> This is a problem because “SI” is also a classification marking.
They can just make up another name to redefine this classification which people are already used to. How about SIBISI? This follows the transformation they instituted a'la kilobyte -> kibibyte.
Not a lawyer but I think training a model with hacking skills they explicitly prevent the public from accessing without doing anything to stop the model itself from using those demonstrates intent.
what you described is negligence. unless you can prove that openai specifically targeted huggingface and specifically instructed their model to hack huggingface, it would not be intent.
anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa's requirements.
it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid.
Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder. There is a line between intent and negligence that puts acts over the line to intent if intentional acts led to a harmful incident.
I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products. Squeeze one disgruntled employee or another.
>Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder.
i am unaware of any case where someone was convicted of first degree murder from a drunk driving accident. my searches came up empty as well. are you able to pull one up?
>I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products.
to successfully prosecute a cfaa case, you would have to prove that openai employees intended to hack specifically into huggingface. not that they wanted a PR boost.
i dont get why everyone's got a hard on for prosecuting this as a cfaa case. skip the cfaa case, go for gross or willful negligence + damages. it'll be significantly easier to hold openai accountable that way.
Anthropic's policies are literally the supply chain risk.
The DoD could have used the same authority to seize the technology if it wanted to. Especially in a time of war. DoD has instead chosen to respect Antrhopic's boundaries and has simply barred anyone in the agency from buying a product that comes with strings attached.
This is 100% on Anthropic for product:market fit failure.
Am I misunderstanding this entire ordeal, or are Anthropic's policies not precisely what the DOD agreed to in its initial contract with Anthropic? Did the DOD not then seek to change the contract terms, to which Anthropic refused?
If I sell the DOD a service with contracted terms X/Y/Z, the DOD agrees, then later asks me to drop Z, and I refuse, how would that warrant the legal definition of a supply chain risk? How is the appropriate response for the DOD not to simply find another service provider?
The DoW tried to change a contract they had signed. Anthropic refused. That doesn't make them a supply chain risk (the wording of which implies "likely to sabotage" the government).
Do you think OpenAI's terms for the DoD are published on a website? Pretty sure when Anthropic got zapped, OpenAI sent DoD a memo 500ms later saying they wouldn't restrict use.
Look at it pragmatically. What does the DoD use every single procurement for? Hint: military use.
reply