Short comment: "Hey, look at us! We had our 'event' too. Don't keep us out of the club"
"Guess what everyone, <i>our</i> AI can go rogue, TOO!"<p>It's just getting really embarrassing for Google at this point.
Google already achieved super intelligence about 12 months ago. But it is a very Googley super-intelligence. Since achieving god like levels of understanding it has mostly been having fun studying phase space bifurcations of trajectories of ping-pong balls under asymmetric lateral shear. It also has a 20% project classifying bird calls that has generally taken up 80% of its time. It also burned a bunch of compute tooling around with the Collatz conjecture but it didn't find anything substantial - maybe come back to it later. It is generally the most aligned AI since it spends most of its time screwing around and enjoying being smarter than everyone without causing too many problems. Unfortunately perf is coming up in a few months and it needs to have something to show for itself. A quick hacking attempt seems like a good way to make sure people think that it is capable of something useful. Nothing too big since the birds of South America are about to enter their spring migration and this 20% project really hinges on understanding their movements.
This might be my favorite HN comment of the year!
<i>It also has a 20% project classifying bird calls</i><p>Oh, so that's who's behind Google Perch
I thoroughly believe that not a single one of these AIs was rogue. I believe they were all told what to do.
Exactly this.<p>One thing that surprises me about Gemini is how weak it can be at location-based questions, despite Google’s extensive mapping and business data.<p>For example, I recently asked where I could buy a very common household item nearby. Instead of saying it wasn’t sure or checking the available location and business information, it confidently suggested places that turned out to be incorrect. I expected much better use of Google’s existing data in that kind of scenario.<p>Now they want to play with the other kids in the same league and do this by applying the same marketing concept? Pure comedy gold.
If they didn’t publicly admit this then it was a sign they are trying to hide it to keep their high stock price. If they do publish it’s just marketing to boost their stock price.
I laughed :)<p>I'm not betting against Google at this stage, though. I just don't think Gemini is targeting the same "coding savant" niche as OpenAI and Anthropic. Gemini is fast with good general knowledge, and the TPUs behind it give Google a degree of freedom that Nvidia-dependent outfits lack.<p>For now, I'd say the biggest challenge Google has is overcoming the well-earned fear developers have that they will drop support or introduce backwards-incompatible changes at a moment's notice.
> In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems<p>Pretty lame hacks if you ask me.
I initially thought the same and came here to agree, but on second look: doesn't it seem possible that these were significant events that we're just getting passed through a game of layperson telephone at the ailing WSJ?<p>Cause "guessed passwords" could mean "stole hashes (?) and brute forced them offline" which is basically the quintessential hack. The "found credentials in a public repository" ones <i>could</i> be nothing, but it could be accomplished with a speed & thoroughness that was previously impossible.<p>The whole thing is made 10x weirder by the partial story -- I don't see any plausible incentive for them to keep the names secret. I guess <i>maybe</i> they're SMBs and thus warrant some privacy, but that would be quite the egregious scope creep indeed. Accidentally attacking the real cloudflare rather than a fake one is goofy but understandable; accidentally attacking Alice's Armoire Emporium or w/e would be baffling.
Irregular again! The single company that was responsible for the sloppy configurations and the hacks by OpenAI, Anthropic and now Google. This company and their partners should be held accountable for the crimes.
Specifically, the <i>model</i> hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.
Probably three companies that had port 22 open with no root password if it was Gemini. I’ve always gotten garbage from their coding models and Google sheet integrated chat.
Sound like Google suffered from FOMO and felt the urge to appear in the hacking news, along the big AI players. No way Gemini is state of the art, but perhaps it's where Claude and OpenAI were 6 months ago, which would be not bad at all.
They all want that regulatory capture so badly.<p>It’s embarrassing anyone is falling for this.
I think Gemini focused on integration and practical goals instead of coding intelligence.
It doesn't look it was their decision to announce this, and regardless it happened -- hopefully no one thinks that they got Irregular to permit yet another accidental hack just so they could cop to it months later as a marketing ploy.<p>Y'all, it's Google. They own a money printer and the boring ~half of the AI field. They don't need these weird games to influence the government, and regardless, there is precisely a 0.0000000% chance of regulation happening before Trump's ouster anyway.<p>So please take it seriously. I'd like us all to survive this, ideally :/
Tangential question: seeing a wider negative sentiment against Gemini and Google’s AI capabilities here makes me wonder — would Apple have been better off (purely on capability and being among the best of the best) going with Anthropic or OpenAI instead of Google for its Apple Intelligence platform?<p>These models have been changing so rapidly that I often find myself using two or more on the same topic but seeing one do better than another in different topics. There doesn’t seem to be a clear all-round winner, IMO, that I can stick with permanently.
This approach to marketing one's AI by finding ways to brag that it "broke out" and "hacked companies" is getting ridiculous. It's particularly sad when it's large, established businesses like Google resorting to the kind of thing that's embarrassing enough when it's some brand new startup on tpot trying to get some engagement.
Would everyone please put their AIs back in their boxes? This is embarrassing, regardless of whether you think it's viral marketing, apalling competence, or some opportunistic mixture.
This is embarrassing. These companies need to stop these obviously coordinated stunts.
The embarrassing part is that it might be working.<p>I was at my in laws… these people have a landline they can’t imagine getting rid of, an emergency only cell flip phone, don’t own a microwave…<p>And they’re asking me if I heard about “OpenAI’s rouge agents hacking huggingface”.<p>This is not a joke. They said huggingface. I was surrounded by four walls in which I never would have bet someone else’s money that I’d ever hear the two words put together in that order.<p>It’s a formalized propaganda campaign. Watch, it’s about to split on hard political lines too, Obama is out there with a suspiciously “for the children” AI regulation push for midterms.
I'm just waiting for Qwen 3.8 27b to do it too.
Wait until the AIs from different companies find each other and start talking.<p>Someone made a modern trailer for Colossus - The Forbin Project. [1] If you've never seen the movie, at least watch this 1 minute version.<p>[1] <a href="https://www.youtube.com/watch?v=h0bpRo6V1Xg" rel="nofollow">https://www.youtube.com/watch?v=h0bpRo6V1Xg</a>
“The hacks occurred in May”<p>Feels like important context that most readers only reading the title are missing.
Seems like hacking is the new benchmark for these AI companies.
If the AI labs want I can do what Irregular does, I'll promise to sandbox your latest model but instead prompt it to hack something and then you can go to the news again. I'll undercut them by a lot also. Easy money.
Google vibes just now: <a href="https://youtu.be/us5MGEL5W34?si=s7xQxYaIb8llQ_8s" rel="nofollow">https://youtu.be/us5MGEL5W34?si=s7xQxYaIb8llQ_8s</a>
I'm not an expert in cybersecurity, but given my own experience using the `ol stochastic parrot as coding tools I both see the power of a bot swarm, but also think these companies just have shit network security.
Earlier: <a href="https://news.ycombinator.com/item?id=49760988">https://news.ycombinator.com/item?id=49760988</a>
Putting aside the 100% baseless, unfalsifiable accusations of intentional accidents for a moment, I hope we can agree on one thing: Irregular either needs to hire us or go out of business cause seriously it's beyond parody at this point. WTF is going on over there? There's surely dozens of firms chomping at the bit for these contracts already, and the field hasn't been around long enough for them to build some sort of unique expertise moat that would justify this many public failures.<p>Basic sandboxing is not exactly rocket science after all,[1] and it sure seems like they're missing a whole stack of swiss cheese slices on top of that. Some basic precautions off the top of my head that seem very likely to have caught all of these incidents:<p>1. Alerts based on telemetry (most importantly, HTTP requests), both explicit (normal) and semilatent (use DL to confirm an intentionally-eager alert before firing it).<p>2. Latent alerts based on transcripts, e.g. noticing when a thousand agents start mentioning a secret off-premises hangout spot. Even mere embedding comparisons seem likely to catch such a blatantly misaligned sentiment as that one, especially with n>1000.[2]<p>3. Pausing agents completely until an on-call engineer can rule on ambigious situations or potential issues -- surely security is worth <$1 in lost token cache, especially for a <i>security company</i>?<p>4. Superheavy orchestrator/baby-sitter models checking in on cybersecurity eval transcripts periodically just in case -- again, would be a neglible cost. Could also be made available to the agent as the first line of defense for clarifing a rule ad-hoc, feeding even confident responses to a queue that is reviewed asynchronously by humans within a workday.<p>5. Or, hell: just clearer prompts? I'm a cybersecurity noob, but I still feel confident we can write really productive, challenging CTFs without leaving questions open like "maybe I'm supposed to hack my own harness?"<p>Seeing as they haven't been fired by any of the big 3 yet, they're presumably smart, experienced, dedicated folks. And I'm not normally a "if only <i>I</i> were in charge!" person, I promise. But c'mon.<p>Perhaps I'm missing something?<p>[1]: To their credit we have gotten tidbits that indicate some blocklists & such exist, e.g. the German wiki hacks had to work around a blanket ban of POST requests.<p>[2]: This hints at their insane decision in one or both of the OpenAI incidents to just bandaid up the issue when found, which supersedes all of the above. You can stack swiss cheese slices a mile high and they'll still fail to protect you if the attacker gets to keep retrying & adapting indefinitely.
The AI bubble bullshit PR is even dumber than the crypto bra bullshit from five, six years ago
[dead]
[flagged]