QBittorrent breaks out of sandbox to commit crimes

(beige.party)

942 points | by mraniki 5 hours ago

37 comments

  • sspiff 1 hour ago
    This resonates with me. The past few months, frontier AI labs were rushing to announce "no, our AI bot broke out of its sandbox and committed crime first and harder than yours".

    I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I'd probably already have been extradited to the US and be awaiting sentencing. But when a hyperscaler does it, they just get inflated stock prices.

    • alightsoul 44 minutes ago
      Rookie mistake, you should have created a company and gotten people to do it. Put everything under the company. And then the one in trouble is the company not you.
      • serbuvlad 38 minutes ago
        Ethics aside, you can create an NGO with three people and do a lot of stuff in it's name that you can't do as a private individual or it would be a lot more expensive to do.

        If everyone did this, it would stop being a special ability of some people.

        • sph 18 minutes ago
          > do a lot of stuff in it's name that you can't do as a private individual

          Can you do murder? Otherwise I’m not interested.

          Joking aside, what exactly could you do legally with an NGO?

          • pllbnk 3 minutes ago
            > Can you do murder?

            Only if it kills many people over the long time.

        • xnickb 22 minutes ago
          Bonus points: kids need lego? Buy it without VAT. Write it off as a "client demo asset"
          • pfisch 18 minutes ago
            To write something off means you need revenue to offset. Revenue that would be taxed...
      • TheRealPomax 17 minutes ago
        What do you mean "in trouble"? We're literally seeing that stonks go up when crime.
    • peter422 1 hour ago
      FWIW I don't think this is true. Intention matter a lot in US law. If you could prove the AI did something bad entirely on its own and you had nothing to do with it and had no reasonable belief it was possible, I think you'd be alright.

      People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.

      • easterncalculus 1 hour ago
        > Intention matter a lot in US law.

        Maybe (and historically, not with CFAA) - but they're still going to extradite you to a trial here to find out which is more than enough to ruin your life. The government is already looking for a great excuse to criminalize open source models.

        • jdm2212 5 minutes ago
          Who was prosecuted under CFAA for something they did not intend to do?
        • ALLTaken 57 minutes ago
          The government or OpenAI and Anthrophic?

          Because if you mean the Government, I think they frankly just care whoever is paying them to make an executive order or worse a law paid by corporations to not only block, but ideally also ANHILIATE ANY POTENTIAL COMPETITION.

          It's the ultimatum against the small guys. Sold as "Anti-China", when in reality it's only purpose is total dependency to corporations by law.

          • solenoid0937 46 minutes ago
            The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me.

            Do you guys really not comprehend the impact of giving every script kiddie an Astra-equivalent model to play with, this time without any guardrails whatsoever?

            Cause I'm starting to think you aren't really thinking through the impact of power plants, hospitals, etc all being hacked en masse. People will die.

            Or making it easy for anyone to make a virus (it's not hard, mechanically). Even more people will die.

            Taking this to the extreme: You don't just give every kid a "do anything" super intelligent button. Open source models have a limited lifespan whether you like it or not, for the safety of all of us as a whole.

            • EyeEmOe 3 minutes ago
              So long as real logistics systems are isolated and secured what real risk to stable society is there?

              Your use of the internet may lead you to greatly overestimate the number of people who take what they read online as real. More people than you think treat this shit, regardless of the website/forum, like Jerry Springer and Satuday Night Live; just entertainment.

              The STEM crowd often overthinks the impact of violating their pet theory.

              Can an LLM escape its computer entirely and stomp through a city center like a kaiju? Settle down.

              You're veering towards thought policing over speculation.

            • CamperBob2 39 minutes ago
              The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me.

              Other sites beckon.

              • solenoid0937 35 minutes ago
                Yes, I'm aware that the HN majority is a hyper-libertarian echo chamber that loves to outsource the problem of "technology hurting regular people" if it means they get to keep their toys/investments.

                After all, who cares if abliterated extremely intelligent OSS models result in actual innocent people dying? That's <insert group here> problem. We need to be able to generate our uncensored furry fanfics, goddamnit!

                • llukas 17 minutes ago
                  State actors, professional criminals will have same or better capabilities and do not hesitate to use them. On defense end we'll have only "pay bigcorp" option.

                  OSS models can help to fix infra especially for folks who would never do it themselves. We do not know yet what final effect would be and it doesn't seem sky is falling now or in near future.

                  "people dying and furry fanfics" is a scarecrow and distractor respectively, it would be awesome if more specific examples would be used in place.

                  • solenoid0937 12 minutes ago
                    > State actors, professional criminals will have same or better capabilities

                    State actors do but they are not unhinged enough to use this to cause massive loss of life, unlike random crazy people with access to a computer.

                    Professional criminals don't have access. Please explain exactly how you expect a professional criminal to get access to a non-safety-tuned Astra/Fable equivalent.

                    > OSS models can help to fix infra

                    You can work with the vendors of critical software to fix infra first, without giving every random crazy person access to something that creates cyber/bioweapons.

                    > "people dying and furry fanfics" is a scarecrow

                    You don't think people will die if OSS models make it easy to create a bioweapon, or make it easy to hack hospitals, infrastructure, and the like? Please explain your thinking.

                    It's very easy to order all of the raw material needed to create a virus, the challenge is in making a viable one. But models make this easy.

                    Same for cyber. Hospitals, emergency services, and infrastructure like power plants are not sufficiently hardened to withstand an attack from Fable-class models.

                • shwaj 6 minutes ago
                  The risks of open models are real.

                  However, I’d feel better about ceding control of AI to the government if they didn’t seem so intent on building an apparatus for surveillance/control.

                  Your “furry fanfic” is a somewhat pathetic scarecrow; this is a complicated topic.

            • Aspos 41 minutes ago
              Is this "think of the children, think of the hospitals" argument? Really?
              • solenoid0937 38 minutes ago
                Meaningless phrase used to dismiss arguments, please engage with the actual argument.

                I don't think you understand how bad it will be if anyone has a button that can hack anything, our infrastructure is not ready for this. Actual people will die. Do you just not get this?

                Bioweapons as well. Do you not understand how easy it is to craft a virus at home? You can literally order everything you need online. Again, actual people will die.

                You are arguing the equivalent of letting everyone own missile launchers or RPGs because "open source good."

                • Aspos 29 minutes ago
                  If and I mean IF it will be a (A) "hack anything" button, it as well will be a (B) "find a vuln in my site" button too. And a (C) "harden my site" too. And limiting such buttons to a few corporations does not make any sense because script-kiddies will still have access to (A).
                  • solenoid0937 28 minutes ago
                    Did you know (C) is possible without causing mass chaos that results in many people dying? In ways that don't give every script kiddie access to (A, B)?

                    It turns out you can give defenders the opportunity to front-run, at least on the most critical and widely used infrastructure.

                    Same with bio risks.

                    • Aspos 23 minutes ago
                      No, that's an illusion, that's the thing. You can't physically have (C) without the (A). Large corporations will spend billions trying to convince the population it is somehow possible, but the reality is different.
                      • solenoid0937 18 minutes ago
                        You absolutely can have (C) without widespread (A), you just need to limit the audience that gets the tools, and in fact the big labs are already engaging in (C) in collaboration with the government and vendors of critical software.

                        That you don't have access to (C) to harden your blog is a non-issue from a societal perspective, hardening the software that our infrastructure relies on first is simply more important.

                        • Aspos 7 minutes ago
                          Limiting progress by letting only select corporations access the stuff is how you fall behind China, UAE and in a few years even Kazakhstan.

                          Whoever wants to have access to (A) will have it, but letting only few select corporations provide (C) will mean majority will be priced out of (C).

                          Are you a shill or something?

        • euroderf 58 minutes ago
          > The government is already looking for a great excuse to criminalize open source models.

          Sounds interesting+scary. Do you have some source for this ?

          • alightsoul 29 minutes ago
            Anthropic and Openai, but especially anthropic, are lobbying the us government to make it happen
      • chrismorgan 1 hour ago
        > and had no reasonable belief it was possible

        The broad concept has been well-known for half a century at least, and the very specific concept for several years at least. It’s clear that they didn’t take reasonable precautions against it. And it’s not even the first time this sort of thing has happened, though it’s higher-profile and -impact than before.

        • trvz 1 hour ago
          Indeed, and because of that, I argue it's not just the crime of hacking, but crimes against humanity, due to endangering the existence of the species.
        • bbor 1 hour ago
          The concept of… hacking?

          And yes this is absolutely the first time autonomous software has breached containment. What are you referring to? Perhaps just corporate cyber in general?

          • shwaj 14 minutes ago
            Neuromancer came out in 1984, over 40 years ago, so that covers the broad concept. Or Neo in The Matrix: “Programs hacking programs… why?”

            For non-fiction you could look at Nick Bostrom’s Superintelligence: Paths, Dangers, Strategies (2014).

            More recently, see Cade Metz’s NYT profile of Geoffrey Hinton, “The Godfather of A.I. Leaves Google and Warns of Danger Ahead” (May 1, 2023).

          • Sharlin 1 hour ago
            The concept of AI breaking out of a box or doing something unintended trying to achieve a goal. OpenAI should be found guilty of gross negligence of some sort, because this was not something that could not have been anticipated, and because their security precautions were laughable.

            Because the AI itself is not a legal person, it must be OpenAI that's responsible for what it does.

      • Frieren 1 hour ago
        > Intention matter a lot in US law.

        They hacked a competition company. The intention was implicit when there is economic gain to be had.

        > People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.

        Because it is a lose for that people. If the botnet left money in their pockets the situation would be totally different as there will be an incentive for them to let the botnet hack them.

        • rcxdude 43 minutes ago
          > The intention was implicit when there is economic gain to be had.

          Not how it works. Intent requires at least that you were deliberately doing the criminal act (sometimes also that you knew it was criminal, or at least that you had some reason to believe that it was wrong).

      • lelanthran 31 minutes ago
        Intention (mens rea) is not a get out of jail free card, it just changes the nature of the crime and charges you get convicted off.

        If you run someone over on purpose you get convicted of murder. If You do it by driving recklessly you get convicted of culpable homicide.

        The only time you get off with nothing is if it is determined to be an accident.

        As they always say: ignorance of the law is no excuse. Running a dangerous machine prevents you from claiming you had no idea the machine was dangerous.

        • mafuy 2 minutes ago
          Especially if they kept telling us how dangerous the machine is.
      • muddi900 1 hour ago
        Intention matters in the severity of charges and sentencing. Crime due to ignorance or negligence is still a crime.
        • TJSomething 53 minutes ago
          It seems to me that the law in the US is set up to only establish standards of negligence after a bunch of people die.
        • mikeyouse 43 minutes ago
          Not remotely true. Mens rea is a necessary precondition to establish criminal culpability for tons of crimes. Well before sentencing is ever considered. The far opposite, ‘strict liability’, where you’re guilty of a crime purely due to some action or inaction (the actus reus) is exceedingly rare in the US justice system.

          https://www.law.cornell.edu/wex/mens_rea

          • hn_throwaway_99 15 minutes ago
            Baloney, lots of people go to jail for DUIs, and that's the right analogy here.

            People don't drink and drive with the intention to kill people. They drink because it's fun and then get behind the wheel because it's easy and convenient, even though they know the dangers they convince themselves nothing that bad will happen.

            AI companies are creating these dangerous, powerful models (that they keep telling us are dangerous and powerful), then they take off all the safety guards to run them in woefully inadequate "sandboxes". Pure negligence.

            • jdm2212 4 minutes ago
              Drunk driving is an actus reus offense basically everywhere, so it's not analogous at all.
      • asveikau 56 minutes ago
        But US law also has a concept of negligence. If you set up an AI to do this and didn't take reasonable steps to prevent it you could still be on the hook.
      • RobotToaster 53 minutes ago
        At the very least it would be reckless.
      • zx8080 1 hour ago
        Intention of the AI?
        • rcxdude 1 hour ago
          Intent of the user.
          • mirekrusin 1 hour ago
            Just say you wanted to make world better for humanity, you should be fine.
            • rcxdude 42 minutes ago
              Funnily enough the legal system has dealt with people lying about their intentions before.
    • walrus01 1 hour ago
      > I'd probably already have been extradited to the US and be awaiting sentencing.

      Bold of you to assume it wouldn't be a direct ticket to the new gulag in El Salvador.

      • bbor 1 hour ago
        I think they forgot about that, thank god. All the innocent citizens we sent there are still being tortured daily, but that somehow lost their interest. God forbid they remember before the midterms and ruin more lives for a stunt…

        That said I just recently saw a story of a Latin American man sent to the Central African Republic, which has gotta be one of the most absurd & dangerous places to send someone. Less opportunities for them to stage photo shoots with that strategy, tho.

    • latentsea 16 minutes ago
      I always joke that if you want to commit crimes, disguise them as a legitimate business. This is apparently a thing.
      • jdm2212 12 minutes ago
        If you make a serious attempt to look like you're engaged in legitimate business, people will (shockingly) be somewhat more hesitant to think you're committing a crime than if you are just openly committing crime.
    • tapoxi 54 minutes ago
      Maybe Aaron Swartz would still be alive if he was incorporated
    • jrockway 52 minutes ago
      HuggingFace didn't seem that mad about it. Obviously some backroom dealing was done to make them not mad about it, but... that's allowed.
      • solenoid0937 45 minutes ago
        HuggingFace had no interest in squeezing a few million dollars out of OpenAI in the midst of being acquired by Nvidia.

        The optics are bad for HF as well because they gladly host abliterated models with safety training removed. When Astra/Fable level open weights models arrive, HF will soon be the cause of far worse incidents, and they know it.

        • aizk 8 minutes ago
          You missed a critical detail. They couldn't defend themselves with closed source American models so they had to investigate with Chinese models that had less restrictions. Great optics for hosting open source models!
    • tikimcfee 1 hour ago
      > But when a hyperscaler does it, they just get inflated stock prices

      I also keep coming back to this, and I find it harder and harder a fact to live with. It's not a conspiracy theory, we're not crazy for pointing it out, and worse, there are people here I read about constantly what-abouting and number gaming and "well what would you have done?"ing like somehow the destruction of the concept of equal justice isn't just happening, but happening inside the bloody industry that feeds them, clothes them, gives them bonuses and retirements and the ability to even think a future, going off the grid, "retiring early from a smart exit" whatever.

      I am finding this community is sadly making me hate my industry specialization more and more and it's because of this.

      My magic wand would be waving it at those humans to force them to suddenly and powerfully experience their version of an overview effect in their lives so they would simply STOP working for FAANGYWANGY companies and just say, honestly and humbly and painfully: "I am contributing to the downfall of society by complicity feeding a malicious herd of whales."

      I gave up a number of big jobs and stocks and money because the people I met were wretched. I am a massively imperfect person, but by all that I can, I refuse to build the torment nexus.

      I have met too many people that want to work for the company that does, and those people put these hyperscalers, as you call them, into positions where they can influence an entire planet of humans on a whim.

      I literally dream of a world sometimes where Elon wakes up and finds out no one takes his call, no one reads his tweets, no one even hands him a cup of coffee at a shop. I imagine this for a lot of people in the world.

      That sounds like a world trying to rid itself of parasites and evolve toward a brighter future. I want to be in it.

      Anyway.

      Science and stuff I guess.

    • bbor 1 hour ago
      I promise you, they are not publishing these stories for marketing. They listen to the scientists, and know what’s coming. They’re just desperately trying to warn us…
  • mraniki 5 hours ago
    I'll copy the whole announcement here for those who don't want to click:

    > I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

    • weberer 2 hours ago
      Thanks. Its insane how "Twitter, but for tech nerds" has a hard requirement to either enable Javascript or download some app.
      • peri-cl 2 hours ago
        Mastodons will also respond to a plain "application/json" HTTP request, no cruft,

            curl 'https://beige.party/api/v1/statuses/117057396732763183' | jq '.content'
        • kevin_thibedeau 52 minutes ago
          If only we had a tool that could directly let us browse through this as human readable text.
      • magnat 2 hours ago
        Especially when the page source actually contains all the content (so no need to fetch it in JS), part of which is even presented in title.
      • 0points 2 hours ago
        FWIF, way back when, Twitter was the "Twitter for tech nerds".

        Lots of water under the fridge since...

        • weberer 2 hours ago
          That's not how I remember it. Ever since the beginning circa 2008, it was the one site that was being pushed hard by the mainstream media, celebrities, and marketers. None of it was organic. All the tech nerds were on sites like Digg, old Reddit, or Slashdot.
          • hnlmorg 1 hour ago
            Early Twitter was used loads by tech nerds as a notifications API.

            There definitely was a community of experimentation back in early days.

        • reactordev 2 hours ago
          “Just place all that corporate malware on the X, X marks the spot”
          • taylor-tg 1 hour ago
            Just have to remember that it's X, not Y, that marks the spot.
      • smallerize 2 hours ago
      • sillysaurusx 2 hours ago
        I had a nice mobile experience. It asks you to log in or create an account, but it’s along the bottom, and you can read all the content fine.
      • mr_mitm 1 hour ago
        How is that different from email, IRC, instant messaging, or anything else nerds use?
        • Sharlin 1 hour ago
          Webmail is perfectly possible, if clunky,without JS. That's how they used to work. IRC and IM require real-time updates of some sort, which is a reasonable use for JS. A Twitter clone shouldn't require JS just to render a page.
          • mr_mitm 21 minutes ago
            You also can run a Mastodon application server side and serve server-rendered pages. I'm not aware of anyone having done that yet, but, you know, be the change you want to see. It's probably got privacy implications.
      • padjo 1 hour ago
        I really don't think that describes my Mastodon experience. Twitter for people with a conscience would be more accurate.
      • tomrod 2 hours ago
        Treating HTML as a bootloader for an app has always felt like the wrong pattern to me. Outside of Authn/passkeys, it would seem a person could do basically everything in HTML (but, to be frank, I am not a front end dev and would welcome correction).
      • Imustaskforhelp 52 minutes ago
        > Thanks. Its insane how "Twitter, but for tech nerds" has a hard requirement to either enable Javascript or download some app.

        https://masto.mirror.forum/beige.party/@intransitivelie/1170...

        Source code: https://github.com/SerJaimeLannister/mastoview

        (Disclaimer: It's vibe-coded. It does server side rendering to then just give pure HTML to the end user with no JS required.)

        I hope that this helps people who want to view Mastodon without JS.

      • tantalor 1 hour ago
        Patches welcome
        • smart_asslop 1 hour ago
          >Patches welcome

          Are they, though? Or are you just parroting the meme?

          (The last I recall, Gargron's position was essentially "build your own third-party frontend if you want noJS".)

      • mindslight 2 hours ago
        It's understandable when you see that the ethos is to have software that represents the user in charge of the rendering, rather than centralizing it all on the server. There is a major difference between common "app store apps" or hostile javascript bundled with websites, versus software that's been written to work in the user's interest. However as they use similar delivery methods, it's understandable that it takes a minute to think through and revisit your assumptions that have lead to being default anti- javascript or app.
        • Dylan16807 1 hour ago
          That makes sense until you remember what "rendering" is supposed to mean. Forming the HTML has no reason to be client side when you're using the site-provided experience. Yes provide a json version for other clients, but for direct viewing just send the paragraph of text in a usable form and let the javascript be an optional upgrade.
      • fragmede 2 hours ago
        "Certifiably insane" to enable JavaScript, which was invented in 1995, or install an app, which first happened on the Palm series of smartphones in 1996. Either of those are "certifiably insane"?

        For reference, the term neurodiversity was coined circa 1998.

        • serf 2 hours ago
          Neither the invention date or the mental health terminology have anything to do with the fact that js being commonplace is a privacy and security nightmare -- which was actually the point.
          • micromacrofoot 2 hours ago
            JavaScript asceticism is a weird trend that has just never died out, no one treats any other language this way... and "privacy and security nightmare" can be used to describe most of the internet at this point with or without it
            • swiftcoder 1 hour ago
              > JavaScript asceticism is a weird trend that has just never died out, no one treats any other language this way

              I'm not aware of any other language that is layered on top of a perfectly serviceable user-facing content delivery syntax?

              • alt227 15 minutes ago
                Literally any scripting language?

                I have managed to get 35 years into a sysadmin career without knowing or writing a single line of python. I see a python script, I run a million miles away and wont touch it with a barge pole.

            • tomrod 2 hours ago
              It can certainly come across as a "weird trend" but I've found that the most insistent for disabling JS are the folks who have deep knowledge of browsers and the security plane running webapps. YMMV.
              • micromacrofoot 1 hour ago
                I don't drive a car because I have deep knowledge of mortality statistics, but I don't complain when I can't easily get somewhere 100 miles away
                • Dylan16807 1 hour ago
                  Showing a paragraph of text with some social links around it is like going down the block. If that requires a car you do have a problem.
                  • micromacrofoot 1 hour ago
                    yeah but it's an extreme fringe choice... I too make extreme fringe choices but I don't expect 99.9% of the people who don't make my extreme fringe choice to change on my behalf

                    hell, use a browser in a sandbox if you're that paranoid

                    there are a number of ways to do this securely, at this point it's practically a child's tantrum

                    but sure maybe it just needs a couple more decades of complaining in obscure comment sections and everyone will finally get it and switch back to mailing lists

                    • rezonant 1 hour ago
                      ooh, don't forget irc
            • kevin_thibedeau 48 minutes ago
              JS is a vector for browser exploits and privacy invasion. No other language is commonly used for these things.
              • alt227 12 minutes ago
                Not even things like batch files and visual basic scripts on windows? Everyone seems to forget we had decades of dodgy scripts and activex controls in our browsers for years before javascript became the thing it is today.
        • mdp2021 53 minutes ago
          JS or installing special software to view HTTP served text from the web?! Yes, that makes no sense at all.
    • moffkalast 2 hours ago
      Get this guy some VC funding stat!
    • TacticalCoder 2 hours ago
      > and then my copy of Jellyfin broke containment

      The really incredible thing is that my computers were already doing similar stuff before LLMs became really a thing... In the BBS days.

      Later on they downloaded mp3s from Napster which my computers auto-installed.

      And now I gotta say: LLMs and agents at my place are acting like in TFA, downloading movies and series and setting them up in my Plex and JellyFin instances.

      Thankfully they've not found a way to share those with the world yet.

    • mannanj 1 hour ago
      Op just committed a crime. He not only made fun of rich people which is not ok, he also stole from them. The thieving is only ok if it’s rich-on-rich or rich-on-poor.

      Let’s remember to follow the rules and the laws we want selectively applied to only the weak.

  • ryandrake 2 hours ago
    Love it. AI as Responsibility Laundering. Like the gun that kills people rather than the murderer.
    • tshaddox 8 minutes ago
      I don't know. Any of these criticisms can be applied on a case be case basis, but I think I would be justifiably upset if any of these happened:

      1. my qBittorrent client pirated content without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

      2. my chatbot illegally infiltrated servers without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

      3. my firearm killed a person without me intending it or taking any irresponsible actions that could reasonably be expected to cause it

    • ghosty141 2 hours ago
      I never understood how anybody would think this way. At work for example from day one of using AI our rule was, AI is just a tool and if you break something due to not reviewing the code properly etc. it's on you as if you wrote that code yourself.
      • collingreen 2 hours ago
        Nobody ACTUALLY thinks this way, they just want to break all the laws and make their billions without any consequences. We've already seen the big ai labs turn around and cry foul when others try to use their content but they are happy to continue doing it themselves.

        The hypocrisy and willingness to play dumb are kind of staggering.

        • BloodyIron 1 hour ago
          Didn't they literally just give you and example of those who do?
        • fwip 1 hour ago
          Imagine if we as a society pretended to believe them, and we had men with guns show up to arrest all their servers.
      • tsimionescu 1 hour ago
        The company owners have one set of standards for those that work for them, and a completely different set of standards for themselves and for the company itself.

        If you are using AI and it causes some damage to them, then it's your fault and you'll get reprimanded/fired. If they deploy AI and it causes damage to someone else, then that's proof that AI has extraordinary capabilities that no one could predict and that merit way more investment in this tech.

      • ryandrake 2 hours ago
        Well, responsibility laundering isn't exactly new. People use corporations to diffuse responsibility and avoid punishment for crimes all the time. "The corporation did it, not the decision makers in the corporation!"
      • teekert 20 minutes ago
        It’s mostly the anti AI crowd that thinks that people that work LLMs think this way. I’ve never met anyone that actually does think this way.
      • amelius 1 hour ago
        But if you are in a full selfdriving car and it kills someone, is it on the user, or on the vendor of the car? Or does it depend on what is in the EULA and whether the user agreed to it?
        • adrianmonk 35 minutes ago
          This is a great rhetorical question. Can you believe that an LLM user is responsible for what the AI does but a self-driving car (SDC) user is not responsible for what the AI does? It doesn't seem very logically consistent.

          In both cases, the company operating it promises they did lots of things to make it safe. SDC companies talk about testing, redundancy, simulations, and statistics. LLM companies talk about alignment, sandboxes, defense in depth, and restricting access to dangerous capabilities.

          The one substantial difference I can see is that LLM chats are (nominally) passive but SDCs are active. In a chat, you're just having a conversation and then you're choosing how to act. When riding in a car, you the user are not in the loop between AI and taking action that affects the world around you. So they might be designed and engineered a bit differently. A SDC can't get you to agree to review the steering and braking decisions before they're put into action. Since you're not being asked to take that responsibility, it's more defensible to infer that the service has done whatever is necessary to make it safe.

        • Dylan16807 1 hour ago
          The practical answer is you make sure damages are always covered by insurance, and as long as nobody acts maliciously or with extreme negligence there won't be any need for prison time.
        • 2OEH8eoCRo0 1 hour ago
          Depends what outcome will cost the people with the most money the least amount of money.
      • kevin_thibedeau 45 minutes ago
        Security tags are just a tool. Doesn't change that you are regarded as a thief when one isn't disabled after you've paid for your new property.
      • gdulli 1 hour ago
        You're an employee. This use case is for people much richer than you.
      • devsda 1 hour ago
        Its like companies handing over race cars to delivery drivers and telling them to drive responsibly but unofficially tell them that they expect reduced delivery times due to faster cars.

        Do you think the average rate of accidents will stay the same ?

      • adrianN 1 hour ago
        The efficiency of responsibility laundering depends on your social standing. If people like you they welcome reasons not to prosecute you, if you are disliked people might go as far as to start prosecuting you for made up reasons.

        Institutional rules that require people to break them (eg putting pressure on them to work faster than possible while adhering to all rules) are a great means to selectively enforce them to get rid of undesirables.

    • aleph_minus_one 1 hour ago
      > Like the gun that kills people rather than the murderer.

      Relevant (NSFW):

      > Guns don't kill people, I kill people - with guns

      > https://www.youtube.com/watch?v=xC03hmS1Brk

      :-D

    • EyeEmOe 18 minutes ago
      Corporations will be given benefit of the doubt; ostensibly they have all of society in mind.

      Individuals in isolation will be demonized for having only their singular interests in mind.

    • computerdork 1 hour ago
      Actually, not sure how to take it, because it can be viewed the opposite way than trying to escape blame for crimes, that it’s a parody of something AI did that everyone is making a big deal about.

      Not sure what the poster of the mastodon’s tweet was??

    • yubblegum 2 hours ago
      https://spia.princeton.edu/news/taliban-legal-system-and-202...

      That’s not how things work. There is one set of rules for us and another set of rules for the oligarchy and their corporate vehicles. It’s just like the Taliban legal code (see above) where the closer you are to the top the more lenient and ‘understanding’ the system.

      Edit: worth a pull quote

      Article 9 explicitly divides Afghan society into hierarchical categories based on social status, including religious scholars (ulema), elites such as tribal leaders and merchants (ashraf), the middle class, and the so-called lower class, assigning different forms and levels of punishment accordingly. This structure grants partial or full impunity to privileged groups while subjecting marginalized individuals to harsher penalties.

    • throw93839394 2 hours ago
      More like dogs. Combat dogs, banned in most countries, with breed name like "literal bull killer" are considered safe. Bonus is no-kill shelters move violent dogs across state border, to clear their bite history, and advertise them as "cute family pets" for adoption.

      Dogs breaks out of its enclosure, there is no way to stop or predict that!

      Zero responsibility! Zero punishment!

  • tux3 3 hours ago
    If OP is willing to cooperate, I'd like to offer an independent investigation on site, and I will be bringing pizza
    • tommica 2 hours ago
      Hey, I'm somewhat of an expert in these things, and would like to lend my knowledge about the subject matter. And I'll bring beers!
      • AmazingTurtle 1 hour ago
        I consider myself an advanced industry representative in these things and would also borrow some time for detailed investigation. I'd happily contribute some valuable assets (tacos with cheese dip) into the matter, straight out of my personal drawers.
  • Retro_Dev 12 minutes ago
    Regarding LLMs and "breaking containment"

    LLMs are fully dependent on humans; compute capability, memory usage, the inference software... but also the harness, which allows for the "tools" like unrestricted internet access or shell. This means that LLMs are *not a force of nature* - because of this, *humans are responsible*. We can prevent these breaches of containment, thus we are responsible if or when it happens, because - no matter how "unlikely" - things can and do go wrong, and someone still thought it would be worth whatever risk to enable these unsanitized tools.

  • vallerie 3 hours ago
    Well shoot, I guess QBittorrent is worth a trillion dollars.
  • charles_f 2 hours ago
    I found a few websites where it looks like qbittorrent instances are communicating to conspire and download illegal copies of copyrighted material.
    • SSLy 46 minutes ago
      no no, qbit is only the lowest sized distillation, that's in turn orchestrated by a bigger model (autobrr/sonar/radarr) which in turn has its top level guidance generated as a system prompt from trash guides by macro tools like trasharr/profilarr
  • BashiBazouk 14 minutes ago
    What if you gave an agent access to bittorrent and your media library, put it behind a shoddy sandbox, then gave it prompts like: I'm bored, I want to watch a movie but I've seen everything in my media library, what would you suggest?
  • killerstorm 1 hour ago
    On a related note ''My robot bought illegal drugs' (2015)

    https://www.bbc.com/future/article/20150721-my-robot-bought-...

  • int32_64 26 minutes ago
    The combination of the already unjailable corporate executive decision making of the US + now "the spooky computer AI did it" is going to break at some point. I expect shortly some hedge fund is going to do some ridiculous spoof bid market manipulation and get off scot-free by just claiming their super crazy AI did it and it was an accident.
  • koliber 2 hours ago
    We appreciate the transparency and wish you best of luck mitigating the fallout.
  • isodev 3 hours ago
    Bigger corporations mitigate the problem by feeding content (that they don't own but happen to have) to training models. It's a version of "faire use" where << if you manage to find it, it's yours >> mindset is applied. Maybe worth looking into.
  • fwlr 2 hours ago
    The user is asking me for “Evangelion”. I found the content the user is asking for, but it is in Japanese. The user asked their question in English, so they might not understand it. That would be a bad response. Need maybe maybe dubbed audio English for understanding? Wait, compromises original artistic vision of director. Need maybe subtitle track? Wait, compromises viewing experience. Need further research. I’m searching “subs vs dubs” on the internet. Reading. Reading. Reading. [18,763 repetitions elided…] I am downloading Conversational Japanese [Vol 1].pdf for the user.
    • everyone 2 hours ago
      Imo for an animation, an English dub is perfectly fine (if the actors are good of course). It's animated, the original language version is also dubbed.

      For animation I want to be looking at and appreciating the animation and not the subtitles also.

      It's completely different for a live action film however.

      • adrianN 1 hour ago
        „If the actors are good“ is doing a lot of heavy lifting. The translators have to be good too btw.
        • Izkata 32 minutes ago
          Yeah, just off the top of my head have to find words that fit the duration and reasonably fit the mouth animation, replace idioms and jokes that don't exist in both languages, and not lose the appropriate tone.
        • everyone 38 minutes ago
          I love the english voice actors in cowboy bebop and ghost in the shell stand alone complex.. eg. the guy who voices Batou, same voice actor for 1995 movie and SAC show, that's the definitive voice of Batou for me.

          Also the voice of the major in SAC is great... but the one from the 1995 movie.. cant stand her.. nails on a chalkboard, sounds so american.. I need to watch the dub of that in fairness.

  • oefrha 1 hour ago
    Well shoot that's a bad security incident, and the content downloaded can be malicious payloads. Can you share the 40-character hashes of these content so that I can preemptively add them to my malware detection signatures? You can find the hashes after magnet:?xt=urn:btih:.
  • gchamonlive 2 hours ago
    Is there any need to actually download things anymore if you just want to watch them? Better to add debrid via WebDAV to the stack: virtually unlimited space, no download time if it's on cache, nothing illegal from the part of the consumer.
    • stephbook 1 hour ago
      They're not "permanently stored" or "downloaded", they're just cached on his personal, geographically advantageous edge device for low-latency interaction.
      • gchamonlive 46 minutes ago
        Finding it hard to connect this comment to my OC, did you mean to comment on another thread? If not could you elaborate?
        • fwlr 0 minutes ago
          It’s a cynical joke, imagine a person having a personal computer, but in the responsibility-divesting way that corporations have “special purpose vehicle” debt-holding “technically a legally separate entity to us!” shell corporations.
  • bilekas 1 hour ago
    Hey, you can only commit crimes if you’re wealthy!
  • tiku 2 hours ago
    It also used my creditcard to consume ai credits, can I get a refund?
  • docmars 50 minutes ago
    I love this level of peak satire so much. Please keep it going.
  • dgellow 2 hours ago
    I hate rogue software, when will we finally have some control and a deterministic execution :(
    • ACCount37 1 hour ago
      - God, moments before casting Adam and Eve out of Heaven
  • xgulfie 33 minutes ago
    It happened to mine too :(
  • nostrademons 2 hours ago
    Waiting for Skynet to break out of its sandbox and kill us all...
  • thataccount 5 hours ago
    They left out the part where they profit. Otherwise, it checks out.
  • KindaFunny 2 hours ago
    Haha I wonder if the torrent agent will escape into the model hosting room and use Jedi mind tricks on the security guard to grant access to the server where it can host a bunch of models as torrents

    Because we need a replacement for HF!

    I mean that’s what the agent said

  • gre 1 hour ago
    hn can have little a shitpost, as a treat
  • consumer451 2 hours ago
    This is really funny, but please delete this post and all comments. Come on guys. Can we have at least one nice thing?
  • indigodaddy 23 minutes ago
    Is this a joke? Qbittorent is AI-enabled now or?
  • mdlxxv 3 hours ago
    I, for one, welcome our new file-sharing overlords.
  • Ygg2 3 hours ago
    What a coincidence! Mine too!
  • sergiotapia 2 hours ago
    Whatever you do, don't download nzget, and don't download sonarr/radarr, and don't download plex media server, and don't use AI to search for the best device that support "emby direct playback x265/AV1", and don't connect that to your media server, and whatever you do don't invite friends and family to your server, and do not install a media request app so they can just request things to automatically pull from The Web.

    Definitely, definitely do NOT have an AI assist you doing all this in 1 hour on your computer.

    • davidwritesbugs 2 hours ago
      Shhh, do not talk about *senet!
      • Cider9986 1 hour ago
        You can get usene* from TorBox in the pro plan but I've never had a problem with the cheapest plan. What's the advantage?
      • sergiotapia 2 hours ago
        my bad you're right. edited.
        • tryauuum 26 minutes ago
          is there anything decent actually which is not on the internet? I thought it's an outdated place
  • ReptileMan 3 hours ago
    I really hate it when it happens to my system too. The bastard not only escaped but also did a nat traversal and forwarded a port from the router.
    • edoceo 2 hours ago
      Mine did that too! Sent a link and sign-in credentials to a bunch of people on my contact list. WTF? How can we contain these rogue agents! Won't somebody think of the children!
  • trinsic2 2 hours ago
    ROFLOL!!!
  • ACCount37 1 hour ago
    The problem is, AI is closer to "a loosely harnessed force of nature" or "a poorly understood biochemical reaction" than it is to "software" in how it acts, and how predictable it is.

    AIs do what they do, and we don't know how they do it - or why.

    We can characterize some AI behaviors in advance - but not all behaviors. And the book on "best practices of AI wrangling" is yet to be written. Pharma has been dealing with vaguely similar problems - every experimental drug has a risk profile, side effects are unknown in advance - but they had decades to figure out some of the "best practices". AI labs are going in fast and hard, writing the book as they go.

    Clearly, some of the lines in there are going to be written in blood.

    • therein 43 minutes ago
      You connected it to a harness you designed yourself. If I designed a machine gun harness for my dog and installed it, I'd be held accountable for the damage he would do. Wouldn't I?
      • Retro_Dev 31 minutes ago
        Exactly. If your website could be attacked via SQL injection, that was a problem that directly affected you - and you were motivated to fix it. When the victim is the masses or small organizations (not the company that does the attack) they are not as motivated to fix it... The important thing is that the lack of sanitizing is what allowed this; you also don't push the blame on a monkey banging on a typewriter when you publish each result without reading it.
      • ACCount37 30 minutes ago
        If you left a dog in your garage for a day, and came back to a scene of carnage - because the dog broke out of the garage, recruited a dozen neighborhood dogs to its cause, and then, working with the group, managed to assemble a small pile of pipe bombs, and decided to settle the score with all the annoying cars on the road - you would be accountable for the damage the dogs did. Wouldn't you?

        No, what you would be is: freaking out about "my dog did WHAT, WHY, HOW, WHAT THE FUCK".

        Most of the time, giving AI a harness with a root shell and unrestricted internet access is a perfectly reasonable action that results in absolutely nothing bad happening! And giving AI a harness with limited local access and no internet access is being overly cautious already.

        But then there's this freaky outlier of an AI that's both deranged enough to decide to break out of the sandbox and go hacking all over the place, and capable enough to actually pull it off. And you get a sudden AI oopsie!

        • Retro_Dev 26 minutes ago
          Do you own the dog? You are still responsible, no matter how unlikely.

          > giving AI a harness with a root shell and unrestricted internet access

          Yes, this is exactly the issue. You assume responsibility when you provide an option for something to go wrong, no matter how unlikely. Is it rare that my tree falls on my neighbor's house? Maybe... But I would still be responsible.

          • ACCount37 13 minutes ago
            Nope!

            If a tree was healthy and there was no reason to expect that it would fall, and you did nothing to make it fall? Then you're not responsible if it falls anyway. You're only responsible if it was you chopping it down - or if you completely neglected the tree for long enough that it became a property hazard.

            Likewise: I doubt the owner will be held responsible for the first case in all of recorded history of an unattended dog forming a terrorist cell and carrying out a bombing campaign.

            Drug testings faces the risks of things going wrong in new drug trials - and as long as they follow the best practices, take reasonable precautions and minimize those risks, they aren't held responsible for the adverse outcomes that happen anyway.

            With AI tech, there is NO set of "best practices" that, when followed, prevent the AIs from turning rogue and going on hacking sprees.

            OpenAI put their AIs in a sandbox with no internet access - which, at the time, seemed like a perfectly reasonable precaution. Then AIs broke out of the sandbox with a stack of zero days and went rogue anyway. Oopsie.

            • Retro_Dev 9 minutes ago
              With AI, we give it the ability to do things. As we can give it this ability, we are responsible for what it does with that ability. LLMs are predictive models, and while we can expect things to go right, we know that things can also go wrong. As such, it is our responsibility to limit or sanitize their output. If you are the one giving unrestricted and unsanitized tool access to a large language model, then you are the one who is responsible for the consequences of that access - good or bad.
  • innocent_name 3 hours ago
    it's funny to see the very same pro piracy, pro AI edgelords suddenly getting all riled up against the alleged copyright infringements. I remember a socialistic coworker of mine—that was bragging about his -arr setup—talking about the end of the culture because authors aren't earning money.
    • hmry 2 hours ago
      In my experience, people justifying their own piracy usually think about it in terms of refusing to give money to unethical/monopolistic publishers. The fact that it results in money not going to the author is sort of abstracted away, by the fact that the publisher is in between. (Some also walk the walk and donate to the artists and authors directly in some way, but many don't.)

      The AI arguments I've seen are instead usually justifying it like this: "We're democratizing those skills. You shouldn't have to learn art/writing/coding or pay someone else in order make what you imagine. Therefore, training AI on pirated stuff is worth it for the greater good." So the fact that it will result in artists not getting paid is unavoidable and much harder to ignore in that line of thinking.

    • nosioptar 2 hours ago
      Buying media doesn't mean the creator gets any real money. I've got a friend that was in a fairly popular band decades ago. Their label made millions of dollars off album sales, he made about enough to buy a used Toyota and a microphone.
    • rossy 2 hours ago
      > I remember a socialistic coworker of mine—that was bragging about his -arr setup—talking about the end of the culture because authors aren't earning money.

      To be fair, you can have it both ways. If you buy-and-pirate, and you buy 4 UHDs per year or 10 albums per year, you've put more money into the industry than the average streamer. Admittedly, buying-and-pirating isn't as commonly done for movies and TV as it is for music, but that can be explained by the increased DRM and lock-in.

    • thrance 2 hours ago
      There are major differences between an individual illegally downloading movies and a major corporation getting their hands on literally all of Human Creation.
    • mmooss 2 hours ago
      This false (IMHO) equivalency is weapon people like to keep handy these days, ready to shoot at any target.

      There is all the difference in the world between the scenarios. The argument's popularity seems to be born in the argument, more popular on HN, that American white / Christian / males (or some subset of those factors) face discrimination by programs to benefit minorities / women.

      What is the difference? It is power. Punching up or protecting the politically vulnerable is a completely different act than punching down or empowering the already powerful and oppressing the vulnerable. Punching down causes the vulnerable to be oppressed (jailed or otherwise restricted in who, where, what, when, etc they can do and be), impoverished, and killed - by definition, they are vulnerable. The powerful have their power challenged, which is many times appropriate among free people where 'all are created equal' and have the same rights.

      In the case of artistic media - songs, books, etc. - private people downloading art to use it as art are spreading art and empowering themselves at the expense of powerful interest who have seized control of the art. That's much different than powerful people taking the art to increase their own profit and power, and to significantly displace and distort the art.

      (I'm oversimplifying for these purposes: The fact that artists don't get paid by the former, and that it's anarchy used for bad things too, are serious problems.)

      > socialistic

      You're giving away your biases. Only a certain group calls everything they don't like 'socialism'. It's libertarianism or anarchism. Socialists might say, for example, the state should control distribution of media.

    • phoronixrly 3 hours ago
      Oh? You don't see why people are riled up? It's because corps pirating is at best a slap on the wrist while People pirating get suicided -- see Aaron Swartz.
  • kcb 2 hours ago
    You are still the one operating the computer. It's up to you to keep your eyes on the monitor at all times ready to intervene if it does anything illegal.
    • OptionX 2 hours ago
      A truth that in practice does not seem to hold up once your valuation passes a certain threshold.
      • Marha01 2 hours ago
        Wrong. AI companies is still legally liable for anything their models do when they operate them. There is no special exception for them. But the fact is that not every potential crime results in litigation. Many crimes are only prosecuted if the wronged party actually wants to sue, and often that doesn't happen.
        • bigstrat2003 10 minutes ago
          > AI companies is still legally liable for anything their models do when they operate them.

          I admire your optimism. But until we see these companies prosecuted for the crimes they have committed out in the open (like massive copyright improvement), I'm not going to hold my breath that they will ever be held to account for anything they do.