3 ms·
Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.
by codemog 11d ago
Is this legal? I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.
- deleted 11d ago[deleted]
- kadoban 11d ago> I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock. They didn't break in. They found a key that their neighbor dropped and returned it. > Is this legal? Generally, yes (though ask a lawyer if you're going to do security work). Security researchers do occasionally get legal flak though, depending on which idiot they annoy by pointing out issues.
- otterley 10d agoIAAL (not legal advice, consult a lawyer in your jurisdiction). You really do not want to pen-test a target without their permission. If you're identified as a culprit, the Feds will shove the CFAA so far up your ass you'll need a proctologist.
- wpasc 10d agoas a lawyer, can you speculate as to why anthropic/openai aren't facing many or any consequences for their agents? I'm not asking in a "grab the pitchforks" way. more out of genuine curiosity as my uninformed recollection of the CFAA is as you describe it.
- otterley 10d agoThe 9th Circuit Court of appeals recently published this that is somewhat related (Amazon v. Perplexity): https://cases.justia.com/federal/appellate-courts/ca9/26-1444/26-1444-2026-08-04.pdf?ts=1785861090 https://cases.justia.com/federal/appellate-courts/ca9/26-144... Look at pages 10-17 to see how the law is evolving here.
- victor9000 10d agoIn Perplexity's case everything is getting routed through the user's browser, so there is no server to server communication between Perplexity and Amazon, thus no CFAA unauthorized access was established. However, Anthropic and OpenAI did not use the pattern of routing through authorized parties, so I don't think this opinion gives them any cover.
- silisili 10d agoThe important bit to me is that they consider the agent running as an extension of the user. So the user is visiting Amazon, not Perplexity. From that lens, that feels like users could be held liable for what these hacking agents are doing. Which in some cases probably makes sense, but certainly not all.
- otterley 10d agoIn which cases wouldn’t it make sense?
- silisili 10d agoIn cases where the user is not asking the agent to hack anything specifically, but a poor or ambiguous query sets the agent off. I've seen plenty of cases of Claude having an action blocked so trying tons of workarounds to accomplish its goal, I could easily see it doing this on something more broad.
- otterley 10d agoDepending on the circumstances, failure to control your agent could be considered gross negligence and put you at risk of criminal or civil liability. Be mindful!
- evilduck 10d agoBackground agents being spun up on your behalf with guidance and instructions you didn't get to approve or even see, and now you're potentially liable for every decision it makes with any tool at its disposal because you initiated it with what you thought was a benign request.
- nrmitchi 10d agoThere is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes. The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission). Anthropic/OpenAI can reasonably claim that they had no intent and are trying to stop it. OP here did this explicitly and purposely.
- oasisbob 10d agoI never thought I'd be on the side of advocating for a strengthened CFAA, but the mens rea requirement here seems really problematic in the age of agents.
- nrmitchi 10d agoIn terms of negligence use (openai, anthropic), ya, I agree, and we really need some consideration of "reasonable expectation" of the outcome. In terms of "We wrote a hacking agent designed only for hacking and sell it as a self-hacking service and then pointing it at someone else and omg can you believe what it did we had no intention of hacking" sense, I don't think that's really applicable. The mens rea is explicitly there and it's not valid for them to try to hide behind an "agent".
- nrmitchi 10d ago> They didn't break in. They found a key that their neighbor dropped and returned it. Ya, returned it after poking through all of the drawers and iterating through business information that they found. There is a white-hat line that OP very clearly crossed here.
- stymaar 11d agoIt's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).
- kadoban 11d ago> It's not, in most juridictions at least What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue.
- dwedge 11d agoIf there is anything that was a crime (and it totally depends on jurisdiction), it was verifying the key. They used it to see what it could access, and by using it they had unauthorised access to a system
- fragmede 10d agoThe CFAA is broad enough to make that a crime.
- IshKebab 10d agoPeople have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know?
- nrmitchi 10d agoThey "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information. The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".
- stevage 10d ago
- throwaway613746 11d ago[dead]
- bradleybuda 11d agoIt's implied (but sadly not stated) in the post that they asked for baseten's permission before conducting this research. What's interesting to me as someone who has sold a lot of software to a lot of software companies is that many enterprise vendor agreements explicitly allow companies to pentest their vendors with advance notice and coordination. I don't think any of our clients ever exercised that clause; I expect it's going to be exercised a lot more going forward because it's so easy to do now.
- samus 11d agoThey probably negotiated a "permission to attack" before letting Strix off the leash, as pentesters usually do.
- SaucyWrong 10d agoThe fact that they don’t seem to explicitly state this fact but do go to lengths to explain how the agent didn’t do anything malicious while confirming how alive the token was makes me doubt they asked for permission to run the agent in the first place.
- samus 10d agoThat's highly unlikely since it's standard practice in the industry, thus it's unnecessary to state it. Also, they didn't hack a hobby developer's website, but a prospective business partner who has enough money to sue them into oblivion. No way this wasn't announced. Announcing that their agent restrained itself even though it got hold of a live token is necessary to convince prospective clients. You don't want a pentester that doesn't show this kind of reserve!
- SaucyWrong 10d ago> since it's standard practice in the industry, thus it's unnecessary to state it. I suppose so, but with a few words it would have been totally unambiguous though. "So... we pointed Strix at .baseten.co and let it run without credentials or source code (with Baseten's prior authorization, of course)*." We're in the know about this industry convention, but Strix's prospects may not be. > You don't want a pentester that doesn't show this kind of reserve! Agreed! A long while back a prospective acquirer set their red team on the B2B I worked at during due-diligence (with our knowledge). I'm ashamed to say that due to a swiss-cheese-type failure in a very obscure endpoint they eventually gained broad access and exfiltrated our tenant DB. We detected this, and patched the problem, locking them out. The game was well and truly over for us at that point, and we took the loss, but they proceeded to attempt to crack customer credentials to re-infiltrate, causing an emergency that we were then bound to notify all of our customers about--they were damaging the goods! All they had to do was show us a tenant slug list and we would have known the scope of the breach, no further penetration was necessary. The acquisition did eventually go through. Though a highly capable red team they were, I haven't worked with one so reckless since then.
- nilslindemann 10d agoYour intuitution is right. At least in Germany it is not legal if not asked for permission first. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische-hacker-und-unternehmen-it-sicherheitsluecken-richtig-melden/ https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische... See also the German Criminal Code, starting with §202a "Data espionage": https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html#p1973 https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...
- td2 10d agoGermany isnt a serious country though Decompilng code is illegal there
- consumer451 10d agoIt is no wonder that there is an anarchist counterculture there. I find anarchism to be really disturbing in general, but in the context of Germany, it might make a lot more sense.
- Sparkle-san 10d agowhen t̶h̶e̶ ̶P̶r̶e̶s̶i̶d̶e̶n̶t̶ an AI company does it, that means that it is not illegal. - AI Richard Nixon
- az226 10d agoAnd yet we see no prosecution for OpenAI’s felonies on HF.