Hacker Newsnew | past | comments | ask | show | jobs | submit | charonn0's commentslogin

No. "Intentionally", "willfully", or "knowingly" are prerequisite states of mind for crimes defined by the CFAA.

Good thing it’s an AI then so it can’t commit crimes by definition.

Liability would rest with the user, who presumably told GPT to solve ExploitBench make no mistakes, not to hack Huggingface, and thus would not have willfully or intentionally done anything.

The agent did it intentionally and willfully and knowingly. But you can’t sue the agent, I suppose. And the human didn’t ask the agent to do so.. so not a problem? Or the legislation needs an update?

Only the human did ask the agent to do so. That was the whole point of this exercise.

Did a human ask it to abuse vulnerabilities and escalate across external systems?

How long before an agent steals their human tester's nude photos and extorts them for the answer key?

It seems like bug hunting might be the one area where AI is actually making the world a better place.

There's also the weird scenario of a reporting bias where instead of admitting to a bunch of vulnerabilities, you can frame it as "look at how useful AI is".

We even have companies implementing solutions for ffmpeg vulnerabilities themselves instead of just handing them the vulns to fix themselves.

It's very possible the tide reverses if it's not in people's interest to advocate for AI anymore, so we better not get too used to it just in case.

It's nice that we currently have an alignment of AI advocacy and infosec, though. Maybe Microsoft can even point their AI to their questionable UX and UI practices next.


How many were introduced by misuse of AI coding/vibe coding though?

highly unlikely for many of them. SharePoint, bitlocker, Active directory, hyper-v, rdp, DHCP and MSMQ are all software/technologies that have decades of history and long pre-dated LLMs. seriously, do people not realise it was entirely possible to write insecure or bad code before LLMs?

It’s like people don’t remember the whole outsourcing trend and all the awful code that came from that.

Don't forget the damned interns!

Everyone but me!

Hey, I wrote slop at Microsoft way before it was cool.

> seriously, do people not realise it was entirely possible to write insecure or bad code before LLMs?

Some of these threads make me think every line of code written pre-LLMs was apparently perfect in all ways. Feels like romanticizing the past.


Sure, that's true.

It is also true that Copilot is currently in use developing Bitlocker and Sharepoint. So I wouldn't be confident saying it was one or the other.


Especially if they made heavy use of offshoring, which I would bet they did.

It's funny because SharePoint and AD are so god-forsakenly awful you would think they're vibe coded if you didn't know any better

For what it's worth, at my workplace AI has uncovered quite a few issues that have been there for a decade or two and survived countless rounds of careful reviews, external security analysis, pen testing and so forth for all those years.

Vibe-coded apps probably have loads, but mostly because they're using less capable models than the people who're doing the bug-hunting. Once vibe-coders are using models like Mythos too you should expect the number of bugs in vibe-coded apps to collapse quickly, because the LLM will write the bugs but will also fix them (assuming the system prompt tells it to.)

For some reasons, models are blind to their own output...

Not my experience.

I use Claude to build me a small web app I needed for ages, I'm using its superpowers to discuss/talk about architecture /brainstorm/build plans, and always a fresh context with the built plans.

A few times the plan implementer (subagent writing a code assigned to the task) found something lacking (more often it was test issue related to the code, not the actual flaw of the implementation plan), fixed it on the fly, or found something in the review (last step of each task). Also there's always a technical review for each "slice" (set of tasks), consisting of code review and e2e tests.

Only when it passes I do the fresh code review of the changes with the Opus or Fable again. Happens rarely rarely, but it did found a few issues.

Code works every time, I have yet to find the fault myself.

Of course there are issues and I need to read the output especially in the planning phase very carefully and yes, Opus disappointed me many times trying to weasel out from something it "agreed with me" (and entered into architecture + todos)...

Of course right after agreeing to use devcontainers it proceeded to attempt installing a handful of node modules in my os, so intended up running it in the bwrap (pain in the ass in itself).

But it works, it's fascinating, and I have the app I actually needed.

Not magical but useful.


Not my experience with my homie Claudius.

The code review agent usually has feedback to be resolved before committing, which includes bugs and unhandled edge cases. Sometimes the primary context is understandably embarrassed.

Sometimes it truly be your own people.


One reason seems obvious/intuitive: because their own output matches their own biases, that is, is a direct result of their model walks.

I think this could be true if you use a single Claude context, since it has its own reasoning in the context.

But a separate code review agent does much better, in my experience.


The distinction I'd draw is between AI-assisted and AI-generated. Using AI to write isolated functions you understand and review is different from prompting your way to a complete system you can't debug. The second case is where you get surprising failures at runtime that no amount of linting catches.

It is hard to tell, the code may genuinely be decent quality or not.

That is the issue with vibe coding. Increased output but reduced understanding. So if something does go wrong, one has to hope that there is still enough understanding to address it quickly.


Is it worse than what humans were doing on their own anyway?

Well yes if they expect to find and correct more bugs every update which is pretty much what they are saying.

If AI ever manages to make something half as atrocious as Windows XP that would probably be the first proof of AGI.

No, just more prolific.

3 or 4

How many were known, and put on the roadmap because war got hot?

At Microslop? Evidently, lots.

Depends. If the AI fixes don't introduce new bugs or unnecessary complexity (where bugs like to hide), then yes.

It was like a bunch of mythos scans through and through which then generated the reports for everyone to implement, not sure if in all orgs though. Mythos was great as it came from the top, i.e. a clear incentive. I think bug reporting otherwise does not reach the engineers unless an incident is raised by the customer care against a responsible team.

I am curious, they say we should expect a trend of more security patches every update.

It this is true and Microsoft devs are using agents it means that AI is doing a shitty job and is introducing more bugs/vulns per month than it fixes them. Otherwise you would have had a lot of bugs/vulns fixed in the first 2 security updates then a steady and significant reduction every month because any new code would have been scanned and fixed before release.


Bad guys can use AI too. Not sure about the net result.

If your ally is stealing trade secrets from your companies and spying on your politicians and journalists, is it really a good guy?

Sure there are _worse_ guys, but the supposed good ones aren't.


99.9% of people complaining about AI making the world a worse place would be fully happy with AI if they shared in the economic benefits of automation.

Not if it ends up deskilling society and taking away what brings us meaning in life.

I don't see why AI would deskill what you love to do. People still do embroidery even though mass manufacturing exists. If you love something you would continue doing it irrespective of automation.

For better or worse this round of "automation" will hit harder than most others because it comes for what makes you you. Your brain, not your body. The industrial revolution replaced your body, this one could in theory replace you entirely. And it isn't coming for some job, it comes for most. It's not just a hobby but being able to do the job. You are replacing 10000 types of jobs with 1 type: AI prompter. We'll probably have an AI just to help ask for the right thing.

You have transferred all the skills and knowledge to the AI. When the skills are gone, who's going to teach you to do any non-trivial job? What will give you any sense of accomplishment when all you do is ask the AI but have no capability yourself?

Even if you have a guaranteed income, because "your AI" is getting paid for the work, where will you be with close to 0 contribution to anything? Maybe we're overreacting and this will never be an issue. I know we shouldn't take cues from fiction to predict reality but it's hard not to picture a world with a combination of Idiocracy and Wall-e (or the famous "Paradise" Matrix) where we decay because the change is so fundamental that we aren't ready to adapt.


Yeah this round replaces both body and knowledge.

Basically what is left is internal politics and cross company dynamics until we get to the point where a company is self autonomous.


For a lot of people it’s not the job that is rewarding it the role having a job gives them in life and home life. Financially contributing to the household through earning it through work is a meaningful and rewarding thing that can define the near total of how good you feel about yourself thing even if you don’t like the job?

But do people make a living doing embroidery by hand? Or is it more of a hobby?

Yes. I love eating pieces of string. I'm partial to wool myself, really filling.

I suppose you're a cake enjoyer, miss Marie Antoinette?


The bonuses SK Hynix staff are getting might vindicate that point of view. Of course, that's from AI investment, not revenue itself. They are the extremely successful shovel manufacturers, who for once have managed to leverage their power collectively as employees to benefit from a one-off like this.

Perhaps it has always been the case that people would be happy if they shared the benefits, but that is not how the world run by billionaires works.


I've been benefitting from automation my entire life. I don't see why anything would change when that automation is driven by language models.

for your first couple of B you stop complaining about anything

"People complaining slavery makes the world a worse place would be fully happy if they were slave owners"

Probably, but just proves people can ignore bad things when they benefit them.

Not what it pretends to prove, that the thing isn't bad.


> Count Binface

I did not expect this to be a real person. Is he with the Standing At The Back Dressed Stupidly And Looking Stupid party?


Hilariously, no.

That would be the Monster Raving Loony party who will apparently also be standing in this by-election. Count Binface has ruled out a pact with them.


I was very disappointed to hear that the Monster Raving Loony party is deciding to stand and split the vote.

I thought this was an opportunity for them to be tactical, but no.

(this is a joke)


But if Count Binface convinces them to tactically withdraw, that would be a Loony–Bin pact

Binface's speculation to the media is that the Monster Raving Loony party may split the vote with Farage instead as that is closer to where his loyalties lie.

This is funny :) True, as well...

Their policies are obviously not compatible, I just don't see how that could work out for either party. Sure you could get more votes that way, but the honourable thing to do is to run seperately.

The "More" button changes to a "Stop" button when clicked.


And run the whole thing in DOSBox.


Seems like a case for HTTP 451 (Unavailable for Legal Reasons) rather than 404.


HTTP 666 (We're evil) seems more fitting here.


The company involved here is apparently based in Washington, DC, which has a "Ban the Box" ordinance that limits employment background checks for most kinds of jobs. And apparently DC's version of the law is particularly strict.


The prevents them from asking before extending an offer, but it seems they could (and should) have checked after.[0]

> However, an employer may ask about criminal conviction(s) after extending a conditional offer of employment (the employer can never ask about arrests or criminal acusations that aren't pending). An employer who properly asks about a criminal conviction can only withdraw the offer or take adverse action against the applicant for a legitimate business reason that is reasonable under the six factors* listed in the Act.

One of the six factors is "Fitness or ability of the person to perform one or more job duties or responsibilities given the offense"[1], which they probably could have invoked after asking (though they never checked or didn't check thoroughly enough, so I guess it's moot).

[0]https://ohr.dc.gov/page/returning-citizens-and-employment

[1]https://ohr.dc.gov/sites/default/files/dc/sites/ohr/publicat...


Shouldn't this force companies that need to pass a SOC2 out of the district? Doesn't SOC2 require background investigation of personnel with access to sensitive systems?


I would blame the email over Outlook.



I clicked a link in your first one and it generated https://halupedia.com/guild-of-amateurs

I feel seen :pokerface:


They all work for me now, maybe it was getting hugged to death?


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: