Comment on: Iowa et al asks OpenAI to keep their bots sandboxed
> If we are going to start punishing companies for security negligence, there are WAY worse casesPerhaps, but you have to start someplace.I think we do need to punish companies for security negligence. However the details matter (nobody can be perfect: you need to do something reasonable to stop the known attacks, but I have to agree to allow that you can't be perfect and so someone will get compromised). I'm not sure how to get the details right to cover everything without going too far. If we handwave that away though, eventually somebody will need to get punished for something that someon
Comment on: Iowa et al asks OpenAI to keep their bots sandboxed
So OP asked you for one example and you can't give one? You just fall back to the generic statement slop, you must be a bot right?Again, what's ONE (1) real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted.
Comment on: Iowa et al asks OpenAI to keep their bots sandboxed
> real world example of "SSN/PII" being illegally exposed that wasn't investigated or prosecuted"Investigated" is a weasel word here, since you can call anything investigated, and I'm not saying companies shouldn't be investigated. I'm saying we should focus on the biggest harms first.So I'll stick with what this thread is about - criminal prosecution. This gives us:1. Equifax - civil settlement, not prosecution. 147M people’s SSNs, DOBs, addresses.2. National Public Data - no settlement, prosecution, or compensation. Hundreds of millions of SSNs.3. First American Financial. Hundreds of milli
Comment on: Iowa et al asks OpenAI to keep their bots sandboxed
I'm not sure why you don't believe it? It's literally true?
I guess if you want to believe it, go study law? I'm not really sure what to say there.Negligence is not a crime, it's civil liability.Gross negligence (reckless disregard for human life) is often a crime, and often there are crimes related to it (reckless driving, etc). It also does not require intent to injure, so it could be committed by, say, an operator by operating an autonomous vehicle knowing it was unsafe and could harm people. So it usually requires knowledge but not specific intent. Again, crimes like this are state s
Comment on: Iowa-led states ask OpenAI to keep their bots on a leash
The problem is that law is reactive, and punishment entails the harm already happened. Some dumbass kid getting convicted for committing a cybercrime with AI doesn't do anything to get rid of the structural problems that enabled it. That conviction can only happen if the harm happened in the first place, and the problem is the harm itself. It's like trying to solve a mold problem by targeting a single fruiting body. You're not really doing anything.On top of that, it's not really any consolation if the advanced persistent threat gnawing at my ports lives in a different country either. That doe