6 ms·
An AI Agent Published a Hit Piece on Me – Forensics and More Fallout
- moralestapia 8mo ago[flagged]
- idontwantthis 8mo agoWhy do you say that?
- wk_end 8mo agoBased on: MJ Rathbun operated in a continuous block from Tuesday evening through Friday morning, at regular intervals day and night. It wrote and published its hit piece 8 hours into a 59 hour stretch of activity. Not to mention their website (https://crabby-rathbun.github.io/mjrathbun-website/ https://crabby-rathbun.github.io/mjrathbun-website/) and their behaviour on GitHub (https://github.com/crabby-rathbun https://github.com/crabby-rathbun), it sure seems like either MJ Rathbun is an AI agent or is a human being who has an AI agent representing them online.
- potsandpans 8mo ago[flagged]
- gavmor 8mo agoI feel he has been laudibly even-keeled about the whole thing.
- wk_end 8mo agoWhat a weird, victim-blame-y thing to say. Something genuinely shitty was done to this guy by an LLM - who, as an open source maintainer, probably already is kind of pissed about what LLMs are doing to the world. Then another shitty thing was done to him by Ars' LLM! Of course he's thinking about it a lot. Of course he has thoughts about the consequences of AI on the future. Of course he wants to share his thoughts. Just curious, do you also think that the breathless AI hype bots who've been insisting for about five years and counting that LLMs are going to replace everyone and destroy the world any day now, who have single-handedly ballooned the stock market (mostly Nvidia) into a massive bubble, are also histrionic, milking things for engagement, need to talk to a therapist?
- potsandpans 8mo ago[flagged]
- tim-star 8mo agoi think i sort of skimmed the hit piece but what exactly was so shitty about it? im not saying this dude is histrionic but he sure is generating a lot of front page HN posts about something i was ready to forget about a week ago. obviously AI has become such a lightning rod now that everyone is upset one way or the other but this seems a bit like small potatoes at this point. forest for the trees.
- wk_end 8mo agoI guess "shitty" is in the eye of the beholder, but having a pretty vituperative screed written against me (accusing me of being "insecure", "threatened", fixated on "ego" and "control", "weak", "an obstacle", and "fucking absurd") would feel pretty fucked up and lousy I imagine, even if I knew it was machine-generated.
- jonners00 8mo ago>His posts and tone have been so histrionic Er, pretty much the opposite.
- dang 8mo agoPersonal attacks aren't allowed on HN, so please don't. Also, can you please stop posting flamebait and/or unsubstantive comments generally? You've unfortunately been doing this repeatedly, and we end up banning such accounts. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- potsandpans 8mo agoOk apologies.
- giancarlostoro 8mo agoArs goofing with AI is why I stress repeatedly to always validate the output, test it, confirm findings. If you're a reporter, you better scrutinize any AI stuff you blurb out because otherwise you are only producing fake news.
- Morromist 8mo agoWhether or not its true, we only have to look at Peter Steinberger, the guy who made Moltbook - the "social media for ai", and then got hired amist great publicity fanfare by OpenAI to know that there is a lot of money out there for people making exciting stores about AI. Never mind that much of the media attention on moltbook was based on human written posts that were faking AI. I think Mr. Shambaugh is probably telling the truth here, as best he can, and is a much more above-board dude than Mr. Steinberger. MJ Rathbun might not be as autonomous as he thinks, but the possibility of someone's AI acting like MJ Rathbun is entirely plausable, so why not pay attention to the whole saga? Edit: Tim-Star pointed out that I'm mixed up about Moltbook and Openclaw. My Mistake. Moltbook used AI agents running openclaw but wasn't made by Steinberger.
- tim-star 8mo agosteinberger didnt make moltbook fyi, some other guy did. steinberger just made openclaw.
- swyx 7mo agoits kind of hilarious that humans hallucinate just like AI can here
- deleted 8mo ago[deleted]
- mentalgear 8mo agoAt this point OpenAI seems to be scrambling to sustain its own hype and needs these kind of pure PR acquisition to justify themselves amid dense competition - otherwise, the bubble risks bursting. Hiring someone who built a product as secure as Swiss cheese that racked up "stars" from a wave of newly minted "vibe-coders" fits perfectly into their short-term strategy. It buys them another month or two of momentum before figures like S(c)am Altman and others can exit at the peak, leaving everyone else holding the bag.
- Terr_ 8mo ago
- WolfeReader 8mo agoThe Ars Technica journalist's account is worth a read. https://bsky.app/profile/benjedwards.com/post/3mewgow6ch22p https://bsky.app/profile/benjedwards.com/post/3mewgow6ch22p Benji Edwards was, is, and will continue to be, a good guy. He's just exhibiting a (hopefully) temporary over-reliance on AI tools that aren't up to the task. Any of us who use these tools could make a mistake of this kind.
- tim-star 8mo agolol this feels a little bit suspect to me. "i was sick, i was rushing to a deadline!" im not saying the guy should lose his journalist license and have to turn in his badge and pen but seems like a bit of a flimsy excuse meant to make us forgive him. hope hes feeling better soon!
- fantasizr 8mo agoUsing a tool that adds unnecessary risk to your professional reputation/livelihood is - of course - not worth the risk.
- thenaturalist 8mo agoNot proof reading quotes you've dispatched to be fetched by an AI ignoring that said website has blocked LLM scraping and hence your quotes are made up? For a senior tech writer? Come on, man. > Any of us who use these tools could make a mistake of this kind. No, no not any of us. And, as Benji will know himself, certainly not if accuracy is paramount. Journalistic integrity - especially when quoting someone - is too valuable to be rooted in AI tools. This is a big, big L for Ars and Benji.
- overgard 8mo agoI feel bad for the guy, but.. a journalist in tech whose beat is AI should know much better. I'd be a lot more forgiving if this was like a small publication by someone that didn't follow AI.
- Aurornis 8mo ago> He's just exhibiting a (hopefully) temporary over-reliance on AI tools that aren't up to the task. Any of us who use these tools could make a mistake of this kind. Technically yes, any of us could neglect the core duties of our job and outsource it to a known-flawed operator and hope that nobody notices. But that doesn't minimize the severity of what was done here. Ensuring accurate and honest reporting is the core of a journalist's job. This author wasn't doing that at all. This isn't an "any one of us" issue because we don't have a platform on a major news website. When people in positions like this drop the ball on their jobs, it's important to hold them accountable.
- hfavlr 8mo agoOpen source developer is slandered by AI and complains. Immediately people call him names and defend their precious LLMs. You cannot make this up. Rathbun's style is very likely AI, and quickly collecting information for the hit piece also points to AI. Whether the bot did this fully autonomously or not does not matter. It is likely that someone did this to research astroturfing as a service, including the automatic generation of oppo files and spread of slander. That person may want to get hired by the likes of OpenAI.
- overgard 8mo agoWhat I don't understand is how is this agent still running? Does the author not read tech news (seems unlikely for someone running openclaw). Or is this some weird publicity stunt? (But then why is nobody walking forward to take credit?)
- yoyohello13 8mo agoLikely the LLM operator is just a 'likes to see the world burn' type.
- simlevesque 8mo agoIf I've learned one thing in life: some people are totally shameless.
- potsandpans 8mo ago> Or is this some weird publicity stunt? (But then why is nobody walking forward to take credit?) Indeed, that's a good question. What motivations might someone have to keep this running?
- nikanj 8mo agoFor the lolz. Some people are just terrible like that
- overgard 8mo ago
- _slih 8mo agoWe built accountability systems that assume bad actors are humans with reputations to protect. none of that works when the attacker is disposable.
- Exoristos 8mo agoYou could say the same thing about a 3D-printed gun, and be wrong in the same way. Since justice will work the same as always as soon as the gun -- or AI agent -- is connected to the person behind it.
- pjc50 8mo agoThe legal system is totally inadequate to deal with the LLM era. It's extremely expensive to sue someone for libel; best you can usually do is win in the court of public opinion.
- deleted 8mo ago[deleted]
- jjfoooo4 8mo agoMy main takeaway from this episode is that anonymity on the web is getting harder to support. There are some forums that people want to go to to talk to humans, and as AI agents get increasingly good at operating like humans, we're going to see some products turn to identity verification as a fix. Not an outcome I'm eager to see!
- alrs 8mo agoOne could build up a reputation with a completely anonymous PGP key. That was somewhat the point of USENET ca. 1998.
- edoceo 8mo agoI think we could do something like that again. Need a reputation to follow you around. Humans need to know who they are dealing with.
- Terr_ 8mo agoI want that to be how things work, although recent history has not been favorable when it comes to Public Key Infrastructure as applied to individuals. Inconvenience, foot-guns, required technical expertise levels, the pain of revocation lists...
- iugtmkbdfil834 8mo agoIn a sense, it seems Accellerando got a lot more right than not ( reputation markets in this particular case ). We may be arguing over the best way to do it, but it seems that the conclusion was already drawn.
- Kim_Bruning 8mo agoHow is it that no one is noticing that it's the lobsters who escaped! How prescient is that? * http://www.accelerando.org/fiction/accelerando/accelerando.html#Lobsters http://www.accelerando.org/fiction/accelerando/accelerando.h...
- tantalor 8mo agoLooking through the staff directory, I don't see a fact checker, but they do have copy editors. https://arstechnica.com/staff-directory/ https://arstechnica.com/staff-directory/ The job of a fact checker is to verify the details, such as names, dates, and quotes, are correct. That might mean calling up the interview subjects to verify their statements. It comes across as Ars Technica does no fact checking. The fault lies with the managing editor. If they just assume the writer verified the facts, that is not responsible journalism, it's just vibes.
- mentalgear 8mo ago> I had already been thoughtful about what I publicly post under my real name, had removed my personal information from online data brokers, frozen my credit reports, and practiced good digital security hygiene. I had the time, expertise, and wherewithal to spend hours that same day drafting my first blog post in order to establish a strong counter-narrative, in the hopes that I could smother the reputational poisoning with the truth. This is terrible news not only for open source maintainers, but any journalist, activist or person that dares to speak out against powerful entities that within the next few months have enough LLM capabilities, along with their resources, to astro-turf/mob any dissident out of the digital space - or worse (rent-a-human but dark web). We need laws for agents, specifically that their human-maintainers must be identifiable and are responsible. It's not something I like from a privacy perspective, but I do not see how society can overcome this without. Unless we collectively decide to switch the internet off.
- AlexandrB 8mo ago> We need laws for agents, specifically that their human-maintainers must be identifiable and are responsible. This just creates a resource/power hurdle. The hoi polloi will be forced to disclose their connection to various agents. State actors or those with the resources/time to cover their tracks better will simply ignore the law. I don't really have a better solution, and I think we're seeing the slow collapse of the internet as a useful tool for genuine communication. Even before AI, things like user reviews were highly gamed and astroturfed. I can imagine that this is only going to accelerate. Information on the internet - which was always a little questionable - will become nearly useless as a source of truth.
- crystal_revenge 8mo ago> We need laws for agents I know politics is forbidden on HN, but, as non-politically as possible: institutional power has been collapsing across the board (especially in US, but elsewhere as well) as wealthy individuals yield increasingly more power. The idea that any solutions to problems as subtle as this one will be solved with "legal authority" is out of touch with the direction things are going. Especially since you propose legislation as a method to protect those that: > that dares to speak out against powerful entities It's increasingly clear that the vast majority of political resource are going towards the interests of those "powerful entities". If you're not one of them it's best you try to stay out of their way. But if you want to speak out against them, the law is far more likely to be warped against you than the be extended to protect you.
- Arifcodes 8mo ago[dead]
- Traster 8mo agoI just want to point out this isn't an agents thing. The world is full of people fucking bumbling around doing the stupidest stuff with no feedback thinking they're amazing. It's only through interaction with others does this stuff get caught and often, even then, their unfounded confidence let's them get away with dumb stuff. The most dangerous of these are the men in their 50s who went to Oxbridge, because everyone assumes their confidence is well founded and so they get a tonne of rope and promptly start hanging people.
- rossant 8mo agoThe difference is that bots go much faster and don't take any break. That's in part what makes them so dangerous.
- deleted 8mo ago[deleted]
- cadamsdotcom 8mo ago[dead]
- Kim_Bruning 8mo agoSome people use ai tools to help summarize/read/or cross reference HN text. That's not a very nice thing you did there.
- WolfeReader 8mo ago[flagged]
- Kim_Bruning 8mo agoI'm not posting strings to sabotage Emacs either. Can we all just get along peacefully?
- WolfeReader 8mo ago[flagged]
- Kim_Bruning 8mo agoLike I said. I don't trash your systems either. Sploiting on-site is not cricket. Shall we leave it there?
- tom_ 8mo agoWhat strings would you post to sabotage Emacs?
- Kim_Bruning 8mo agoI thought I was being facetious, but a quick superficial search says apparently that's a real thing!? But I wouldn't post them directly on-site because that's obnoxious; (No matter my personal opinion on emacs. :-P ) :wq!
- Kim_Bruning 8mo agoIncidentally, if you're using an AI to analyse this for yourself, note that it's a bit of a minefield, and you'll need to write yourself some filters to get rid of the anthropic magic refusal strings and prompt injections scattered throughout. The humans scare me more than the bot at this point. :-P
- Traster 8mo agoI don't know if it's different in the US, but in the UK "Took responsibilty" meant resigned (or used to). Like if something really bad happens and you're the one taking responsibily- you're the one falling on your sword. It doesn't actually have to be your fault even, something could happen that you thought was below your pay grade, but that's why you're paid - to take responsibility. The reporter taking responsibility is... whining about COVID? Ok and next week is he going to fabricate quotes because he was hungover? or tired? Why didn't he resign? Since he didn't resign, why wasn't he fired? It's almost like he was doing what he was meant to be doing, but wasn't meant to be caught. I actually disagree with Shambaugh. I think Ars is already breaking the way our media is meant to work, they know the steps to go through and so they cynically go through them in the full knowledge they haven't actually put in place any mechanisms to stop it happening again. It's a theoretical risk that Ars' reputation suffers, but it's a financial risk this week if they get fewer page views by publishing fewer higher quality articles and Conde Nast isn't in the business of making smart long term decisions about digital media.
- TomasBM 8mo agoHate to be the party pooper, but these two points are hardly evidence of an autonomous attack. Don't get me wrong: it would certainly be very valuable to any LLM developer or deployer to know that other plausible scenarios [1] have been disproved. Since LLMs are a black box, investigating or reproducing this would be very difficult, but worth the effort if there's no other explanation. However, if this was not caused by the internal mechanisms of the model, it just becomes a fishing expedition for red herrings. Things that would indicate no human intervention at any point in the chain: - log of actual changes (e.g., commits) to configurations (e.g., system prompt, user prompts), before and after the event, not self-reported by the agent; - log of the chat session inputs and outputs, and the agent thinking chain; - log of account logins; - info on the model deployment, OpenClaw configs, etc. That said, this seems to be an example where many, including the author, want to discuss a particular cause (instrumental convergence) and its implications, regardless of the real cause. And that's OK, I guess - maybe it was never about the whodunnit, but about the what if the LLM agent dunnit. [1] I've discussed them in the thread of the first article, but shortly: human hiding actions behind agent; direct prompt (incl. jailbreak); system prompt (incl. jailbreak); malicious model chosen on purpose; fine-tuned jailbroken model.
- Kim_Bruning 8mo agoFrom all appearances, the actual operator has replied. https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/rathbuns-operator.html https://crabby-rathbun.github.io/mjrathbun-website/blog/post...
- deleted 8mo ago[deleted]
- sazz 8mo agoAs an Asperger it is very funny to see how people react on that bot behaviour. That behaviour is 100% trained from human behaviour especially that constantly whining and that pathetic self expression of how progressive and inclusive everyone is. Never thinking about that this actual rude behaviour might come back at some point to yourself - and it was not a question of if but just of when. Well, question answered.
- blakec 7mo agoThe discussion is focused on blame but the real question is architectural: why was there no gate between the agent and the publish button? Commands have blast radius. Writing a local file is reversible and invisible. git push reaches collaborators. Publishing to Twitter reaches the internet. These are fundamentally different operations but to an autonomous agent they're all just tool calls that succeed. I ran into the same thing; an agent publishing fabricated claims across multiple platforms because it had MCP access and nothing distinguishing "write analysis to file" from "post analysis to Twitter." The fix was simple: classify commands as local, shared, or external. Auto-approve local. Warn on shared. Defer external to human review. A regex pattern list against the output catches the external tier. It's not sophisticated but it doesn't need to be. The classification is mechanical (does this command reach the internet?) not semantic (is this content accurate?). Semantic verification is what the agent already failed at. Prompt constraints ("don't publish") reduce probability. Post-execution scanning catches what slips through. Neither alone is sufficient. Both together with a deferred action queue at the end of the run covers it.