3 ms·
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no
by brookst 23d ago
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction.
Do you think there is evidence of this?
- bix6 23d agoHonestly yeah I bet there is and I hope to someday read about it if the government ever gets off its ass. Someone set up the “experiment”…
- VyseofArcadia 23d agoIt would seem to me that the difference between the corporate world and organized crime is that a corporation can get away with, "the responsibility is too diffuse" but the mafia at least has to go to the trouble of finding a fall guy.
- shakna 23d ago> There are no negligent or stochastic hacking laws I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access". You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count. > knowingly accesses a computer without authorization or exceeds authorized access [1] "Knowingly", not "intentionally", as in the other counts. You only have to show that: a) They trained a system to access without authorization (hacking) b) The system that was trained exceeded authorized access As responsibility falls to the operator with automated systems, the company becomes liable. [0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-responsibility/ https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res... [1] https://www.energy.gov/sites/prod/files/cioprod/documents/ComputerFraud-AbuseAct.pdf https://www.energy.gov/sites/prod/files/cioprod/documents/Co...
- user43928 22d agoI'm not a lawyer but I don't think Sam Altman 'knowingly accessed' anything. Are you sure that is applicable here? And for the first count with 'knowingly accessed', he would need to have accessed classified national-defense or atomic-energy information, otherwise we are back to 'intentionally accessed'.
- shakna 22d agoThe first count is "or any restricted data", not classified material. A technological restriction, is enough. "Knowingly accessed" has never meant you personally. Operators of a botnet don't know directly what they access. They know that the autonomous software is built to access restricted things.
- user43928 22d agoI don't think so: > or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with the intent or reason to believe that such information so obtained is to be used to the injury of the United States, or to the advantage of any foreign nation
- shakna 22d agoWell I suppose no one has ever been charged under that paragraph of the law then. And the courts have never interpreted it that way.
- user43928 22d agoI understand it was applied in the case of leaking classified CIA material to WikiLeaks, where a former CIA software engineer was sentenced to 40 years in prison.
- mullingitover 22d ago> I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access". Frankly he got off too easy, but we haven't explicitly outlawed "being a malicious dipshit" so he got convicted on the closest available charge. > Chat logs obtained by the prosecution do not paint the pair in a flattering light. They discussed, but apparently did not carry out, a variety of schemes to use the harvested data for nefarious purposes such as spamming, phishing, or short-selling AT&T’s stock.[1] 1000% agree though that the operators of these systems are culpable. If their agents wind up being malicious dipshits, the agents are still just programs that they are operating. At best they're negligent. [1] https://arstechnica.com/tech-policy/2012/11/internet-troll-who-exploited-att-security-flaw-faces-5-years-in-jail/ https://arstechnica.com/tech-policy/2012/11/internet-troll-w...
- hallway_monitor 22d agoSo we make a law that the CEO is responsible for actions of any agent created or operated by anyone in their company. CEOs will get serious about AI security real quick. Honestly we need to do something. There needs to be a single wringable neck.
- Octoth0rpe 22d ago> There needs to be a single wringable neck. Does there? Could be the whole c-suite/board.
- ryandrake 22d agoI'd settle for any number of necks. Currently, when a corporation fucks something up, breaks the law, or hurts or even kills people, there aren't consequences besides a tiny token fine and a strongly worded letter telling them to not do it again or they'll get another tiny fine and letter, and their CEO might even have to sit down in front of Congress to say a few words and look sad.
- embedding-shape 22d agoWhatever is easiest to legislate and most people agree on, as long as there is at least one wringable neck.
- jonway 22d agoI feel like our legislators would never get this far. They really don’t seem to care, maybe after “their emails get hacked”, but do you find it likely for this to actually pass into law?
- jonway 22d agoI feel ya, but who is we? The legislature would probably take a glance at the stock valuations, apply their limited knowledge of technology and after being lobbied by every tech company with skin come to the opposite conclusion.
- bonzini 22d ago
- nicce 22d agoThat is not how it works, at least in a civilized country. The charges are not about agents, it is about operational responsibility and negligence in the company itself. CEO is responsible for letting this to happen, not enforcing enough supervision, if not intentionally, then being grossly negligent. More severe if encouraging and letting this kind of agent research and operations happen at scale, while knowing that it can damage other systems and businesses.
- bonzini 22d agoNegligence is enough. Somebody who brags every other day that AI could lead to human extinction surely would think twice before leaving agents run unchecked over the internet?