@DaveMWilburn@infosec.exchange
Post #4414727
2026-08-06 10:45 UTC
@flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange
IMO there was enough of Morris's intent explicitly programmed into the worm to satisfy that element of the crime. The buffer overflow, the rudimentary password cracking, the self-propogating logic, the anti-analysis techniques, etc., all reflect intentional choices by the author.
With these LLM-driven incidents in the news, none of that appears to be true. I've yet to see any evidence that a human being explicitly programmed or prompted the displayed offensive activity into the model's behavior. Rather, it appears the model made those choices* based off of poor internal reasoning*. The model amorally decided* it would undertake these actions to satisfy some other requirement in the otherwise benign user prompt. As far as the human activity goes, the most you can get to is some sort of negligence, but negligence doesn't satisfy the CFAA statute's elements of the crime.
* (I use words like "choices", "reasoning", and "decided" only loosely here because whatever ersatz thinking is being applied by the model doesn't reflect actual sentience)
Replies (1)
-
@flyingpenguin@infosec.exchange 2026-08-06 10:59
@DaveMWilburn@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange interesting. Morris specified offense in C, while the labs specified it in their precise test configuration. The worm made runtime choices too like which hosts, which exploit... and every one was attributed back to the man who launched it. Authoring the code rather than the config is a difference but it doesn't move the attribution. Intrusion tasks chosen as the benchmark, safeguards deliberately switched off, internet egress provisioned.