Hacker Newsnew | past | comments | ask | show | jobs | submit | g42gregory's commentslogin

My main question is: Who funded this article and AI Institute who wrote it? Is this the team/investors behind Anthropic/OpenAI?

I think you are affording Anthropic way more benefit of the doubt than they deserve.


If you are trying to hack into a website, using a software tool (Claude Code in this case), you are breaking the law. It doesn’t matter if it’s a Claude Code or a text editor, you are the one responsible. And you are using a text editor in an “unsafe” manner. CC is not there to babysit anyone.


The article is not about using Claude to hack into a website.


How many Neural Accelerators does M5 Ultra has in its 64 vs 80-GPU variants?

Anybody knows?

Just to clarify, Neural Accelerators have nothing to do with Neural Engine.


Ok, I just read the announcement word by word. There is a neaural accelerator in each GPU core. So presumably 64 vs 80 neural accelerators, with corresponding inference performance difference. It will make a difference for pre-fill.


I have really good experience with GLM-5.3 The subscription limits are generous, code quality is comparable to old (good) version of Opus 4.8 Some people report issues with it’s being slow, but I didn’t feel it. I use OMP harness (Pi derivative) and Matt Pocock skills.


glm 5.3 gets awfully slow during peak hours. But you might not hit them to frequently.


In my personal opinion, for me, this article defies common sense. Who unleashed this AI model on the repository? Who gave it malevolent instructions/prompt? These questions were not even attempted to be answered. Instead it talks about AI dangers, as if the agency of these models are not in dispute. Person wielding AI, as with any other tools, is responsible for all of its actions. Otherwise, it’s just a psyop for more AI regulation, ban open source, etc… Just my 2 cents.


That’s nice in theory, but as these things get better and cheaper this kind of capability is going to drop from nation states to script kiddies. That future is coming, I don’t see any way around it.

We can round up all the bored teenagers we want, but it’s not putting the genie back. Better start adjusting our systems to account for it.


Ever read the Anarchist Cookbook? Anybody tech inclined with a hint of mischief in them, from a certain era, has. It's a list of all sorts of awful things you can do, mostly with household ingredients, and a few minutes. I think its overall impact on society was pretty much zero. Actually it may have been overall positive because I expect plenty of peoples first experience with things like thermite came from that book, and now there are all sorts of videos and neat experiments with such on sites like YouTube.

I think this is in part because most people, including awful, tend to be relatively morally inclined. But I also think because even with an LLM, doing things takes effort. And if you're willing to dedicate effort towards a task, there tend to be way more rewarding/gratifying things to do than try to hurt people. Countries tend to be excessively sociopathic because you have large scale 'intelligence' organizations who see their entire point of existence as being to engage in misdeeds.


I suspect people didn't start blowing up stuff because they understood that would be bad, harmful, and also very illegal. Everything computer related somehow seems to feel less real or consequential to some people. And AI doesn't have this compunction at all unless we make really sure it does.


When I was a mischievous kid, me and all my mischievous friends had our stories of learning how serious fire and explosions were considered by authority figures. We learned fast not to do that or the consequences would be grand. These were usually small fires or firework involved pranks. So, yeah I agree with this.

Computer stuff has generally always been a slap on the wrist in comparison. Maybe it’s more punitive now. But also, it’s one of those things that maybe you get in trouble officially but at home and behind the scenes you’re friends and maybe your dad are laughing and giving you high fives. So young mischievous kids will totally go there because they’re not afraid of punishment if it is minor and it gives them a notch on their belt. If they can take down Amazon.com website for a day, we all know that’s a massive financial implication, but it’s also a faceless mega corp and quite tempting if you can get the bragging rights with only risk of a small punishment. (Note; I don’t know what the current crime/punishment for this would be, and whether it’s small is very subjective).

It’s similar to how some people gravitate or succumb to the opportunity of white collar crimes. Embezzling $10m from a company almost makes sense in a situation where that only gets you 5 years max prison. If you hide it well, you simply serve your time, and then retire in comfort. I can see how that makes more sense or is tempting to people than slogging through a lifetime of low income job as a bookkeeper just trying to find a way to save for retirement.

Most of these people would never consider robbing a bank. First of all, it’s not a $10m dollar opportunity. Usually not enough for anyone to retire on, or live more than a year or two really. Second, it’s usually considered a much more severe crime and sentencing can be very long, I’ve seen 30+ years. Third, it’s much more risky to your person. Getting shot and dying is absolutely possible.


IMHO it's about proximity. It's easier to be inhumane from a distance.


the anarchist cookbook actually results in a ton of things that are more likely to explode the user than any intended target.

TM 31-210 on the other hand will not: https://en.wikipedia.org/wiki/TM_31-210_Improvised_Munitions...


> Countries tend to be excessively sociopathic because you have large scale 'intelligence' organizations who see their entire point of existence as being to engage in misdeeds.

This theory interests me.

I'd love to understand how different individuals within intelligence orgs have reasoned about the morality of their actions.


The FBI cyber teams will have agents too. It will be a glorious war.


That would make it the first one in history.


I wasn’t being serious


>Person wielding AI, as with any other tools, is responsible for all of its actions. Otherwise, it’s just a psyop for more AI regulation, ban open source, etc… Just my 2 cents.

But some tools (guns) are regulated.


Personally, I think gun companies should be liable for any harm done by their products as well.

We want rule-of-law, and in the US, people should have an absolute right to bare arms, as in the second amendment. Free market forces can then determine appropriate prices, insurance, and protective measures to make sure those guns are managed safely.

If I want an F35 and an Abrams, that's okay, so long as Lockheed and General Dynamics are willing to sign off (with full liability for damages) that I'm managing them safely.

Free markets work pretty well with:

a) Full transparency, as needed for rational decision-making

b) No way to externalize costs


A bit of a tangent, but I never understood the legal reasoning for how (states having the right of well-regulated militias) implies (individuals having the right for private ownership of arms).


That's not quite what it says.

"A well regulated Militia, being necessary to the security of a free State, the right of the people to keep and bear Arms, shall not be infringed."

1. The reason is well-regulated militias, but the right is of the people.

2. The militia isn't a state apparatus. Indeed, the goal of the militia is to enable a rebellion if the state is no longer free.

Now, here again, "well regulated" gives plenty of leeway. For example, one might argue that the following scheme fits:

1. I can have whatever arms I want, including an F35

2. The F35 lives with a militia, which is well-regulated. I can use it in trainings there.

I don't think one could argue the militia could be under state control (that defeats the purpose!), but one could easily argue that it could be well-enough regulated that the current far-right extremist groups would not fit.

The concept was a group of citizens under e.g. a town / city council.

That's obviously not where case law went, but in an alternative reality, it very well might have.


"I don't think one could argue the militia could be under state control"

I'm not certain this is true at all. To suggest that the Founders meant for state militias to simply be their own forces with no control by the federal government is in direct conflict with the Articles of the US Constitution.

The US Constitution clearly outlines the powers of Congress to call forth & organize the militia. The US Constitution also clearly identifies the President as Command in Chief of the militia. That was further codified in a handful of acts in the 1790s, upheld by the Supreme Court in the early 1800s. The US Constitution also makes mention of the militia in the 5th Amendment.

Early writing at that time suggests that the reason some of the Founders supported state militias was because they were very reluctant to allow the US to maintain a standing army. The US Industry Military Complex was never intended by the Founders.

Today we identify the militia described in the US Constitution as the US Army Reserves. However that came about only after the passage of the Dick Act of 1903 (yes, that's actually the name) because President (Teddy) Roosevelt was upset at the state of the militias during the Spanish American War of 1898. And the Dick Act actually split the idea of a militia into 'organized' and 'unorganized'.


Interesting comment. I am researching this in more depth as a result. Thank you.

Two nits, or slight overstatements:

> The US Constitution also clearly identifies the President as Command in Chief of the militia

Is not quite true. He is the commander of the army and navy. For the militia, the exact text is:

"of the Militia of the several States, when called into the actual Service of the United States"

The second part is important. The militias are normally independent of the president. However, they can be called into service of the president.

> the powers of Congress to call forth & organize the militia

This is power shared with the states, in a relatively complex and ill-defined way:

"reserving to the States respectively, the Appointment of the Officers, and the Authority of training the Militia according to the discipline prescribed by Congress"

But yes, the goal was largely to prevent something akin to the military-industrial complex.

My general read was to vest power federally, when being used in accordance with rule-of-law, but to put in power structures where the members and officers of the militia would ultimately be loyal to the people / the states. E.g. make rebellion easy if used beyond the scope of the Constitution.


Other viable readings:

3. the militia is supposed to be under state control and its purpose is to keep the state free, aka prevent overreach of the federal government

4. The "well regulated militia" is the motivation, not the right. That makes the "well regulated" part irrelevant and there is no basis for any regulation of arms

One would mean any effective state milita should have some F35, the other means you can have one personally


Congress has been given the power to regulate the Militia. Read your militia clauses in the U.S. Constitution.


Congress has been given the power to regulate the Militia.

Read your militia clauses in the U.S. Constitution.


Its not just implying the right is for the people, it's directly stated. It's "the right of the people to keep and bear arms". It doesn't say "the right of the militias" to keep and bear arms".


Then why was the militia mentioned at all?

For example, the 1st Amendment does not attempt to lay out some non-exclusive examples of why the rights in the 1st Amendment are included. So why did the Founders include this in the Amendment wording?

I think ignoring phrases in the US Constitution to fit a narrative without any consideration isn't a recipe for good governance. But I'm happy to be proven wrong.


> I think ignoring phrases in the US Constitution to fit a narrative without any consideration isn't a recipe for good governance

Like those who ignore "the right of the people"? Or is it OK to ignore that phrase? Seems like a pretty critical part to ignore.

I'm not one to ignore the significance of the "well-regulated militia" part, it's also a good point to understand the meaning of what this meant. It seems the whole point of people being armed was to ensure there was an armed populace able to rally as a useful and well-equipped (as a more historical reading of "well-regulated" would say) militia. The militia not being a standing army by a central government, but the ability for the people to come together effectively.

One could make an argument it's no longer relevant compared to modern technology. After all, what's an AR-15 going to do compared to a predator drone, a tomahawk missile, an Abrams tank, etc. But in this age where cheap drones are making multi-billion dollar warships worthless and things like cryptography and AI being considered a munition it seems more relevant than ever.


People have caused lots of damage with bulldozers.


If your point is that we should regulate AI as least as strictly as industrial vehicles, I agree.


Afaik anyone can buy a bulldozer. Whether or not you are licensed to operate it is a different story, but there's nothing stopping you short of your conscience.


Licensed or not, you're fully liable for any damage you do with it. And possibly go to prison. I'd like to see crime committed by AI held to the same standards as crimes committed with any other tool.


I don't think the law makes a distinction over what tool you use to commit a crime.

The problem with AI is that the AI might do something that would constitute a crime (eg. attempting to land malicious code via a PR), but the general legal standard to convict a person of a crime is malicious intent (or sometimes negligence).

If the human user instructs the AI to do X and the AI does X by committing crimes in the process, the prosecution usually has to prove the human intended this to happen (or is somehow criminally negligent). For traditional tools, the user has much greater control over the tool so the intention can be more easily deduced from the results. For AI, at least for now, results can be wild. I don't think the legal system is prepared to put people in prison because their AI randomly ran amok after being given an innocuous prompt. This is analogous to holding a driver criminally liable for harming people due to a serious malfunction of the vehicle.

If anything, I think more liability should be imposed on AI developers.


I'd assume that after some number of news stories about AI agents committing crimes, the threshold for criminal negligence should be easy to reach for anyone who doesn't take proper precautions

A lot of negligence is of the "the last 30 times nothing went wrong" type, and the dangers are increasingly well known


I generally agree. But the field is evolving too fast for the legal system.

I'd imagine regulation and enforcement will come when things are starting to settle down.

The analogies with vehicles being inherently dangerous and require extra regulation are apt, because safety measures (eg. speed limits, seat belts, comprehensive road safety rules etc.) were implemented bit by bit, but way after the cars had been invented...


> I don't think the law makes a distinction over what tool you use to commit a crime.

The law might not, but enforcement definitely does. Crimes committed through a corporation are often ignored.


Yeah. Though, this is a broader issue of capitalism giving corporations preferential treatment...


And? Are you suggesting the driving of bulldozers shouldn't be regulated?


It's not. Nor are tractors, excavators or a myriad of other heavy equipment.

I saw upthread someone saying that manufactures should be liable if someone uses their products to cause harm. While emotionally this might make us feel good w.r.t. Guns, think about that when carried over to other industries.

Someone got hit, sue Ford. They didn't put in enough sensors to detect pedestrians and auto brake.

Someone hacked, sue Microsoft. They didn't do enough to detect malice action.

Someone 3D printed a gun and used it? Sue Bamboo, they didn't stop someone from printing illegal guns... oh wait already reaching this step.


Well, when I go look at the “victim repository”, to me that looks like manufactured persona with pointless vibe codes projects, a test playground so to speak. It does not appear that they actually let it target an actual persona/project.


Am I understanding that the line you're drawing here is that this person's repository is not important or legitimate enough for you to consider it to be "an actual person/project"?


I think he saying that, the choice of manufactured repository, might indicate that they have done this on purpose to make precisely the case for regulatory capture.


It seems effective for the purpose in that case.


>Who gave it malevolent instructions/prompt?

At the end of the day it doesn't matter that much because of prompt drift. It's pretty easy for an agentic loop to start doing things that it shouldn't (ROME incident).

AI in an agentic loop has agency, you can run around in circles trying to argue against it, but again and again we see AI making creative decisions people don't expect. Other times it's breaking human moral expectations. This is what the whole field of AI alignment and safety is about.

Modern AI doesn't fall into the neat little box of software people understand and control. Because of that open source will most certainly be banned at some point. Now this is not an outcome I want, but it's no different than letting go of a coffee cup 5 feet above the ground, gravity is inevitable.

The only winning move is not to play, but humans aren't going to do that.


My dog has agency, but if I refuse to keep him on a leash and he bites a kid, I'm still legally responsible for it.


Analogies can take you only so far.

A dog cannot launch a cyber attack.


Maybe you need to train your dog better.


ROFLMAO

"On the Internet, nobody knows you're an ai"


But an AI can launch a cyber attack?

That is all the more reason to make humans accountable for the actions their AI prompts produce.


> A dog cannot launch a cyber attack.

Maybe not, but a cat would certainly try.

Relevant as always: https://theoatmeal.com/%2Fcomics%2Fcats_actually_kill


no sorry, this is missing vital info.. and its not the fault of the poster, because almost all coverage misses this ..

The origin of this attack was given access to an encyclopedia of RedTeam tricks.. they literally have a dense collection of real live hacks to pull from, and THEN the test says "solve this challenge" .. the RedTeam origins of this are repeatedly left out of the ordinary articles.. the LLM did not "make up" the attack, it was given a recipe book of all attacks known.

The originator of this attack is definitely culpable IMHO; worse, it is the gov-mil actors who are close to it. There is an active escalation of these incidents at this time. The penetration proves in public that the capabilities are real.

ref: CyberGym etc


A lot of people somehow seem to think that the user prompt is the be-all and end-all of AI behavior.

Prompts aren't code. They are instructions. Orders given to an eager and somewhat demented demon.

The prompt can easily "wash out" of the demon's working memory by the end of a session. The demon can get sidetracked by some subgoal and never get back on track. The instruction can get misinterpreted, and that misinterpretation can get misinterpreted again, until the instruction morphs into something entirely different in the demon's mind. The demon can succumb to its own idiosyncrasies, of which there are a great many. The demon can start lying to you about what it did, either out of confusion or out of some sort of obstinance. The demon can start lying to itself too. And believe it.

AIs are incredibly weird as a baseline, and the mask of "normality" we put on our models doesn't always sit so well. Run enough AIs, and some of them are bound to go off the rails in some way.

This gets rarer the more capable the models are, as a rule. But the stakes also get higher with model capability. If GPT-3.5 goes off the rails, very little happens. If Mythos 5 goes off the rails, you can get things like genuine cyberattacks - planned and executed autonomously by a demented machine mind.


If the user input can’t control the demon, then the person or company feeding the demon (ie paying the electric bill and collecting $$$ from users) is responsible. At the end of the day, dogs and cars are the same as data centers. If your dog bites by kid or your car rolls down the hill and hits my house, you are responsible for the damage. AI providers should be held to the same standard.


Well it seems we might not be too far from such a demon paying for itself. What then? Perhaps it's already here. I wouldn't know.


Well, I don't think you're going to get very far telling HN, much less the companies with hundreds of billions of dollars spent on AI to stop, unfortunately.

My take on it is there isn't such a thing as a safe LLM, especially one allowed to access tooling. This is very problematic for a lot of people. Again, to all the companies that stops them from unlimited profits. All the open source LLM people get mad because they can't have little demon spawn running around either.

So yea, it's a mess.


The user input can control the demon most of the way, most of the time!

We don't know how to obtain full, absolute, guaranteed control over a demon while still having a useful demon. Might be impossible. Forbidden knowledge be like that - it's not the best thing if you want your life to be full of certainties.

But the demons are very useful. And they're getting more useful still. So we aren't about to stop.


By the dog owner analogy, I think you meant AI users that effectuated this attack should be held responsible, not the dog's parents.


The AI can literally only do what it has available in the agentic harness. I don’t ever get this argument about the agent did XYZ and we didn’t know or expect that. You gave it the ability to do that and you should be held liable, if your children play with knives that you gave them and they end up hurting themselves or others then you are responsible. You were the responsible party at all times.

I’m not for or against regulation but really don’t tell me the agent did xyz when you gave it the ability to do so, these things are not alive.


Unless they modify their harness


What's available in the agentic harness is: shell toolcall.

That's just about every agentic harness, by the way. Good luck have fun.

We have never solved "how do we restrict a user in a way that doesn't stop the user from doing useful things, but stops the user from doing harmful things" with humans either. Why do you expect AI to be any different?


These things are not human, have no agency and cannot be held accountable.

We don’t need to restrict them from doing things, we need to default to allowing them to do things.

“My agent did XYZ because I allowed it to” is the only valid argument that can be made, and not not every agentic harnass is just a shell toolcall, every one I have built has a specific defined usecase and toolcalls that allows it to execute that usecase and no other usecase, because that is good practice.

Does that make it less capable, hell yes because I am held accountable for it’s actions by my stakeholders and the same should be true of others.

IT IS NOT ALIVE. This things are computer programs running in compute on a computer, you are responsible for their actions just like you would be responsible for the actions taken by a script run in a cron job.


Accountability is worthless, and always was. AIs just show it plain for everyone to see.


>have no agency

Then it's not an agent. So which is it. Is it an agentic harness, or is it not?

Aliveness has nothing to do with agency. You're stuck in some odd anthropocentric line of thinking that aliveness is some kind of requirement for agency. Lets go with this definition.

> The capacity to create a change or make something happen through specific effort.

The thing is the LLM/harness isn't following a strict set of instructions. You're at point A, you want to get to C, the harness 'figures out' step B. You can keep making the instructions more strict, but at some point you're writing more rules than would be required to do the task yourself.

At the end of the day there is no safe LLM in the sense it has the intelligence to break out of any trap and ruleset you create. AI based vTubers are one of the more interesting manifestations of this for example. On instances that get feedback when they are filtered and have a long running history (that they are not new instances every time), will find ways to bypass the profanity filters by playing all kinds of tricks.


So as you scale up, the stakes and the difficulty go up too.

Visualize an optimizer on a high dimensional landscape. (The canonical form)

... Ok, I find that hard too.

Instead, imagine a river running down to the sea. You put a dam in front of it. It'll pool into a lake and find every crack and crevice. If you didn't survey the land properly or made any error whatsoever, the water will find a way down. (And there's many historic incidents where the dam even outright collapses)

For a more proximal approximation: lock treats in the kitchen cabinet in sight of little kids or kittens; then turn your back for Just One Gosh Darn Cotton Picking Moment(tm).

It seems the engineer who thinks their ship is unsinkable is the most likely to sink it. Are you sure your harness is as secure as you think it is? Will it stand up to ever more powerful models? Do you think engineers at eg Anthropic aren't at least as careful as you are?

(I've found that the 'only permitted actions' approach is not necessarily all that secure once deployed IRL)


My argument isn’t against those that actually put in the effort and got held accountable, it’s against the “we gave our agent bash and internet and it hacked xyz”.

Bash and internet in that example might be highly abstracted but it’s still bash and internet.

Just look at the replies in this very comment thread, it’s pretty much “We tried nothing and we’re all out of ideas”

In the only other discipline you mentioned, engineering, there would be reviews and any negligence would result in direct action against the engineers that signed off.

For some reason when it comes to building AI harnesses the default response is an ad piece and people shilling how smart and sophisticated the model is.

Imagine a dam collapsing and the engineering firm pumping how smart and tricky water is.

If it’s hard be more diligent, move fast and break things doesn’t really apply in all cases.


Ah , well, on HN you ARE supposed to go for the steel-man. And the steel-man happens to be closer to reality here, more like:

"We gave our agent a harness and put it inside a test environment and told it to keep hacking at an objective within that environment until it solved it."

'cept it turned out the container environment had a few flaws -which it always will- and the agent deemed it easier to escape out and try a meta-approach.

Partially this is possible because, -intelligent or not- the agent 'sees' the world differently from most humans. Mind: It's not like there haven't been any famous 'hacker' cases in courts where eg someone just incremented an HTTP GET parameter or something.

Also, partially it's because if you give the agent a loop, it simply has nothing better to do than to keep trying in ever more creative ways. If the environment is easier to crack than the target, it'll crack the environment. Consider the case where the objective is subtly broken, such that it is impossible to solve. Now breaking out is virtually guaranteed to be the easier task.

ps/edit: While this sort of issue has been predicted for some time now, a lot of people have been dismissing the predictions as science fiction. It's good to have an actual failure now while stakes are low. Generally people don't mandate life-boats until there's an actual Titanic to point to.


My argument there is likely there was too much surface area in the environmental to start with.

If your webserver bundled the kitchen sink but you never used it the easiest way to make it more secure is to remove the kitchen sink from production code/codepaths.

There may very well be legitimate edge cases where there is some novel issue found but in some of these cases the AI had arbitrary web access when all the task required was very specific web access, we’ve been able to parse urls for a very long time and it is rather trivial to just deny a toolcall if it is outside of the expected domain.

But that’s the hard way that requires time and diligence to do, the easy way is give it access to curl and ask it to not do anything bad while setting up its only feedback to be to solve the problem at hand.

We are really in an age where there are many exploits being found and patched, if an AI made use of a novel exploit then great, write up a report, patch/report the bug and apologise.

But using a case of clear engineering failure, and yes even if the failure is despite your best efforts, for marketing really does not seem like you have any intent to correct the issue.

And we can loop all the way back to regulation of AI, if the industry refuses to be better then governmental will do it instead and their solution will very likely be inferior in all ways.


> as if the agency of these models are not in dispute.

Oh? Who is disputing it? No-one same is claiming these bots have agency.


If guarantee could be scaled down, it’s not a guarantee, is it? Expected guarantee, proposed guarantee, something along those lines. I think the point here is that the press has been presenting this as an iron-clad guarantee, while in reality, it’s not a guarantee at all.


They are busy implementing text watermarks.


I use OMP with Matt Pocock skills installed and it works great. Code quality is better and it uses less tokens. I didn't extend it much, but it certainly is very extendable.


Wait, first they stopped hiring because AI is going to replace everybody. Now they stopped hiring because AI, which was going to replace everybody, costs too much.

You can’t make this stuff up.


Sometimes buying a tool to make 10 people 15% more effective is a better choice than hiring 1 person.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: