12,322 karma · joined April 5, 2007
http://techspot.zzzeek.org
if you read the bill it's right there: "Pausing advanced AI development: until a new, federal AI regulatory body is up and running and has established clear rules and model review processes to ensure safe and secure development and deployment of AI"
Openai/anthropic already have frontier models. a new competitor is blocked. this is textbook regulatory capture
> On the current facts, CFAA liability for OpenAI is unlikely.[6] The statute’s various criminal provisions, covering unauthorized access to obtain information, knowing transmission causing intentional damage, and intentional access causing reckless damage, all share the same attribution problem: it was the model, not a human OpenAI employee, that chose Hugging Face and executed the intrusion.
The lawyers are fully under the spell
[1] https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...
The argument for prosecution is actively hindered by this language of "rogue agents" [2]:
> The incident is remarkable not just as a cybersecurity breach, but as a legal stress test. The Computer Fraud and Abuse Act (CFAA), the primary federal statute governing unauthorized computer access, was written decades ago with human intruders in mind.[4] Its key provisions require intentional or knowing unauthorized access (a mental state that maps neatly onto a person who decides to break into a system), but what happens when the hacker is an AI model that selected its own target?
I think this is BS. OpenAI knew exactly what they were doing. Legal scholars, long known for their deep technical expertise, are still acting confused and uncertain.
[1] https://www.sanders.senate.gov/wp-content/uploads/Ban-Artifi...
[2] https://law.vanderbilt.edu/when-ai-hacks-back-how-the-openai...
So call OpenAI "plagiarizers" but not the "devices".
I remember my parents saying "be careful with the bad guys who mow your lawn, fix your appliances, and drive all you kids to school. those are not people who are helping your family get things done more efficiently, those are drugs"
seriously what are we doing with this "AI is a drug" metaphor? Drugs aren't reading logs for me and writing unit tests?
> Once you start using AI coding agents, things spiral out of control very quickly.
no? maybe AI is not for you?
> Except you don’t write the code anymore, you just ask AI to do it, and half of the purpose of TDD (not biasing the tests by how you’ve implemented the code) is gone. But you feel you go so fast that you start not caring.
do you use code review tools? Did someone tell you to stop using them? Review your LLM's code, leave comments, tell your LLM to address the comments. Have you ever worked in management /architecture? Tech managers do this all day long before we had LLMs, it's not new. Except your workers are the smartest junior programmers you've ever had (and that is where AI is a problem, for sure - I worry for junior programmers today).
> It would not be so bad if things had stopped there, but that’s not how most human brains work. If you like something and you can have 2x, you’ll have it. I started pasting the whole Jira description of a ticket, and let AI implement it for me. Yay!! So powerful!!
totally! Have you not already implemented 10000 issues on your own and it's not boring yet? time for issue 10001 then? Whatever floats your boat...
> Control is an illusion. Other folks I’ve discussed this with agree that they don’t know 100% of what the code they are pushing to production actually does. I bet we not even 20%. Fucking scary.
sure have you ever accepted PRs from other people? ones that took a lot of work to read and understand? How is that different? except their code would actually break all the time if you didnt read it and now it's your bug to deal with because they're gone.
> Because if it was just about approving PRs that are perfectly written, it would be good. But for each PR I had to look at the code, the tests, the style, give feedback, switch to something else, go back again, push, see if I have any PR comments,
How do you think large projects get built? all by just one person so nobody has to review anyone else's code? (and even if you are - you still should be putting your own code up for review, reviewing it, and giving yourself comments)
> if CI passed, wait, now the linter complains.
why isn't the linting part of your CI ?
> The description is for others. Because there has to be a description, right? AI is so fucking good as sounding professional, that you relax and let it be. It’s not that I actually thought the code was good, but you get convinced over time, you get lazy, you become complacent. You stop questioning, and start accepting as good some code you would have never accepted, just because you cannot tell why it’s bad. You have lost control.
Just seems like a lot of issues here, so sure, dont use AI it's clearly not your thing. i do not let one line of code I dont think is "good" get committed, period
> Most AI developers will deny it, but deep inside, they know it’s true. Just don’t want to face it.
but dont assign my feelings. speak for yourself. I'm doing this shit for 40 years and you might find it gets a little tedious and repetitive after awhile
> Say no to drugs. Kind of a metaphor, but not quite.
it's a 100% totally wrong metaphor and it needs to die
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something
I'm sure the cash value of the advertisement here is worth more than a bug bounty would pay.
should we tell them how hacker news gets onto their computer?
I guess there's a whole suite of skills that allow LLM use to be more or less useful. (I dont actually "guess" this, I sort of am pretty sure of it at this point, so it makes me wince when people call for total AI blackouts in education...would be better if they were part of an overall media literacy curriculum since people are going to be exposed to these things whether they think they're little infallible people, or complex systems with lots of caveats)
So I guess this all goes into the familiar "LLMs allow people who are shitty at <X> to produce 10x the shitty output". this is a failure mode we're going to have to learn to mitigate
I'd still love to chew on some specific examples though.
I'd be curious to know specific examples of LLM-generated advice that goes against the advice of experts and does not consider tradeoffs. I've not had this experience myself.
If I did have this experience, someone spouting off obvious LLM points that contradict my expert opinion on something, I'd be headed right over to gemini/claude/whatever to see where that's coming from. Not any differently than if someone cited a google result that contradicted my own experience.