HNHacker News
TopNewBestAskShowJobs

tptacek

425,412 karma · joined November 1, 2007

Having said thus much by way of introduction, I commit the following to the candour of the Publick.

Helu! I'm Thomas.

thomas@sockpuppet.org

t@tk.inc

(Don't apologize for contacting me! I'm happy to meet you.)

Daily follow list: 'jcranmer, 'rgovostes, 'pvg, 'rgovostes, 'lisper, 'kentonv, 'DannyBee, 'JumpCrisscross, 'kasey_junk, 'tzs, 'dctoedt, 'idlewords, 'carbocation (many others who don't post often enough to call out like this).

All comments Copyright © 2010, 2011, 2012, 2013, 2015, 2018, 2023, 2031 Thomas H. Ptacek, All Rights Reserved.

submissionscomments
tptacek··on 1 in 8 cancer cases worldwide are caused by infections, study finds
I'm not asking if it's plausible, I'm asking if there's evidence it happened.
tptacek··on 1 in 8 cancer cases worldwide are caused by infections, study finds
Has there been a clear epidemiological signal post-COVID in elevations of any cancers? There are obviously stories about elevated rates of e.g. colon cancer in younger people, but those long predate COVID.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
Right, I don't dispute that their PR language minimizes their culpability in public opinion, but I don't see how it impacts their liability in court.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
How exactly is that minimizing their liability? You just described claims that do not appear to at all minimize liability.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
That's not how civil liability works.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
In what way specifically does it minimize their liability? People say this a lot but it's not clear what they mean by this.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
Civilly, it's fairly clear. Criminally, it's clear too, just not in the direction you want it to be. Criminal liability for hacking requires human intent; not recklessness or negligence or even knowledge without giving a shit, but provable intent.
tptacek··on Who should be held accountable when an AI Agent (accidentally) acts maliciously?
Obviously, the labs (or any other operator of a model) should be accountable for malicious or destructive actions taken by agents.

And they are. I don't think there's any controversy about the civil liability exposure frontier labs have if their agents cause damages, and it is remarkably easy to rack up damages by causing computer intrusions even if those intrusions don't cause obvious direct damages; for instance, many organizations are required to engage forensics firms at nosebleed-high costs to assess the impact of breakins in order to retain insurance coverage.

The "controversy", if you want to call it that, is over criminal liability. People feel that frontier labs should be at least as responsible criminally as human hackers are when they're caught (to be clear: an extraordinarily rare outcome).

The problem is: they're not criminally liable, not so long as the frontier labs operate without specific intent to cause breakins. Mens rea thresholds are their own whole area of criminal law, and there are stark differences between "recklessness" and "intent". All of the meaningful criminal CFAA predicates require actual intent: someone, a human being, has to deliberately set out to create the outcome where a specific intrusion happens. They have to want it to happen and act accordingly. In the most severe cases, they also have to do so with intent to defraud.

We could change the law to make it easier to prosecute breakins without provable intent, but I don't think that would make HN people happier.

tptacek··on There are no "rogue" AI agents
100% Human Written. See, that's how to do it.
tptacek··on Plunging test scores are a slow-moving catastrophe
They are measurable in theory, one supposes, but since that's never ever happened before, there are in practice no such scores.
tptacek··on There are no "rogue" AI agents
Pangram exists. That post: 100%. Please don't bother. It was so obvious that HN autokilled it at first.

You can save yourself some time replying to me in the future; I'm going to check every single time, now that this has happened here.

It's also specifically against the rules here. HN is for people to talk to people; generated comments aren't allowed.

tptacek··on There are no "rogue" AI agents
Please don't respond to me with ChatGPT.
tptacek··on Does Georgism work? Five years later
Within my lifetime, the municipality in which I live enacted policies (historic preservation and racial steering of apartments) specifically to limit the number of Black families that moved in. The preservation-based restrictionism continued into the 1980s (and, of course, remains in force today); the steering into the late 1990s. Our Fair Housing Ordinance included an escape clause allowing our board to resegregate specific blocks, and just a year or two before I was born, they used it.

This is not ancient history.

tptacek··on Plunging test scores are a slow-moving catastrophe
There are no such thing as real country-by-country IQ scores.
tptacek··on There are no "rogue" AI agents
The Nosal decision apposite here was superseded by Van Buren, a SCOTUS decision that, if I'm reading your comment here right, explicitly refutes your interpretation. I think?

Also in the Ninth Circuit: Amazon.com Services v. Perplexity AI.

I really don't see how you can synthesize "intentionally accesses" and/or "knowingly and with intent to defraud" out of recklessness or negligence. Those are very different concepts in the law.

tptacek··on There are no "rogue" AI agents
Circumstantial evidence is just called "evidence" in criminal court. My argument isn't based on whether there's black-letter evidence of intent; it's that there's unlikely to be any evidence of intent. "Recklessness", "negligence", "willful disregard"; these are all concepts that have their own specific language in criminal law. Deliberate intent is just that: a human had to have a picture in their head of the crime that was to be committed, and a desire for that to happen. You don't have evidence of that because it's not what happened.
tptacek··on There are no "rogue" AI agents
I don't see how that follows at all. There are strict liability crimes and there are crimes with specific intent standards. Presumably you've read the CFAA language.
tptacek··on There are no "rogue" AI agents
No, it's not nebulous at all; it's a whole area of criminal law. I'm basically shoplifting arguments Daniel Berlin made about this just a couple days ago. If you think he's wrong: lay out the case you think could be made here.

The problem you have is that there is unlikely to be any evidence that OpenAI actually wanted to hack random (or any) websites.

tptacek··on SNL Weekend Update: Anthropic CEO Dario Amodei on A.I.'S Threat to Humanity [video]
This is the best thing Jane Wickline has done. I worried about whether she was on the bubble because she's so situational (I think that's a good thing), but clearly she's got staying power.
tptacek··on There are no "rogue" AI agents
In civil cases the "enforcement" generally comes from injured parties filing lawsuits.
tptacek··on There are no "rogue" AI agents
The labs are already liable civilly regardless of how these incidents are described.

Meanwhile: your dog mauling someone is one of the rare instances where criminal liability does attach to your intent-free-but-reckless actions. Most crimes don't work that way, and US computer intrusion statutes are unusually intent-specific.

tptacek··on There are no "rogue" AI agents
Can you say more? Under what law were they arrested? Where was this?
tptacek··on There are no "rogue" AI agents
However this makes people feel, and that's not nothing and I'm not knocking it, this is not a useful analysis.

Criminally, the intent standards for hacking are high enough that no reasonable case is going to be made against the labs for this stuff. A human being has to intend for websites to get hacked. Recklessness generally isn't enough. In the most severe criminal cases, not only do you have to prove intent to break into a computer, but you also need to prove an intent to defraud specific to that breakin.

Meanwhile, the civil liability that attaches to this stuff doesn't depend on intent, and "rogue agent" isn't a meaningful defense. To whatever extent the labs are exposed civilly, they're exposed regardless of how this stuff is described. In fact, the "rogue agent" thing can exacerbate their exposure.

(I'm not a lawyer, I have spent a career paying attention to this specific armpit of the law though.)

tptacek··on Ten lines of code that changed my world
Hmm. What a great question.

    while(1) { fork(); } 
Must have meant something to me, because it was in my Usenet sig. And then:

    exit(main(kfp->kargc, argv, environ));
from FreeBSD crt0; kind of a big moment for me to realize there was more C code underneath main().

Then:

    statements: /*E*/ | statement statements
The moment Yacc clicked for me; that line was profound but a more accurate depiction of the moment was realizing that all you were doing with the parser generator was building a tree, and that's what the side effects of each production were for: returning and plugging in tree nodes.

If there was a single line I could come up with for "double the size of the hash table when it fills up", that'd deserve a slot here.

Then, of course (we get to cheat because assembly):

    jmp .call
    .pop: pop esi
    ...
    .call: call .pop
The "delta offset" trick, which I believe came from x86 virus culture but was universal in 90s overflow exploits as a way to get position-independent references to strings and other memory things.

For sure:

    void walk(node *n) { if(!n) return; walk(n->left); visit(n); walk(n->right); }
I should figure out a way to fit a write-select(2) into a line because that's another "oh shit" moment for me.

Similarly: when Vern Paxson explained to me that he'd implemented TCP reassembly by simply opening up a file and using "seek" to place incoming segments in the right position. I could probably golf that down to a line! But it would be an annoying line.

tptacek··on Does Georgism work? Five years later
My business partners will chuffed when the vote happens in October or November, whichever way it goes, because this has been siphoning a huge amount of my attention over the last year.
tptacek··on What even is an OS now?
I will not be, because, again, I didn't submit this article here --- what I did instead was write this and then dread what would happen when it hit the front page.

That's not true for all (or even most) of what I write, but it's true this time, and I'm not letting it slide.

tptacek··on Tells of a Slop UI
An "inactive" student is one who is enrolled but is not currently attending classes.

This is a super useful article but a lot of these complaints about things like alignments are also the natural outcome of me, a non-frontend person, building any kind of web frontend at all. So I wouldn't sweat it too much.

tptacek··on What even is an OS now?
It pisses me off (not just for my own site) when people talk as if stories that show up on HN are somehow community property of HN. It's a page I put on my own website. I will make it look any way I fucking choose. People here do this all the time and I can only imagine how alienating it must be to website authors who aren't familiar with our giant clique.
tptacek··on What even is an OS now?
I am dismissive of that point of view, and I'm a "hacker". Not everybody here agrees on everything. I feel like I'm... pretty in tune with HN. Like, I think I could present concrete evidence on that claim.
tptacek··on Does Georgism work? Five years later
People have all sorts of unreasonable expectations and we are not obliged to honor them.
Page 1 of 34Next →