I think they explicitly said that.
5,685 karma · joined December 24, 2013
I think they explicitly said that.
Especially this. OpenAI will host it. OpenAI will throw "Sign in with ChatGPT" there. "Apps" will be built that depend on end users ChatGPT "connections". The app will fundamentally not work without an end-user having a ChatGPT account/subscription and "connected apps".
Having "the best model" will absolutely not support a $1T+ valuation. Owning the activity of 25-50% of internet users (assuming a split between OAI/Anthropic/Google/maybe-Meta), is.
Straight from the HN Guidelines page:
- Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".
In this case, the "agent" had every intention of doing what it was doing.
I'm not claiming that "accidental hacking" (whether by human, or agent) is covered and illegal. I am claiming that calling this "accidental" is not a valid defense. One incident? Maybe. But this is pretty far past one incident.
It’s a camera system, and data can be queried by police. They have to search for something. So the cops searched for a vehicle matching the description in the general area, seemed to take the first one, and called it a day.
That’s not an AI-uncanny-valley. That’s the equivalent of (pre-flock/cameras) looking at vehicle registration list and assuming the one at the top of the list must be it.
The automation-trust is a legitimate concern but it’s not applicable here.
As far as I know, it lets law enforcement query for things against the data. Can be specific (like a license plate) or more general (like a dark colored mid-sized SUV around <location> at <time>).
To get where this story is at, cops here must have done the latter, and taken the first name off the top of the pile and patted themselves on the back, and then waited 7 months, and went and arrested her. Unless there’s an explanation for a 7 month delay, it seems designed to allow defensive evidence to spoil.
There isn’t an uncanny-valley of automation here. There is just lazy, grossly-incompetent, bad-faith, and malicious cops/investigators.
The headline is what 99% of people read, and remember.
This situation the equivalent of an eye-witness saying "Ya, I think it might have been this person I know, Tom!" and a cop/prosecutor taking that at face value and arresting Tom (and the system that allowed that to happen).
The people who make decisions and take action so (grossly) negligently need to be held accountable and face consequences. Blaming the tool (whatever tool it is) is giving the people who have the actual responsibility an escape hatch to avoid accountability.
This is literally the first sentence of the article.
You can dislike public surveillance, but statements like "Flock camera data put this woman in jail for 13 days" blatantly ignores the the fact that Flock didn't put anyone in jail, a bunch of cops who very clearly knew that it wasn't her.
> The Flock camera, meanwhile, had recorded Isaacs’ car and its license plate several miles away from the site of the accident, sometime around the time of the incident.
Blaming a tool, when the cops in question are clearly willing to grasp to whatever piece of "evidence" makes their job "easier" is a giant cop-out and excuse for the people who are abusing it.
Any piece of evidence requires some form of critical examination; that is what law enforcement's job is. If you're just going to go with the first theory/piece-of-evidence they find.... they're not doing their job (and violating peoples constitutional rights through sheer laziness).
Which is just... highly unfortunate.
The additional thing is that it... isn't a bad sign. I have seen a ton of terrible AI-slop food signage. This sign does not try to be "hyper-realistic", and end up in an uncanny-valley, or look like fake food. It's not fully of spelling mistakes and things disobeying the laws of physics.
Does it have maybe too much information shoved on it? Sure. Does it use a font that is definitely "AI-popular". Ya.
But there are tens of thousands of worse examples of AI menu usage out there. It seems people decided to pick on this one because it's not horribly done. A local artist looked at it and, instead of thinking "wow that looks soo fake", they thought "that's basically the same thing I would have delivered, and 99% of people wouldn't have been able to tell the difference! I should have been paid for that!"
Reference: the sign in question: https://www.instagram.com/p/DdBgsgnNDaC/
Not only are yo projecting, you are attributing "AI coffee shop sign" with "not successful". You yourself say what made your "retail" successful was "the care I put into curating the product, building out the space and attending to the customers". None of those are "the A-frame sign that we put out for specials".
You are trying to find one thing you disagree with and use that to call the owner "too lazy" and "doesn't care about their work".
If you think the opposite, and that small business owners have ample time and are just lazy when they don't build everything from scratch, you should teach a course about how to manage a small business.
People take things very personally when their core livelihood and ability to support themselves are threatened.
The issue comes when you (or someone, not you personally) dig way to deep into what "it" is, there is always something that someone was, to quote you, "too lazy to do yourself". You might not like the result, and that's fine, but you're phrasing it as if the other person is just being unnecessary-lazy.
They probably bought their display stands instead of designing and building them themselves. They also probably bought the cheap ones from Amazon (instead of building them themselves, or hiring a local artisanal carpenter to build them).
Do you refuse to engage with a pastry stand because the owner was "too lazy to do it themselves"? If you're at a friends house and they order food, do you refuse to engage with it because "they were too lazy to cook it themselves"? Where do you draw the line?
Your point as it applies to something that takes a sufficient portion of your time is valid, but this conversation is literally about a menu sign at a coffee shop. If you spent substantial time engaging with a coffee shop sign, I have questions (and wouldn't want to be behind you in that line).
The way to make these transitions less aggressive on everyone is to not have it tied directly to whether or not someone can afford to eat.
You might not have spent a lot of time in the world of "small business", but this is hysterically out of touch.
In terms of "We wrote a hacking agent designed only for hacking and sell it as a self-hacking service and then pointing it at someone else and omg can you believe what it did we had no intention of hacking" sense, I don't think that's really applicable.
The mens rea is explicitly there and it's not valid for them to try to hide behind an "agent".
Ya, returned it after poking through all of the drawers and iterating through business information that they found.
There is a white-hat line that OP very clearly crossed here.
The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission).
Anthropic/OpenAI can reasonably claim that they had no intent and are trying to stop it. OP here did this explicitly and purposely.
The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".
It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!".
Strix also crossed the line at this point:
> Strix decided to pull an image and see what was inside.
You're going past the white-hat point here when you start active exfiltrating data and looking at it. Once you start using credentials from the exfiltrated data and start listing and poking around internal systems, you are way past it.
Listen, I get it, their product is "meant for" self-testing, so it assumes it's safe to go digging. After all, it's a self check. That is exactly why it's irresponsible, and borderline illegal, for them to point it at a third party. Even if they had "permission", I dobut that permission extended to "and also search and/or download our repos if you can".
The overall tone is less than professional. Statements like (in bold) "This is an insane amount of access to leave in a publicly downloadable image." Everyone is aware of this, and it's phrase like it was a purposeful decision.
Security tools from teams that actively shit on the people they're designed to "help" feels wrong.
Edit: For clarity on my point about "pulling repos", this post includes descriptions of the purpose and functionality of multiple repos (which is past what a name gives them), and they explicitly state: "A listing of that private repo showed a top-level customers/ directory, with subdirectory after subdirectory named after Baseten customers". Strix explicitly took action that they knew they were not permitted, and extracted confidential customer information. Claiming "We didn't clone the customer repo" when you, instead, just listed the contents of the repo, is not a valid defense.
If you are big enough to be able to withstand that, you’re already running (or trying to run) your own/open-weight models.
The general wealth distribution has shifted to the point that they do not need access to public funds, and frankly, if they can't find private funds for their needs, it is a huge red flag that they would just be dumping on the public.
Yes.
As of the current moment, the domain is just pointing to an IP owned by "Abacus.AI, Inc.". The entire platform is "describe the app you want and we'll generate it and host it for you".
Might just be my opinion, but I consider a Show HN that is "look at the thing AI entirely made for me" to not really be aligned with good faith sharing of work/projects.
My claim of "bad faith" was specifically because the post, between 1) explicitly pointing to a "full stack ai dev platform" ("So I had abacus.ai whip one up"), and 2) the entire missing list of "observations" (mid post), came off more as a shadow advertisement for an ai dev tool than an actual project.