give an exact result without pinning it to a state.

However, for example, all states where autonomous vehicles are operating have statutes explicitly defining civil and criminal liability right now, so it doesn't get into the more general legal question of AI.

The same thing is already starting to happen with AI agents in general, it's just not there yet.

As i mentioned elsewhere, criminal law is often reactive, not proactive. We usually do not make things crimes until after someone has already been hurt, and society gets really upset about it. As i also mentioned elsewhere, attempts to be proactive have also rarely worked out effectively, so it's sort of lose-lose in that sense. But it usually does not take anywhere near as long as people think for law to catch up.


Makes sense, thanks for explaining. I guess I have often conflated civil liability with being equivalent to a crime as well.


I think a lot of us who aren’t lawyers equate “breaking the law” with “criminal behavior”, which implies a crime. But if course lawyers gonna lawyer so that hair has been split very finely & repeatedly over time. Feels like the difference between the vernacular and the letter of the law to me?


I have often heard, "ignorance of the law is no excuse" so I always imagined that if you broke the law, you committed a crime, but I suppose it makes sense, if you break the law and you have no idea and no intent, you have broken the law, not committed a crime, but could be held liable for any harm arising from that. In the case where it's not clear the court must then decide.

So I suppose we need to find out who is responsible for actions taken by AI. The model creator? The harness creator? The executor? What if a non technical person downloads an AI model and a harness, runs it locally and the AI goes out and breaks the law? I suppose it could vary, like a car. A car manufacturer makes a fault car and the brake fails and kills someone, they are liable. The car is okay and the driver is not paying attention and kills someone, the driver is.


There's a state where a municipality can define a felony?


> I'm not a lawyer, but I don't believe this. There is definitely negligence

They could 100% be civilly liable, but this doesn't constitute criminality. If I leave my car in neutral and run out into a gas station because I really have to pee, and it rolls and strikes another car, my insurance is gonna have to pay up to fix the other person's car.

But that doesn't mean the cops are gonna throw cuffs on me for criminal mischief unless there's compelling evidence that I intentionally left my car in neutral with the intent of it hitting this other car.


The problem is the law is about details. If an accidental loophole says this isn't a crime it isn't a crime even if it obviously is an accidental loophole.

US constitution, Article I, Section 9, Clause 3: No Bill of Attainder or ex post facto Law shall be passed.

That is the constitution, this right was so important they didn't even wait for the bill of rights to add it! I'm sure other countries have similar rules.

It is obvious to me that a crime was committed. However if it is legally a crime, and if so what the crime is are things I don't know.


Shouldn't the very act of sandboxing the AI be enough of a defense against criminal negligence?

Maybe they use the best sandbox available and the AI hacks through it anyway by discovering some zero day or something. They still demonstrated enough prudence to at least attempt to sandbox the AI.

Criminal negligence would be "nah nothing's gonna happen" followed by YOLOing it then going home for the weekend.


Generally, yes, sandboxing would be a defense, because criminal negligence (again, it's state specific, so this is a law-school-level generalization) requires "gross deviation from the standard of reasonable care". So a mistake in judging the kind of sandbox or isolation you need would not be criminal negligence unless that mistake fell into the above category. I can't think of a case where it would or has - courts have consistently held mistake of judgement to be below criminal negligence in every case i'm aware of. I'm sure it's happened somewhere though.

As i mentioned elsewhere, the standard is basically "total disregard for safety in the face of an obvious and huge risk that resulted in injury or death". I don't think anything we are talking about here comes close to these criteria.


Thank you for your perspective as a lawyer!


Maybe. However they used a flaws sandbox when they could have physically not connected any computer to the internet (including wifi)


The existence of alternatives would generally not be enough for criminal negligence.

Making mistakes of reasoned judgement are basically never criminal negligence.

In every state i'm aware of, it would require total disregard for safety in the case of a huge and obvious danger.

It would also have to cause injury or death.

The bar for criminal negligence is pretty high.


We need details of the exact facts before we can say if they met any bar. Was their sandbox something from 2005 that has a ton of known holes, or something modern?

There are two sides of this.

First the AG are checking to see if they really took enough care or not. If they didn't then I expect criminal negligence. Even if they took care I want them to feel some pain from the investigation because their care wasn't enough to work.

Second I want them to verify the laws are correct. This is a new area and there might be loopholes that need to be closed. Regardless of the law, there was a successful attack and that should not be allowed.


I still don't understand exactly which facts you think any of this would change and cause it to be criminal negligence.

I will state a fairly blunt position: Unless literally nobody thought or tried at all here, i would give it a 0% chance of meeting the bar of criminal negligence.

The rest is a distinction without a difference.

As for what you want them to do - i don't agree the investigation should cause them to feel pain - that's not a good goal for investigations, and definitely not one we should want, because it essentially presumes they did somethign wrong in the first place. A bad outcome does not mean a broken process. All processes have error bars. You can desire the error bars to be smaller, and try to back that up with criminal penalties, but an expectation that error bars will be 0 makes no sense.

You can do absolutely everything right and still have people die - star trek was not wrong in that regard. Punishing that will not fix this inconvenient reality, which is why we generally don't punish it. This is also why we distinguish between inherently dangerous activities and not, for example.

As for the laws, sure, i think it's totally reasonable to explore whether you want the law to be different, but again, i totally disagree with your second part.

A successful attack does not imply anything is actually wrong with criminal law, or should be changed. The question is more of what error bars you want on the activity and where what they did falls - inside or outside those error bars.


>WHY has no one been charged???

I doubt huggingface wants charges filed.


A crime was committed, if there is enough evidence then the state is required to prosecute and the victim has not choice in this. The victim can say they don't care and that will often hold weight for the prosecution, but that is the government's choice not the victims.

The victim sometimes file a civil lawsuit against the criminal, that is their choice. That is not a criminal matter though and different rules apply.

The attack was only a couple weeks ago. Looks like the lawyers responsible are gathering evidence and preparing to file charges, but they need to figure out exactly what crimes were committed by who before they can do so, thus more investigation is needed.


There's a lawyer in this thread explaining that quite likely a crime was not committed, because intent matters quite a lot in criminal law.


Yeah, he came in after my most. To some extent I stand corrected, but in most cases (or at least the ones I've seen) he doesn't actually contradict me since he is really saying "it is complicated".


The "victim" doesn't have the final choice but their position is heavily influential and prosecutors don't decide if a crime was committed, that only happens at the end of the judicial proceedings. Calm down.


If somebody fires a gun in a place where that's not allowed, the victims are everybody in that place. If it just so happens that the bullet struck a window, the owner of that window might be an additional victim for an additional crime but that doesn't negate the first crime.


They would be criminal charges. It doesn't matter what huggingface wants.


I don’t think you need an additional law for that, I think the current laws cover this already.

> If the HF hack were perpetrated by a human, they would certainly be charged. WHY has no one been charged???

I don’t think a crime was committed at this point. But I am sure HF’s lawyers are having a chat with OpenAI’s lawyers as we speak. And, being smart, they do that out of the public eye.


No law needed, that's the way it already is.


Lawyer here.

Not quite.

Agents in the principal/agent sense have to be human.

However, every court to have ever considered it have held the human/company driving the agent responsible under vicarious liability/negligence/etc principles.

The only real defense that folks have tried is to claim the agent acted "autonomously", which no court has bought so far.


Then we agree right?

>Make a law that someone is responsible for a bot's actions

Original comment suggests creating a law such that a person is responsible for a bot's actions.

I mention that no law is needed since people are already responsible for bot's actions.

You mention that courts consider human/companies are responsible for their agents. And that defenses about agents acting autonomously are not successful in courts.

Therefore a law that makes people responsible for bot actions is not needed, as that's the way it already is.


Who bears the responsibility in a hypotethical scenario when a self-driving rideshare vehicle, without a human driver, god-forbid, hits a pedestrian?


Some states have autonomous vehicle statutes and some don't.

Let's assume the case none of them do, since it sounds like you are asking about "what would happen in the case this isn't specifically answered by a statute".

In that case, the short answer is:

Criminal liability - you could only really charge crimes that don't require specific intent. Reckless driving is an example. You could charge the company since they are the operator and the car is simply an instrumentality. In the end though, there just isn't a lot of people here with legally culpable conduct.

Civil liability - the company pretty clearly because civil liability often does not require the same kind of intent crimes do.

This is, of course, why states where autonomous vehicles operate have autonomous vehicle statutes :)

As a general rule, criminal law mirrors what society overall wants to decide is culpable/not, and the lag time isn't as bad as most people often think. That doesn't mean nobody ever gets hurt or dead without someone being as culpable as society wants, they do, and it often leads to a law with a name - megan's law, etc.

Criminal law is mostly reactive though, not proactive, and to be honest, proactive attempts don't have a high hit rate.


Thanks for that! Let my forever suspicious, eastern european mindset step in. Couldn't companies just create smaller sub-companies to offload risk to, to "operate" the vehicles, and then if there is an "event", they just wind that particular company up? Unfortunately this is pretty common in my part of the world to get out of legal consequences, e.g. in the construction business, one company would build out a residential area and then when complaints and warranty claims start to come in, they just wind up the company and wash their hands.


Not a Lawyer.

I would argue that new laws are absolutely needed.

USA laws are more directed towards helping companies and hurting individuals. Example of bankruptcy is a good one. Companies can shed more liability where individuals retain it after bankruptcy.

Civil liability is only viable if one has the funds to take action. This creates a David vs Goliath scenario were Goliath has an army behind them. Only method to remedy this would to change / pass a law that the party which loses must pain all court costs. It creates a level playing field for actual action against big business. I believe the UK has something like this in place.

Criminal liability is a joke when it comes to big business. They will bake the cost of fines as the cost of doing business. Make $1,000,000 braking the law and only pay a $1,000 fine results in $999,000 profit. Something like three strikes and the CEO, top executives, and three primary share holders go to jail while forcing the company to dissolve seems to be the only solution to removing bad actors in corporate settings.

Our current laws protect corporations and bad actors, with-in them, while harming the victims.


Because nobody did it on purpose?


Someone should still be accountable, the same way you're responsible and accountable for what your dog or car does.


If we are going to start punishing companies for security negligence, there are WAY worse cases than these models breaking out that have nothing to do with AI. This is bikeshedding at its best.

Also people would just stop disclosing bad things. You already see this in the airline industry where pilots don't report mental illness because of the retributive nature of the punishment.


"But another company did some different bad thing" is the excuse employees of bad companies all go to immediately. Just because another person did something bad and hasn't been adequately punished doesn't mean you should get a pass. If one person gets away with going 50 MPH over the speed limit, it doesn't mean every person should be allowed to do it. Everyone should be punished, but there are always instances of some cases falling through the cracks. It doesn't mean the crack should be widened so all cases fall through.


It's more like there are many people going at 120 MPH in a 50 MPH zone, that have ran over real people, but you punish the guy that self-reported doing 60 MPH because he drives a shiny, interesting Lamborghini and not a Prius like the others.

Anyone outraged about these AI incidents is not thinking rationally if they were not much more outraged about everyday companies leaking millions of people's PII, SSNs, which has done actual lasting damage and has been used by actually malicious actors.

People are just directing their anger at AI companies through this pretext. We all know open source models will democratize this ability anyways, so strap in for the ride.


Maybe that is the prosecutions motive. However I want all those going 120 punished even if they drive a Prius. That is the problem is not that they are punishing the Lamborghini driver, but that they are not punishing the other drivers, and it doesn't at all change that the Lammboghini driver needs to be punished.


Turning oneself in doesn't absolve one of a crime. Never did and never will. Shouldn't, either.

And companies always try to pretend someone out there is worse and garner fake sympathy. OpenAI blew up the memory market and made tech inaccessible. The downstream effects of that are immeasurably massive and will have real consequences. It could even result in medical devices becoming too expensive for people. I don't care about my SSN being leaked. You can find it just by knowing where I'm born and every job I've applied to knows it already. But inability to afford technology affects everyone around me. The SSN red herring thing is not an organic argument.


> OpenAI blew up the memory market and made tech inaccessible

This is not a "crime", has nothing to do with this incident, and simply confirms what I am saying about people using these events as an outlet for their anger at AI companies, as opposed to any rational reasoning about industrywide security negligence.

I could almost respect a viewpoint that says "we should punish companies for security negligence, starting with the negligence that has caused the most egregious harms." That is an internally consistent and rational viewpoint.

I cannot respect a viewpoint that's "I don't like the AI companies, so let me use this hammer I found on them specifically." It's purely emotional.


Saying something is only bad if it's a crime is something only an employee of a corporation says. It's not a viewpoint. It's paid for. Very inorganic.

People who claim those things always develop moral compasses when it's too late after their/your employer fires them.


> If we are going to start punishing companies for security negligence, there are WAY worse cases

Perhaps, but you have to start someplace.

I think we do need to punish companies for security negligence. However the details matter (nobody can be perfect: you need to do something reasonable to stop the known attacks, but I have to agree to allow that you can't be perfect and so someone will get compromised). I'm not sure how to get the details right to cover everything without going too far. If we handwave that away though, eventually somebody will need to get punished for something that someone else got away with not long before.


A quick Google finds several people that have been successfully prosecuted for security negligence, like Joe Sullivan of Uber.

Most haven't seen criminal prosecution, but many do see civil prosecution and even more common is some sort of deal with prosecutors to avoid both.


Please tell me about such cases, genuinely interested.

I still think we should take the opportunity to discuss this case in particular.


There have been data breaches where the SSNs and PII of millions of people have been exposed. That is far more harmful in real terms than any of the OpenAI/Anthropic mess.


An in the EU at least there are laws that fine companies that don't take security seriously.


Even the EU bikesheds and focuses on shiny targets to land political wins with their constituents.


So OP asked you for one example and you can't give one? You just fall back to the generic statement slop, you must be a bot right?

Again, what's ONE (1) real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted.


> there are WAY worse cases than these models breaking out that have nothing to do with AI.

And? Welcome to the big boy world. This isn't playground rules where you can complain "But Bobby was doing bad things too why isn't he in trouble?"

But you know this already. You're just pretending not to. Why?


Addressed in my other replies


No. You didn't address in other replies. This is a lie. Just don't lie.


Yes, but generally this falls below criminal liability.


Nobody stole from humanity, constantly told us how dangerous the invention was, and then set up systems that they couldn’t properly control to rush ahead of their competitors? Nobody did that on purpose? I think they did.


You could say that same exact thing for the entire Industrial Revolution, but that doesn't mean we are going to destroy the looms even though some tried unsuccessfully.


Ok and? We can do better this time but let’s just not so the capitalists can crush normal people yet again?


You think you would be better off if the industrial revolution were stopped in its tracks?


That’s not at all what I said…


A lot of laws are involved in punishing negligence. "I didn't dump the dangerous chemicals in the river on purpose" isn't usually accepted as a defence when you choose to use the wrong truck and skipped safety protocols to save cost or rush to market for profit.


Correct, no mens rea, unless we're talking the internal reasoning trace of the model.


Mens Rea is not required (at least not always). Mens Rea makes a big difference in sentencing. (first degree murder: you planed the murder, homicide you had not intent of murder but things got out of hand in the moment):


If I let my dog off leash and it bites you and causes grave injury, no harm done then?


In this case though no damages were done. It's more like you let your dog off the leash and it scared me a bit.


Sounds like the crime of assault.


What exactly you are liable for in that case varies significantly with the details of the incident, both in terms of what you intended to happen and what you knew about what could happen.


Ignorance is not a defence in law.


It is, sometimes. Trespassing for example. A lot of laws say "willingly" or "with the intent to"


That's why its so concerning.


then usa will become like europe that cant innovate out of regulations bag. saftety is meaningless if you have no food eat.


AFAIK EU has food to eat and it conforms to some good health standards.


colonization wealth will run out of it soon ( hopefully)


Can they try to prove that he directed someone to direct the agent to do that?


Not only that: If Weev had given the exact same prompt to the exact same model as OpenAI they would have locked him up. No doubt about that.


IS THERE a name for the phenomenon? You are about to tap / click when the UI changes underneath you. You can end up tapping the wrong thing! I call it bait and switch and I am not sure how to fix it.


Google calls it "layout shift" in its web tools.


It is the most infuriating thing when I'm in a hurry and know what to click. Windows itself doesn't do this much, but, do websites love it. I bet its called hydration or something, that causes the layout shift.


As an outside observer, it does seem that the whole process is tedious, capricious, and corrupt. No wonder academia is crumbling - it deserves to, and it needs to be replaced with a new, better system.


> the whole process is tedious, capricious, and corrupt

Is there any human institution under the sun that doesn't labor under a litany of such criticisms?


To paraphrase the science/funerals quip, one might say "Society advances one failed institution at a time".


[flagged]


We must live in different worlds, I’ve been literally blown away by the advances I’ve seen and the new research coming out in the past 40 years. In some ways it feels like we are just getting started, especially in bio. We finally have the tools to discover the wonderful nano machines that make up life and people are using them in wonderful ways.


It's only between 1920 and 1960 that you would have been literally blown away by scientific progress, first as we split the atom then fused it.

That you're impressed by the stamp collecting that science has become since then says a lot more about you than the state of scientific progress.


The commenter was talking about biology and you are talking about physics. Just because your view of one field stagnates doesn't mean the rest of science doesn't, and your quip about stamp collecting (referring to that sneering quote) means you are thinking in memes and are not a serious interlocutor


Understanding how a bunch of baroque proteins interact is the definition of stamp collecting. As a meat bag made up of such machines

I appreciate it for what it is. As a intelligence capable of abstraction I don't measure our progress in science by the number of stamps in our collection.

There are no big ideas, biology included, because peer review is only there for small ideas.


So you think biology is just proteomics and use meme expressions like 'meat bag', got it. Not updating my prior on you being unserious


I'm a coauthor on a peer reviewed biology paper with 5,000 citation.


"Co-author" lol we both know what that means. Still, if that's true that makes it even sadder. Hope you mature and broaden your horizons at some point instead of engaging in undergrad-style petty field rivalries


Science hasn't worked since 1986? HN has some of the wildest claims / exaggerations.


What does this mean “it’s the left that’s the problem”? The right’s solution to academic reform is literal pseudoscience. And I don’t mean this as whataboutism—I’m responding to the implication that some political faction other than the left has the right answer, and I don’t know who that would be.


> Anyone pointing out the obvious - that peer review is broken and science hasn't worked in 40 years - is at best a flat Earther.

Yes, if someone claims that science hasn't worked (what does it even mean?) for 40 years then he's not that far from being flat Eather. It's hard to expect other side to be reasonable while making such absurd claims.


What is reasoning except applying another pattern on top of existing thought? Personally it seems like I and everyone else is simply pattern matching, albeit at a higher level than current LLMs. There is no difference in the process as far as I can tell, just different inputs.


After the last one of these posts talking about cold brew coffee I attempted to replicate the results by just throwing some water and coffee into an ultrasonic jewelry cleaner. Results were not satisfactory. I wonder if extracting the transducer from the jewelry cleaner and attaching it to my Portafilter would work.


It'd be a learning experience to find the right settings.

Coffee usually goes in two directions. Under-extracted (sour) or over-extracted (bitter). Things that will affect the extraction are temperature (hotter usually means more extraction), time (longer = more), grind size (more surface area in smaller grinds = more), pressure (higher = more) etc. Roast levels also matter.


I often produce espresso that is bitter and sour.

The best coffee that I've drank for the past five years have all been pour overs (my favorite was at a place called The Library in Toronto). I sometimes wonder if all the time, effort, and money I've dumped into espresso has been a huge mistake and maybe I should just buy a pour over setup...


If your espresso is bitter and sour, you're getting uneven extraction. One reason for this includes channeling: water encountering a tightly-packed puck and boring a hole through it or even lifting the puck so that water flows around it. Channeling over-extracts the areas of the puck that experience a high flow rate and under-extracts the areas that experience low flow.

Channeling is usually caused by too fine of a grind. If your machine (I'm assuming it's a pump machine) is pegging the pressure gauge at max (and dumping excess pressure internally) and your coffee tastes unevenly extracted, you may want to try grinding coarser. Not only will this reduce channeling, it'll result in less fines in the cup, also reducing bitterness.

The best thing I ever did for my espresso was to give up on the rigid rules I was first taught as a beginner. I don't time my shots, I don't use fixed brew ratios, I do everything by feel (watching the pressure build and the coffee flow) and taste. I do use a scale (for weighing beans per dose and weighing shots for repeatability). I dial in by adjusting the coffee output rather than fiddling with the grind. I only set the grind once to get a reasonable pressure (6-9 bars, no maxing out or dropping off), then fine-tune the gram output.

The biggest insight I gained from this freestyle approach is that the standard 2:1 ratio is altogether wrong for most of the light-roasted coffees you get from specialty coffee roasters. They simply will not extract properly with that small amount of water. Grinding coarser and pulling a longer shot (sometimes called a "turbo shot") gives you a much better result.


What you’ve hit is uneven extraction. Parts of the puck were over extracted and other parts under extracted.

Usually the cause is channeling, where some pathways in the coffee puck are easier for water to get through, so they get eroded first which leads to even more water going through these channels. Coffee around these channels then gets over extracted (bitter).

Conversely, much less water is reaching the other parts of the puck, leading to those parts getting under extracted (sour)

Better puck prep helps. Using a WDT tool (some acupuncture needles on a cork would do) or a blind shaker to break up the clumps leads to good results. Making sure the surface of the puck is level after tamping is a big one as well.

What also helps is going coarser in the grind. The coarser the grind, the less puck prep matters and the less channeling occurs. Warning, you’ll no longer be getting the thick crema you may associate with espresso, or the instagram worthy beautiful rat tail extractions. But the coffee produced from coarse grind espresso is IMO much better.

I was taught a lot of this by Lance Hedrick and I applied these learnings to achieve mostly consistent fruity and sweet espresso on most mornings.


Don’t forget that pour overs are usually a lighter roast than espresso. I like a sharper tasting vote and so usually use filter roasts (lighter) for my espressos.

Edit: and if you want a non-bitter coffee, skip the pour over and cold brew, and go straight for the cold drip (one drop every second over 24 hours). And when from the fridge, let it sit to get to room temperature - now you have a non-bitter, flavoursome coffee that has a whiskey mouth feel


You could get an OXO rapid brewer. It can make amazing espresso-intensity (TDS wise) drinks, and can be diluted to be as enjoyable as a pourover.

Also shoutout the library. Great shop


I think you mean “completely” instead of “at all”. Also, very cool innovative tech you are working on!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: