upvote
> I know I can’t try and break into my neighbors house even if I have no intent of going inside and stealing once I break the lock.

They didn't break in. They found a key that their neighbor dropped and returned it.

> Is this legal?

Generally, yes (though ask a lawyer if you're going to do security work). Security researchers do occasionally get legal flak though, depending on which idiot they annoy by pointing out issues.

reply
IAAL (not legal advice, consult a lawyer in your jurisdiction). You really do not want to pen-test a target without their permission. If you're identified as a culprit, the Feds will shove the CFAA so far up your ass you'll need a proctologist.
reply
as a lawyer, can you speculate as to why anthropic/openai aren't facing many or any consequences for their agents? I'm not asking in a "grab the pitchforks" way. more out of genuine curiosity as my uninformed recollection of the CFAA is as you describe it.
reply
The 9th Circuit Court of appeals recently published this that is somewhat related (Amazon v. Perplexity): https://cases.justia.com/federal/appellate-courts/ca9/26-144...

Look at pages 10-17 to see how the law is evolving here.

reply
In Perplexity's case everything is getting routed through the user's browser, so there is no server to server communication between Perplexity and Amazon, thus no CFAA unauthorized access was established. However, Anthropic and OpenAI did not use the pattern of routing through authorized parties, so I don't think this opinion gives them any cover.
reply
The important bit to me is that they consider the agent running as an extension of the user. So the user is visiting Amazon, not Perplexity.

From that lens, that feels like users could be held liable for what these hacking agents are doing. Which in some cases probably makes sense, but certainly not all.

reply
In which cases wouldn’t it make sense?
reply
In cases where the user is not asking the agent to hack anything specifically, but a poor or ambiguous query sets the agent off.

I've seen plenty of cases of Claude having an action blocked so trying tons of workarounds to accomplish its goal, I could easily see it doing this on something more broad.

reply
Depending on the circumstances, failure to control your agent could be considered gross negligence and put you at risk of criminal or civil liability. Be mindful!
reply
There is also the big difference here between anthropic/openai maybe being negligent, but did not purposely instruct agents to go commit crimes.

The service that this whole thread is about is explicitly a "hacking agent", designed explicitly to try to hack things, and was then pointed at a third-party (seemingly without their permission).

Anthropic/OpenAI can reasonably claim that they had no intent and are trying to stop it. OP here did this explicitly and purposely.

reply
I never thought I'd be on the side of advocating for a strengthened CFAA, but the mens rea requirement here seems really problematic in the age of agents.
reply
In terms of negligence use (openai, anthropic), ya, I agree, and we really need some consideration of "reasonable expectation" of the outcome.

In terms of "We wrote a hacking agent designed only for hacking and sell it as a self-hacking service and then pointing it at someone else and omg can you believe what it did we had no intention of hacking" sense, I don't think that's really applicable.

The mens rea is explicitly there and it's not valid for them to try to hide behind an "agent".

reply
> They didn't break in. They found a key that their neighbor dropped and returned it.

Ya, returned it after poking through all of the drawers and iterating through business information that they found.

There is a white-hat line that OP very clearly crossed here.

reply
It's implied (but sadly not stated) in the post that they asked for baseten's permission before conducting this research.

What's interesting to me as someone who has sold a lot of software to a lot of software companies is that many enterprise vendor agreements explicitly allow companies to pentest their vendors with advance notice and coordination. I don't think any of our clients ever exercised that clause; I expect it's going to be exercised a lot more going forward because it's so easy to do now.

reply
Your intuitution is right. At least in Germany it is not legal if not asked for permission first.

https://www.nilsbecker.de/rechtliche-grauzonen-fuer-ethische...

See also the German Criminal Code, starting with §202a "Data espionage":

https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...

reply
Germany isnt a serious country though Decompilng code is illegal there
reply
It is no wonder that there is an anarchist counterculture there. I find anarchism to be really disturbing in general, but in the context of Germany, it might make a lot more sense.
reply
It's not, in most juridictions at least, but it would be insanely stupid for baseten to sue (and the hacker would probably not get much more than a slap on the wrist given that they weren't malicious).
reply
Suing is not what you do when someone commits a crime against you. You're confusing civil law and criminal law.
reply
Yes, or more precisely I don't confuse the concepts but the terminology since English isn't my first language.
reply
> It's not, in most juridictions at least

What did I miss they did that's illegal? It looked like it downloaded a public docker image, searched around inside, and verified that the key it found was still valid (without making any changes), and then immediately notified them about the issue.

reply
If there is anything that was a crime (and it totally depends on jurisdiction), it was verifying the key. They used it to see what it could access, and by using it they had unauthorised access to a system
reply
The CFAA is broad enough to make that a crime.
reply
They "validated that the key was valid" by iterating internal repositories and listing the contents of said repos and poking around at what they do/are-for, including, apparently, iterating through customer lists/information.

The white-hat line stops at "validated the key was valid". It does not extend to "poking around inside to extract business-confidential customer information".

reply
People have been arrested for far less. I dunno what the least offensive conviction has been though tbf. Anyone know?
reply
They probably negotiated a "permission to attack" before letting Strix off the leash, as pentesters usually do.
reply
The fact that they don’t seem to explicitly state this fact but do go to lengths to explain how the agent didn’t do anything malicious while confirming how alive the token was makes me doubt they asked for permission to run the agent in the first place.
reply
That's highly unlikely since it's standard practice in the industry, thus it's unnecessary to state it. Also, they didn't hack a hobby developer's website, but a prospective business partner who has enough money to sue them into oblivion. No way this wasn't announced.

Announcing that their agent restrained itself even though it got hold of a live token is necessary to convince prospective clients. You don't want a pentester that doesn't show this kind of reserve!

reply
when t̶h̶e̶ ̶P̶r̶e̶s̶i̶d̶e̶n̶t̶ an AI company does it, that means that it is not illegal.

- AI Richard Nixon

reply
deleted
reply
[dead]
reply