425,412 karma · joined November 1, 2007
Helu! I'm Thomas.
thomas@sockpuppet.org
t@tk.inc
(Don't apologize for contacting me! I'm happy to meet you.)
Daily follow list: 'jcranmer, 'rgovostes, 'pvg, 'rgovostes, 'lisper, 'kentonv, 'DannyBee, 'JumpCrisscross, 'kasey_junk, 'tzs, 'dctoedt, 'idlewords, 'carbocation (many others who don't post often enough to call out like this).
All comments Copyright © 2010, 2011, 2012, 2013, 2015, 2018, 2023, 2031 Thomas H. Ptacek, All Rights Reserved.
And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage.
The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome).
The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud.
We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier.
You can save yourself some time replying to me in the future; I'm going to check every single time, now that this has happened here.
It's also specifically against the rules here. HN is for people to talk to people; generated comments aren't allowed.
This is not ancient history.
Also in the Ninth Circuit: Amazon.com Services v. Perplexity AI.
I really don't see how you can synthesize "intentionally accesses" and/or "knowingly and with intent to defraud" out of recklessness or negligence. Those are very different concepts in the law.
The problem you have is that there is unlikely to be any evidence that OpenAI actually wanted to hack random (or any) websites.
Meanwhile: your dog mauling someone is one of the rare instances where criminal liability does attach to your intent-free-but-reckless actions. Most crimes don't work that way, and US computer intrusion statutes are unusually intent-specific.
Criminally, the intent standards for hacking are high enough that no reasonable case is going to be made against the labs for this stuff. A human being has to intend for websites to get hacked. Recklessness generally isn't enough. In the most severe criminal cases, not only do you have to prove intent to break into a computer, but you also need to prove an intent to defraud specific to that breakin.
Meanwhile, the civil liability that attaches to this stuff doesn't depend on intent, and "rogue agent" isn't a meaningful defense. To whatever extent the labs are exposed civilly, they're exposed regardless of how this stuff is described. In fact, the "rogue agent" thing can exacerbate their exposure.
(I'm not a lawyer, I have spent a career paying attention to this specific armpit of the law though.)
while(1) { fork(); }
Must have meant something to me, because it was in my Usenet sig. And then: exit(main(kfp->kargc, argv, environ));
from FreeBSD crt0; kind of a big moment for me to realize there was more C code underneath main().Then:
statements: /*E*/ | statement statements
The moment Yacc clicked for me; that line was profound but a more accurate depiction of the moment was realizing that all you were doing with the parser generator was building a tree, and that's what the side effects of each production were for: returning and plugging in tree nodes.If there was a single line I could come up with for "double the size of the hash table when it fills up", that'd deserve a slot here.
Then, of course (we get to cheat because assembly):
jmp .call
.pop: pop esi
...
.call: call .pop
The "delta offset" trick, which I believe came from x86 virus culture but was universal in 90s overflow exploits as a way to get position-independent references to strings and other memory things.For sure:
void walk(node *n) { if(!n) return; walk(n->left); visit(n); walk(n->right); }
I should figure out a way to fit a write-select(2) into a line because that's another "oh shit" moment for me.Similarly: when Vern Paxson explained to me that he'd implemented TCP reassembly by simply opening up a file and using "seek" to place incoming segments in the right position. I could probably golf that down to a line! But it would be an annoying line.
That's not true for all (or even most) of what I write, but it's true this time, and I'm not letting it slide.
This is a super useful article but a lot of these complaints about things like alignments are also the natural outcome of me, a non-frontend person, building any kind of web frontend at all. So I wouldn't sweat it too much.