upvote
Knowingly exceeding authorized access of any computer used in interstate commerce is a felony in the US.

The title of TFA is a metaphorical criticism, not a literal law analysis.

They are not making the statement that the person in Australia who accidentally cancelled someone's reservation in Australia is literally guilty of violating US law. They are drawing criticism of AI models which are taking the kinds of actions for which, if a human did them knowingly, would be illegal.

reply
>An AI cancelling other people's gym classes is a felony? Don't computer systems fail all the time at holding reservations for people?

the difference is intent.

if a concierge/booking system makes a mistake (or has an unintended bug or whatever), no crime.

but if i (or an agent working on behalf of me) use an API in an obviously unintended way to revoke other people's reservations, that would fall under the computer fraud and abuse act (in the usa).

reply
>"the difference is

intent."

>"but if i (or an agent working on behalf of me) use an API in an obviously

unintended

way to revoke other people's reservations..."

?

reply
Double negative. An attacker using the API in an "obviously unintended" manner shows intent.
reply
i am not quite sure what your question is, as you simply quoted me and then put a question mark... i think you are confused that i used "intent" in one context, and "unintended" in a different context, is that right?

the first sentence: the difference is the intent of the person who caused the cancellations

the second sentence: but if i (or an agent working on behalf of me) abuse an API to do things it was not meant or designed to do, such as cancelling someone else's reservation

reply
Yeah if you're unlucky you get hit with like 20 years for wire fraud.
reply