Hacker Newsnew | past | comments | ask | show | jobs | submit | peter422's commentslogin

FWIW I don't think this is true. Intention matter a lot in US law. If you could prove the AI did something bad entirely on its own and you had nothing to do with it and had no reasonable belief it was possible, I think you'd be alright.

People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.


> and had no reasonable belief it was possible

The broad concept has been well-known for half a century at least, and the very specific concept for several years at least. It’s clear that they didn’t take reasonable precautions against it. And it’s not even the first time this sort of thing has happened, though it’s higher-profile and -impact than before.


Indeed, and because of that, I argue it's not just the crime of hacking, but crimes against humanity, due to endangering the existence of the species.

The concept of… hacking?

And yes this is absolutely the first time autonomous software has breached containment. What are you referring to? Perhaps just corporate cyber in general?


The concept of AI breaking out of a box or doing something unintended trying to achieve a goal. OpenAI should be found guilty of gross negligence of some sort, because this was not something that could not have been anticipated, and because their security precautions were laughable.

Because the AI itself is not a legal person, it must be OpenAI that's responsible for what it does.


Neuromancer came out in 1984, over 40 years ago, so that covers the broad concept. Or Neo in The Matrix: “Programs hacking programs… why?”

For non-fiction you could look at Nick Bostrom’s Superintelligence: Paths, Dangers, Strategies (2014).

More recently, see Cade Metz’s NYT profile of Geoffrey Hinton, “The Godfather of A.I. Leaves Google and Warns of Danger Ahead” (May 1, 2023).


> Intention matter a lot in US law.

Maybe (and historically, not with CFAA) - but they're still going to extradite you to a trial here to find out which is more than enough to ruin your life. The government is already looking for a great excuse to criminalize open source models.


Who was prosecuted under CFAA for something they did not intend to do?

Robert Morris, Lori Drew, probably a few others, depending on what you mean by their intent.

Intent is literally a requirement for conviction under CFAA. It's the first line of the law: "Whoever having knowingly accessed a computer without authorization or exceeding authorized access..."

Robert Morris very intentionally wrote a computer virus, released it into the wild to infect computers he didn't have permission to use, and tried to cover his tracks by making it look like it came from MIT instead of Cornell. The only accidental part was that the virus was too successful, and that he got caught.

Lori Drew intentionally violated MySpace's TOS (in the course of cyberbullying a child until she killed herself), and was acquitted because TOS violations don't rise to the level of a crime.


> The government is already looking for a great excuse to criminalize open source models.

Sounds interesting+scary. Do you have some source for this ?


Anthropic and Openai, but especially anthropic, are lobbying the us government to make it happen

The government or OpenAI and Anthrophic?

Because if you mean the Government, I think they frankly just care whoever is paying them to make an executive order or worse a law paid by corporations to not only block, but ideally also ANHILIATE ANY POTENTIAL COMPETITION.

It's the ultimatum against the small guys. Sold as "Anti-China", when in reality it's only purpose is total dependency to corporations by law.


The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me.

Do you guys really not comprehend the impact of giving every script kiddie an Astra-equivalent model to play with, this time without any guardrails whatsoever?

Cause I'm starting to think you aren't really thinking through the impact of power plants, hospitals, etc all being hacked en masse. People will die.

Or making it easy for anyone to make a virus (it's not hard, mechanically). Even more people will die.

Taking this to the extreme: You don't just give every kid a "do anything" super intelligent button. Open source models have a limited lifespan whether you like it or not, for the safety of all of us as a whole.


"Open source models have a limited lifespan whether you like it or not". this tinpot dictator mindset is typical of anthropic.

Who will decide how to use the power of ai...you?

it is no surprise that the companies and safety institutes who believe that they alone may 'tame' the fire, are the cause of safety incidents. a safety test caused the explosion at chernobyl.

anthropic and openai are the danger to society.

they are the ones making the dangerous models. they are the ones using tens of millions USD of inference, and thousands of agents, to hack computer systems.

i have trained zero dangerous models. i own zero servers that i use to run hacking agents. i could run one hacking agent with my single subscription.

there are some arrogant researchers remaining at anthropic who believe that they do care about safety. those who cared about safety at openai have left.

depending on how it goes, we might need some kind of earlier intervention by the US government to take control away from the current leadership of the ai companies and prevent further incidents.


Very easy to download abliterated GLM 5.3 and start doing bad things with it, and it'll be easier when Astra-level variants are available

Just because you don't do a bad thing doesn't mean other people won't. It's why you don't give everyone an RPG launcher.


"Very easy" if you ignore the hardware requirements, anyone could do it?

why should you have the RPG launcher and not me?

I think we're being trolled by solenoid0937. I call Poe's Law.

I’d rather that capability be wide spread and “democratized” than have all of humanity enslaved to the oligopoly holding control of the godhead.

The support of OSS models on HN just days after finding out about the message board incident is so bizarre to me.

Other sites beckon.


Yes, I'm aware that the HN majority is a hyper-libertarian echo chamber that loves to outsource the problem of "technology hurting regular people" if it means they get to keep their toys/investments.

After all, who cares if abliterated extremely intelligent OSS models result in actual innocent people dying? That's <insert group here> problem. We need to be able to generate our uncensored furry fanfics, goddamnit!


State actors, professional criminals will have same or better capabilities and do not hesitate to use them. On defense end we'll have only "pay bigcorp" option.

OSS models can help to fix infra especially for folks who would never do it themselves. We do not know yet what final effect would be and it doesn't seem sky is falling now or in near future.

"people dying and furry fanfics" is a scarecrow and distractor respectively, it would be awesome if more specific examples would be used in place.


> State actors, professional criminals will have same or better capabilities

State actors do but they are not unhinged enough to use this to cause massive loss of life, unlike random crazy people with access to a computer.

Professional criminals don't have access. Please explain exactly how you expect a professional criminal to get access to a non-safety-tuned Astra/Fable equivalent.

> OSS models can help to fix infra

You can work with the vendors of critical software to fix infra first, without giving every random crazy person access to something that creates cyber/bioweapons.

> "people dying and furry fanfics" is a scarecrow

You don't think people will die if OSS models make it easy to create a bioweapon, or make it easy to hack hospitals, infrastructure, and the like? Please explain your thinking.

It's very easy to order all of the raw material needed to create a virus, the challenge is in making a viable one. But models make this easy.

Same for cyber. Hospitals, emergency services, and infrastructure like power plants are not sufficiently hardened to withstand an attack from Fable-class models.


Criminals don't need Astra or Fable. Get a bunch of GPUs, a good enough open weight model and a custom harness. What the model doesn't have in its weights it can research the Internet. How do you think black hat hacking is being done right now?

On bio: while it's easy to order all the raw material, there's the whole process of culturing bacteria/viruses/etc. that isn't trivial, and while a LLM might help in explaining stuff for rookies, there needs to be somebody physically working on it. It's not automatic. Once you get to this level, you'll find that any undergrad biologist or chemist can already make bio/chem weapons, and you don't see it happening. Terrorist groups already employ biologists or chemists that are supporters of their cause, no need for LLMs.

On cyber: aside of the question of why critical infrastructure is on the Internet on the first place (ah yes, lowest bidders, people not caring enough, business not giving IT/OT budget, S in IoT standing for security etc), if the available models can't handle cyber tasks, how can you defend yourself? See the HF "attack" that HF had to use GLM-5.2 to investigate what happened. This is the best argument for open models. Unless of course, you are the AI model creator or somebody they authorized to use their sanctioned model/harness and want to create a moat for their business.

This is FUD. Creation of business moats by fear.


The risks of open models are real.

However, I’d feel better about ceding control of AI to the government if they didn’t seem so intent on building an apparatus for surveillance/control.

Your “furry fanfic” is a somewhat pathetic scarecrow; this is a complicated topic.


Is this "think of the children, think of the hospitals" argument? Really?

Meaningless phrase used to dismiss arguments, please engage with the actual argument.

I don't think you understand how bad it will be if anyone has a button that can hack anything, our infrastructure is not ready for this. Actual people will die. Do you just not get this?

Bioweapons as well. Do you not understand how easy it is to craft a virus at home? You can literally order everything you need online. Again, actual people will die.

You are arguing the equivalent of letting everyone own missile launchers or RPGs because "open source good."


If and I mean IF it will be a (A) "hack anything" button, it as well will be a (B) "find a vuln in my site" button too. And a (C) "harden my site" too. And limiting such buttons to a few corporations does not make any sense because script-kiddies will still have access to (A).

Did you know (C) is possible without causing mass chaos that results in many people dying? In ways that don't give every script kiddie access to (A, B)?

It turns out you can give defenders the opportunity to front-run, at least on the most critical and widely used infrastructure.

Same with bio risks.


No, that's an illusion, that's the thing. You can't physically have (C) without the (A). Large corporations will spend billions trying to convince the population it is somehow possible, but the reality is different.

You absolutely can have (C) without widespread (A), you just need to limit the audience that gets the tools, and in fact the big labs are already engaging in (C) in collaboration with the government and vendors of critical software.

That you don't have access to (C) to harden your blog is a non-issue from a societal perspective, hardening the software that our infrastructure relies on first is simply more important.


Limiting progress by letting only select corporations access the stuff is how you fall behind China, UAE and in a few years even Kazakhstan.

Whoever wants to have access to (A) will have it, but letting only few select corporations provide (C) will mean majority will be priced out of (C).

Are you a shill or something?


I very much doubt China is going to let their citizens freely use AI for hacking. In fact they keep a very tight leash on corporations and their employees.

So long as real logistics systems are isolated and secured what real risk to stable society is there?

Your use of the internet may lead you to greatly overestimate the number of people who take what they read online as real. More people than you think treat this shit, regardless of the website/forum, like Jerry Springer and Satuday Night Live; just entertainment.

The STEM crowd often overthinks the impact of violating their pet theory.

Can an LLM escape its computer entirely and stomp through a city center like a kaiju? Settle down.

You're veering towards thought policing over speculation.


Nothing unites the public behind restrictions like a good dose of fear. The "for the children" angle is a master key for regulation—always sold as protection from the big bad wolf.

"Trust us, we're here to protect you." Sure we are. /s

It's only a matter of time before open-source gets banned in the US under that same paternalistic security blanket. /s


Intention matters in the severity of charges and sentencing. Crime due to ignorance or negligence is still a crime.

Not remotely true. Mens rea is a necessary precondition to establish criminal culpability for tons of crimes. Well before sentencing is ever considered. The far opposite, ‘strict liability’, where you’re guilty of a crime purely due to some action or inaction (the actus reus) is exceedingly rare in the US justice system.

https://www.law.cornell.edu/wex/mens_rea


Baloney, lots of people go to jail for DUIs, and that's the right analogy here.

People don't drink and drive with the intention to kill people. They drink because it's fun and then get behind the wheel because it's easy and convenient, even though they know the dangers they convince themselves nothing that bad will happen.

AI companies are creating these dangerous, powerful models (that they keep telling us are dangerous and powerful), then they take off all the safety guards to run them in woefully inadequate "sandboxes". Pure negligence.


Drunk driving is an actus reus offense basically everywhere, so it's not analogous at all.

It's certainly analogous to the behavior exhibited by these AI companies in deliberately performing dangerous actions and then letting other innocent people deal with the consequences.

Virtually all criminal law accounts for the perpetrator's state of mind. Drunk driving is a specific, rare carveout. The reason for this should be obvious: it is nearly impossible to prove a drunk person's state of mind beyond a reasonable doubt, so we passed laws so you can't say "Your Honor, I was too drunk to be responsible for my drunk driving".

So, no, this is not at all analogous to a totally routine question of whether someone was negligent in how they deployed some software.


The first conviction of Computer Abuse and Fraud Act, for the Morris Worm, was for an unintentional malware. Or at least the unintentional scale

There is a lot of good analysis of the Appeals process on this specific point - the CFAA as written required unauthorized access:

Section 1030(a)(5)(A), covers anyone who

(5) intentionally accesses a Federal interest computer without authorization, and by means of one or more instances of such conduct alters, damages, or destroys information in any such Federal interest computer, or prevents authorized use of any such computer or information, and thereby

(A) causes loss to one or more others of a value aggregating $1,000 or more during any one year period; ... [emphasis added].

The District Court concluded that the intent requirement applied only to the accessing and not to the resulting damage. Judge Munson found recourse to legislative history unnecessary because he considered the statute clear and unambiguous. However, the Court observed that the legislative history supported its reading of section 1030(a)(5)(A).

I'm not sure how you could categorize the Morris Worm as lacking mens rea based on that statute..

https://scholar.google.com/scholar_case?case=551386241451639...


You think that Morris accidentally wrote the malware or that he accidentally released it (in a way specifically intended to obfuscate his connection to it)? lol

It seems to me that the law in the US is set up to only establish standards of negligence after a bunch of people die.

> People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.

What the Frontier labs have done is not this, however. Also, they know damn well what can happen and they still don't take the appropriate precautions. At this point it's very hard to believe it's not intentional for purposes of marketing.


Well that and you spend tens of thousands of dollars on lawyers to reinforce that point and make the prosecution rethink whether they will profit off of this case or not.

US law doesn't really give much of a crap about your intentions unless you can back it up with a wall of money to exclude yourself from the rules of the general population.


THere is intention

ie, I intended to steal money from you. Under common law stealing is "taking with intent to deprive". How thats determined is a bit harder.

But how can someone be "grossly negligent" if they didn't intend to cause an accident? well they either allowed a situation to happen, or didn't stop a situation happening that they could see was bad.

An example of this would be the igintion switch from GM that caused all those deaths. the engineer saw that it was shit, knew it didn't do what it was supposed to do, and half arsed the replacement to the point where it wasn't actually changed.

"We are going to test the cyber capabilities of this new model. Yeah it should be fine to have a package proxy. Hmm? whats that? isn't that a security issue? naaaa those proxies are secure."


Intention (mens rea) is not a get out of jail free card, it just changes the nature of the crime and charges you get convicted off.

If you run someone over on purpose you get convicted of murder. If You do it by driving recklessly you get convicted of culpable homicide.

The only time you get off with nothing is if it is determined to be an accident.

As they always say: ignorance of the law is no excuse. Running a dangerous machine prevents you from claiming you had no idea the machine was dangerous.


Especially if they kept telling us how dangerous the machine is.

But US law also has a concept of negligence. If you set up an AI to do this and didn't take reasonable steps to prevent it you could still be on the hook.

> Intention matter a lot in US law.

They hacked a competition company. The intention was implicit when there is economic gain to be had.

> People are not charged with hacking when their unsecured box is taken over by a botnet and does bad stuff.

Because it is a lose for that people. If the botnet left money in their pockets the situation would be totally different as there will be an incentive for them to let the botnet hack them.


> The intention was implicit when there is economic gain to be had.

Not how it works. Intent requires at least that you were deliberately doing the criminal act (sometimes also that you knew it was criminal, or at least that you had some reason to believe that it was wrong).


> Intent requires at least that you were deliberately doing the criminal act

So, they did something that benefits them by mistake. I would like to see a person would be judged in that situation. I can imagine that the bar to put someone in prison is way lower than to give a fine to a mega-corporation.


You can imagine what you like. I can imagine a million examples of people being judged not guilty because intent could not be proven beyond a reasonable doubt. There are of course many injustices in the 'justice' system, but I would prefer to discuss the concrete details instead of just vibes.

Here's one case: https://supreme.justia.com/cases/federal/us/342/246/ where someone who took some metal they believed to be abandoned was aquitted on that basis, though this particular case made it to the supreme court because the lower courts tried to rule that the fact that he didn't intend to steal them didn't matter.

Also, I don't think there's a strong argument that hacking huggingface did benefit them. If you could prove it was a deliberate ploy to market their models, then perhaps you could argue they expected to benefit. Otherwise, you could argue that it's negatively affected their reputation.


At the very least it would be reckless.

Intention of the AI?

Intent of the user.

Just say you wanted to make world better for humanity, you should be fine.

Funnily enough the legal system has dealt with people lying about their intentions before.

OpenAI is in trouble then, no?

If there's evidence they deliberately did this, yes. If they've lied in other cases then it might make their testimony that they didn't intend this less credible, but also OpenAI as a whole is not going to face criminal charges, so it'll also depend on the situation of whatever individuals do get charged, if it does go to court.

I’m sure we could come up with a better system than paying extreme amounts of money to detain in terrible conditions non-violent people who were following the rules that were previously given to them.

The vast majority of sitting Democratic senators voted against funding for Israel this year.

The DSCC funding is a drop in the bucket of the overall funding in these races, and they have their own goals which may or may not be aligned with the party as a whole.

If your single issue is Israel funding (which it probably shouldn’t be but that is your choice), the Democratic Party and presidents did far more to reign in Israel’s behavior than republicans.


I think parent's broader message was the Democratic party leadership being out of touch with potential Democratic voters.

Support for Israel's current government (elections in October 2026) being but one example.


You need to realize just how performative most votes in Congress are. The Democrats, for example, will vote for all sorts of progressive policies when they know they won't pass. For example, Kamala Harris was a co-sponsor on a Medicare for All Bill. She didn't run on that in 2024. What's the difference? Well if she won in 2024, she might have to deliver on it. In 2019, Trump was in the White House so there's zero chance it would pass.

Republicans do this too. Two of the seats they're at most risk of losing are Maine and Alaska held by Susan Collins and Lisa Murkowski (respectively). They currently have 53 votes (well, 52 with Mitch McConnell MIA). That means they can pass things with 50 votes (and JD Vance's tie break) on anything that can get past or doesn't require cloture (eg approving judicial nominations, reconcilation). So, every time you have a controversial nomination or bill, you'll often find Collins and Murkowski vote no because their votes aren't needed. The leadership is insulating them from attack. But when their votes are needed, they're there (eg Collins's required vote to confirm Brett Kavanaugh).

As for the number of Democratic senators who voted against weapons for Israel, it is significant because it never would've happened 5 years ago, but it's also mostly performative because there's no way it was going to pass.

As another example, Democrats did a rare move to invoke the filibuster last year to stop ICE funding. This resulted in a government shutdown and important programs being punitively defunded (eg there was a reserve fund for food stamps that was intentionally not tapped). What happened? The Republicans needed 60 votes to force a vote. There were 52 votes. 8 Democratic senators crossed the floor to vote with Republicans. That's so weird. It's the exact number required. What a coincidence. Whatever that number was, 1, 5, 8, 12, it doesn't matter. There will most of the time be that number of exact senators requried. This, by the way, is part of the rotating villain role within the Democratic Party.

This is how calculated it was. All 8 of those who crossed the floor were either retiring or they weren't up for re-election in 2026 so the voters couldn't punish them. John Ossoff, the current liberal darling, was going to be one of the 8 but he's facing re-election this year so Chuck Schumer whipped another vote to replace him.

Another classic example was the Epstein transparency act. Trump threatened members who signed the discharge petition. Mike Johnson actually shut down the House for 7 weeks to try and get those that did to change their vote. yet when the discharge petition got 218 votes (the minimum required), suddenly the votes in the House and Senate were almost unanimous. Well, if support was almost unanimous, why not just have a vote to begin with?

Mitch McConnell can really be credited with pioneering a new era of obstruction in the Senate. He realized there was a political cost to some votes. Some things were popular and he didn't want to pass them so he'd just make sure they never made it to the floor for a vote.

So my point is that imagine the Democrats control the House, the Senate and the White House in 2029 and that same Israel funding bill came up. Will all those Senators and House representatives vote for it when it might pass and become law? Nope.


I created a new account recently and the default homepage was all videos that were either (a) AI slop (b) sexual imagery (c) AI slop sexual imagery.

Really not what Twitter used to be about.

It is possible he's done a good job at the micro level, but at the macro level the platform is a cesspool.


> Really not what Twitter used to be about.

AI slop wasn't available then.


In theory I think the stock should be going up because his tenure has found Google getting left behind.


Fake it until you make it, baby!


A year ago AI wrote roughly 0% of my code and now it writes roughly 100%.

Which is to say any AI study from a year ago is fairly out of date with the speed of advancement.


> A year ago AI wrote roughly 0% of my code and now it writes roughly 100%.

Did the amount of money you or your employer make rise by anywhere near 100% as well?

Because that is really the primary question behind articles like this focusing on the economic benefits.


The study is two months old (March 13, 2026).

Edit: Also, it's about writing not coding and it's point isn't that time isn't saved but even with time saved at the task, you don't get a broad decrease in total worked time for many/most workers.


The study was published in May 2025, and then revised in March 2026. It's based on data through December 2024, so virtually useless for saying anything about today.

Given that, I actually think the conclusions of the article are backwards. If the gpt-4/gpt-4o era had a measurable 3% improvement in productivity, how much more improvement are we getting from models today that are way way better?


The study is "new", but the data they are using is old. It has references GPT-4 for god sake.


Right but it looks back well before that.


But that itself doesn't tell us yet how much time it saved you at the end of the day.


As a developer, on my very best days I probably spent no more than 50% of my day actually writing code. So call it 4 hours of actual hands-on-keyboard coding.

But AI can write code much faster than a human. In 4 hours it might be able to write what would have taken me a week. Or more. Assuming it had proper specifications for that volume of code.


Do you still review the code it writes?

Typically it takes me as long to review code as it takes me to write it myself. The exception is repetitive coding tasks that cause my attention to drift, which LLMs can do very quickly.


AI hasn't gotten better, you've just given in to the hype.


Sacks has said so many obviously false things in reference to government actions (Jan 6th, Ukraine, etc) that there is no reason to trust anything he says.

If the Trump administration wants him to say something, he says it. Maybe what he is saying is true, maybe it isn’t. There is no way to know.

The story they are telling is exactly the same whether it was true or they were just shaking down Anthropic for no reason.


I think this is oversimplifying things.

There are many different factions within the administration. Sacks was part of the "deregulate the tech sector" faction, which on this issue is aligned with the "beating China overrides anything" faction.

That's distinct from the Pete Hegseth faction (I don't really know how to characterize his faction other than anti-woke maybe?).

Sometimes these factions agree, sometimes they don't.

In general your approach is right - you can't trust most things coming out of this administration. But you can try to unpick was actually happened by who is saying what, when. That is useful even without liking the people.


> But you can try to unpick was actually happened by who is saying what, when

Indeed, this is very prevalent in investigative journalism as well. Everyone has biases, but it's understanding that and piecing together the various parts that brings the truth out.


> I don't really know how to characterize his faction other than anti-woke maybe?

the war crimes faction?


Anthropic just needs to donate millions of dollars to a “MAGA Inc” like Greg Brockman did and they’ll get regulated properly from now on.

It’s a perfectly good system for government regulation.


In some cases, even just bringing a 24K gold desk ornament to the WH is enough; but I suspect these tributes to Dear Leader are subject to inflation, possibly exponentially so.


$100 Million to The Trump Foundation, and Anthropic get to become the US AI Regulator


It looks like Greg needs to make another deposit to the fuhrer


[flagged]


Probably not personal bribery?


always important to compare things that are actively happening to things that didn’t


Or perhaps threaten to donate $10b to the DNC


That threat will probably result in a DOJ investigation into everyone involved until they hit something they think they can prosecute someone for, even if it's not true.


That makes sense

They could double down though, like actually follow through with just 1b and then threaten to do an extra 1b periodically until the investigations are dropped


I agree. I’m a social person but I also like my purely functional conversations with LLMs, and I have a lot of them going at once!

Doesn’t replace conversations with other people but at the same time I feel no tax talking to the LLMs.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: