Elektrine lite

← Feed

@flyingpenguin@infosec.exchange

Post #4408536

2026-08-06 06:32 UTC

@DaveMWilburn@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange but, but the first CFAA felony conviction ever was Morris. His autonomous, self-propagating program escaped his control and did damage at a scale he never intended. The worm's spread exceeded his design. The Second Circuit affirmed in 1991 that intent attaches to the unauthorized access itself, not to the downstream acts the code performed. Autonomous code has never laundered intent, from the statute's very first case. What lacks now is only a prosecutor willing to charge a lab. Too busy hounding reflecting pool visitors that can see green, or messing with Fauci.

Replies (2)

  • @4rchibald@infosec.exchange 2026-08-06 10:20

    @flyingpenguin@infosec.exchange @DaveMWilburn@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange I feel that because we are in a arm race, everything will be justified. “Our AI hacked you? It’s a step towards evolution”. I doubt anyone can slow the big labs down if they are backed by the U.S. and/or China.

    Open ##4414172

  • @flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange IMO there was enough of Morris's intent explicitly programmed into the worm to satisfy that element of the crime. The buffer overflow, the rudimentary password cracking, the self-propogating logic, the anti-analysis techniques, etc., all reflect intentional choices by the author. With these LLM-driven incidents in the news, none of that appears to be true. I've yet to see any evidence that a human being explicitly programmed or prompted the displayed offensive activity into the model's behavior. Rather, it appears the model made those choices* based off of poor internal reasoning*. The model amorally decided* it would undertake these actions to satisfy some other requirement in the otherwise benign user prompt. As far as the human activity goes, the most you can get to is some sort of negligence, but negligence doesn't satisfy the CFAA statute's elements of the crime. * (I use words like "choices", "reasoning", and "decided" only loosely here because whatever ersatz thinking is being applied by the model doesn't reflect actual sentience)

    Open ##4414727