7 ms·
OpenAI upset that someone is leveraging APIs and content freely available on the web? Let me play for you the worlds smallest violin.
by binarymax 3y ago
OpenAI upset that someone is leveraging APIs and content freely available on the web? Let me play for you the worlds smallest violin.
- NLPaep 3y agoIt’s exploiting bugs on other websites to get free access…
- wzy 3y agoSo they should go at the other sites, or at least have the other sites go after this repo.
- theturtletalks 3y agoCompanies normally pay for that sort of penetration testing...
- rfoo 3y agoCalling public (but undocumented) APIs without authentication is NOT exploiting bugs. If this is "exploiting bugs" then by the same logic I'm hacking the government website by clicking view source.
- BoorishBears 3y agoYeah it's not exploiting bugs, it's abusing websites. To me hacker mentality ends at you found the REST call, and maybe you use it, or share it on some random forum. Creating a gaudy branded library that's providing actual client implementations, then building an entire site that's built on those, is just bad taste If you actually look at the implementation, some of the sites did everything right in terms of CSRF tokens and not exposing their OpenAI key directly. So the next step for the sites they're attacking with this is a whole mess of JS based detection, behavior detection, ie all the mess that we'd rather the internet didn't have. If this person had just shared it anonymously and left it instead of drumming it up for personal glory, some motivated hackers would have used it. Now it's flooding websites at rates that break their ability to pay their bills.
- skeeter2020 3y agoYou could be. Courts have ruled for intent vs the actual act a number of times.
- nextaccountic 3y agoIt's exploiting the fact that the API is unauthenticated, which is hardly a bug (or a security exploit in the usual sense) If OpenAI intended to authenticate the API they probably should do it
- permo-w 3y agoit’s not openAI’s API that’s not authenticated
- BoorishBears 3y agoThey do authenticate it: it's disappointing how many people have 0 understanding of what happened and are commenting. OpenAI authenticates their API, and was getting paid for every query. OpenAI loses absolutely nothing from what these people were doing. Who was losing was random customers who have APIs and products that call up OpenAI. In some cases those customers even secured their API keys, but by the very nature of their product, you put in some input, and get some output from OpenAI. It's like if someone made a directory of apps that use Google's search API to show you results, so instead of paying for Google API access, you started slamming all of those apps with your queries. It's not cool to those apps, but Google shutting it down would be for the apps' benefit: they get paid either way.
- bink 3y agoSounds like someone made a comprehensive directory of their customers who don't have properly secured APIs. Maybe instead of suing the creator of the directory they should use that list to contact their customers and have them secure their APIs?
- BoorishBears 3y agoExcept they did secure their API. Take this implementation: https://github.com/xtekky/gpt4free/blob/main/gpt4free/italygpt/__init__.py https://github.com/xtekky/gpt4free/blob/main/gpt4free/italyg... The site has a rate limit, doesn't expose their API key, and it has a CSRF token. In terms of non-intrusive measures they could have taken, they did it all right. So what's left on the table is intrusive stuff: HN has a lot of people constantly whining about how they're stuck in captcha hell because their hand built Lenovo running Firefox on BSD compiled on an abacus isn't recognized as a real client... but aggressive captchas are going to become even more pervasive if every GPT based product must fight off proxy attempts.
- bearmode 3y ago"bugs"
- gumballindie 3y agoI guess openai shouldn't have uploaded the bot to the internet if they didnt want people to use it this way.