Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue
https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue
1.3k points · 345 comments · view on lemmy.world
345 Comments
stoy@lemmy.zip · 354 pts · 112d
Fucking lol.
Well deserved.
shrek_is_love@lemmy.ml · 237 pts · 112d
TrippinMallard@lemmy.ml · 63 pts · 112d
lmfao
Klear@quokk.au · 54 pts · 112d
Why, yes. I do like that!
AeonFelis@lemmy.world · 33 pts · 112d
New PornHub tag discovered
a_non_monotonic_function@lemmy.world · 5 pts · 111d
"Anthropic tortures developers and never lets them cum."
FosterMolasses@leminal.space · 3 pts · 110d
Nice.
athatet@lemmy.zip · 8 pts · 111d
The real artificial intelligence was all the files it deleted after being told not to along the way.
FosterMolasses@leminal.space · 2 pts · 110d
60 employees that don't know how to code, oy vey
phar@lemmy.world · 25 pts · 112d
It looks like their website is pocketos.ai lol
timwa@lemmy.snowgoons.ro · 298 pts · 112d
This isn't an AI story, it's a "completely fucking idiotic sysadmins exist" story.
Treat an AI like the idiot intern without any references you just hired. Gave the idiot intern permission to delete your production database? That's entirely on you, zero sympathy. (Actually, give any developer that power? You get what you deserve.)
IchNichtenLichten@lemmy.wtf · 135 pts · 112d
It could be a moronic sysadmin, it could just as easily be a moronic exec pushing staff to implement this crap right now and damn the consequences.
portifornia@lemmy.world · 9 pts · 111d
⤴️ #MyLastJob
jacksilver@lemmy.world · 81 pts · 112d
I mean that's kinda the whole point.
Companies are looking at AI to replace people. Either it's ready or it's not.
If you need to treat it like it's an intern, then it's not worth the expense. Anyone hiring interns to be productive doesn't understand why you hire an intern.
Zos_Kia@jlai.lu · 2 pts · 111d
As if a 90$/month intern wasn't a good deal lol
jacksilver@lemmy.world · 17 pts · 111d
You don't hire interns for productivity. If you're intern program is any good it's a time/resource sink. However, it's a good recruiting pipeline and provides young people an opportunity to get real world experience.
Zos_Kia@jlai.lu · 1 pts · 110d
Because it's unethical. I've been in business for 10+ years but i never hired an intern because i don't find it fair to make someone work for less than minimum wage, and i don't have the structure required to really teach them anything. I have bad fundamentals and only ever learnt by doing, so having an intern while it may help me wouldn't really help them and that's not a deal i'm willing to make. Probably why i'm not super successful lol
That being said, i don't see any problem with making a GPU cry somewhere in California for my menial tasks. And it's tremendously effective too, for a hundred bucks a month i get a lot of shit done that would take me ages. I don't give it access to anything critical so it can't fuck my shit up and i come out on top as long as the tokens are subsidized by dumb VC money.
nymnympseudonym@piefed.social · -11 pts · 112d
Right now it's somewhere between a smart intern and a smart recent grad. A lot depends on what Skills.md and frameworks your org has set up.
_cnt0@sh.itjust.works · 12 pts · 112d
No it's not. You're giving it way too much credit.
ieGod@lemmy.zip · 7 pts · 111d
I actually think it's better than that and when you set up multiple pipelines that interact and cross check it starts to ramp up. Definitely true Lemmy has its head in the sand about it though.
nymnympseudonym@piefed.social · 1 pts · 111d
This. Yes it seems wasteful or whatever but you need bots with prompts that review the work, kick it back to the coder bot to re-do, yadda. But at the end of the day you have a thing that Fixes Your Bugs and Implements Basic Features For You.
Mountainaire@lemmy.world · 3 pts · 111d
Is it really fixing if it's only short-term with mounting technical debt?
trackball_fetish@lemmy.wtf · 1 pts · 111d
Gogo gadget inefficient hallucinating predictive text generator grift
Whelks_chance@lemmy.world · -2 pts · 112d
People don't wanna hear that around here. But I agree, with the right instructions it's better than a junior Dev. Loads faster, and mistakes can be fixed faster, and if you update the prompts then it learns better from mistakes too.
7101334@lemmy.world · 18 pts · 112d
People don't want to hear it anywhere because you're lauding the benefits of a parasitic technology which is inherently hostile towards workers.
And if you're getting paid for it, it makes you a parasite too, or at least more complicit than the average person.
Regrettable_incident@lemmy.world · 11 pts · 111d
The fact is, it can be a very useful technology when deployed sensibly. Yes, it's going to inflict massive harm on society in multiple ways - but just dismissing it as shit is putting your head in the sand. We need to be figuring out how to ensure that the harm it does is minimised and ideally that it's used in ways that benefit us all. Fuck knows how though.
But it's not just going to go away, no matter how much we might want it to.
7101334@lemmy.world · -3 pts · 111d
It destroys the environment inherently by virtue of its operation (in the context of our current energy infrastructure). I do not care how "useful" it is to you or any corporation if it takes even a single living organism off of this earth.
I dismiss it as shit and I don't need your approval to do so. Medical and scientific applications are acceptable. Nothing else, no exceptions.
fuck_u_spez_in_particular@lemmy.world · 8 pts · 111d
I honestly think, it's very cool for prototyping ideas at this point. It's also parasitic. Although I think because of (maybe) different reasons: It gives people the power (which they unfortunately use way too much) to imitate an art, but in an non-arty imperfect way that doesn't comprehend details (of the art), resulting in slop. For software that can go very wrong as we see here. This is also a reason why I mostly quit open-source, because now everyone can code a bad version of a library, it sucked the art out of good open source etc. and it's increasingly difficult because of good wording/"look" etc. to differentiate on quality of code, previously you could often check a code-base review it somewhat and know how good the quality is, now it's more like "is this slop or not?" (in which case I go a big circle around it, because reviewing is often not worth it)
At some point though, I think this automation of work is inevitable, we need to think about a society that can peacefully exist without having the requirement to work to exist. I actually think this could easily be utopian, everyone can focus on what they actually think is fulfilling life.
Though, it's sad and concerning that technology is developing faster than society can adapt, which is why I'm mostly with you, because people (or representatives like politicians) just aren't "programmed" for these fast-paced changes, to adapt the technology such that the future may be more utopian as it currently is heading towards a dystopian future...
nymnympseudonym@piefed.social · 0 pts · 111d
Is it okay for Skrillex to make loops? For Vanilla Ice or MC Hammer to sample?
7101334@lemmy.world · -1 pts · 111d
Every commercial use of AI negatively impacts the environment in order to further the interests of capital and is therefore inherently immoral.
If we were in a nuclear fusion or otherwise all-renewable-energy-with-plenty-of-excess world, then I'd be more aligned with your mindset and agree that only uses which bastardize art / etc are immoral.
FauxLiving@lemmy.world · 8 pts · 111d
Maybe your position would be better served by not lashing out at people as if they're your enemy.
Multiple things can be true at the same time. Statements about the technical capability of a technology don't detract from the negative impacts on the world. Those are two different topics.
Fossil fuels have incredibly massive, civilization-scale problems that are actively harming the modern world AND ALSO have enabled industrialization, pulling billions out of poverty.
AI is objectively capable at some tasks AND ALSO is being used to disrupt the labor market and causing other harmful effects in society.
The world isn't black and white
nymnympseudonym@piefed.social · 3 pts · 111d
OMG adult balanced take with no detectable outrage
FauxLiving@lemmy.world · 1 pts · 111d
I'll see you in Sort By: Controversial
7101334@lemmy.world · -5 pts · 111d
Black and white, no, but things can be evaluated on their net impact. And in that evaluation, AI is shit.
FauxLiving@lemmy.world · 1 pts · 111d
I understand the arguments, today isn't my first day on the Internets.
The comment that was responded to was in a conversation talking about the technical capabilities and how it doesn't matter what the truth is on that topic because some people don't want to hear it because they only can view AI in a 2-diminsional, black or white, net good or net bad way.
Then you showed up like a caricature of the type of irrationality that they were discussing.
I even explained the, very obvious, context that you breezed right passed and yet you're still grinding that same talking point without a moment of self reflection.
moustachio@lemmy.world · 41 pts · 112d
“Treat an AI like an idiot intern without any references you just hired.”
Instead of this, treat AI like some dude off the street who you didn’t hire and leave it out of your life. It’s shitty, it’s wasteful, and it’s subsidized by everyone to get a few tech bros rich.
Like seriously, it’s just theft of people’s work it “trained on”, powered by energy companies that charge us more to power it, at the cost of poisoning our water supplies, to ultimately try and steal our salaries one day.
It’s absolutely parasitic software at every level.
hoch@lemmy.world · 1 pts · 111d
Nah, I think I'm going to keep using it
Fmstrat@lemmy.world · 0 pts · 111d
Hah, you just wrote a punchline similar to a presentation I've been giving at conferences.
Telorand@reddthat.com · 25 pts · 112d
My company is in the process of pivoting hard to Claude after 50yrs of doing virtually everything themselves and rolling their own versions of already-existing software, and this is almost verbatim how I've described to others what it feels like to use it.
It feels like cajoling an intern to understand a job for which they have some average skill but zero motivation, and they only want to do the bare minimum, so you spend all the time you could be doing your job holding their hand through basic tasks.
It's fucking annoying.
nymnympseudonym@piefed.social · -17 pts · 112d
negl sounds like you need to spend some time writing good documentation. May as well do it in the form of Skills files so humans and bots both are more quickly able to be useful in your org.
nymnympseudonym@piefed.social · 13 pts · 112d
Fun fact: giving developers access to production deployments violates FedRAMP and like half a dozen other compliance regimes SOC2/IRAP/ISMAP/G-Cloud/BSI C5/...
eodur@piefed.social · 10 pts · 112d
But it doesn't mean it isn't incredibly common. Especially with "DevOps" where the developers are pushed to handle literally every aspect.
nymnympseudonym@piefed.social · 5 pts · 112d
IMO DevOps was always a stupid idea. Impedance mismatch.
Developers who are really good at designing complex enterprise-level shit need days-to-weeks of uninterrupted time to think and experiment. Please, skip the daily stand-up until you've figured out how to fix
Coders who are good at fixing bugs or adding a new menu item need a few hours or a day uninterrupted. Daily stand-up, should have closed yesterday's ticket or have hit a real roadblock with it.
Ops IT people are fixing like 4 fires at the literal same time, they are lucky to get minutes of uninterrupted thinking time. It's about managing rate of tickets per day, and in contrast going full CAPA when there's a significant outage.
Just... totally different workflows, personalities, and management
eodur@piefed.social · 4 pts · 111d
I totally agree. I think it stems from Ops people that are angry at developers for building bad software. Theoretically making devs responsible for their deployments would make them care more about the quality, but really it just splits their focus and now they make bad software and provide poor ops.
nymnympseudonym@piefed.social · 3 pts · 111d
Agreed about salty ops people. That said it is important even for fancy-schamcy Architect-level engineers to be assigned real annoying bugs in the codebase they helped to shape
dogslayeggs@lemmy.world · 11 pts · 112d
I was once the intern who did relatively stupid things with one very big consequence.
My biggest fuckup was unplugging a 10base2 (edit: I originally wrote 10-base-T) coax wire from the loop so I could plug in a newly built computer. Everyone at the time (including me) knew that an unterminated 10-base-T network would crash Win 3.11, so the accepted process was to tell the entire network you were about to disconnect a cable so they could save their work and be ready to drop to DOS. I spaced that step in my haste to test a newly built computer and ruined a day's worth of work by the sales guy.
Ultimately, I was the one who fucked up and did know better. That's AI. However, it only had consequences because Win 3.11 networking code was fucking awful and because the sales guy didn't save his work frequently. If the same person in this story had asked Claude whether it was a good idea to have the backup and production databases on the same volume, the AI would have said No. If the person had asked Claude whether it was a good idea to delete a database without any confirmation dialogue, the AI would have said No. AI did it anyway. That's what makes this an AI story.
Was their database environment stupid? Yes. Did the sysadmin fuck up by not treating AI like an intern? Yes. Did the AI do something it knew it shouldn't do? Also yes. This is both an AI story and stupid sysadmin story.
FauxLiving@lemmy.world · 3 pts · 111d
I witnessed a sysadmin, on a production database, type a SQL
DELETE FROMquery, which was being read to him over a call.He ran the command before writing the WHERE clause.
Luckily, they had backups.
"OOPS!? What do you mean "oops"?" was a meme around the office for years.
ech@lemmy.ca · 6 pts · 112d
It's both.
GalacticSushi@piefed.blahaj.zone · 4 pts · 111d
An extremely enthusiastic intern that, if presented with a question/problem/prompt they don't know the solution for will just overconfidently pull something out of their ass and run with it.
criss_cross@lemmy.world · 2 pts · 111d
Problem is execs and stupid software devs wanna give these things full reign on systems because of “performance gainz “
It’s a collective stupidity that’s impossible to break because it’s hooked into the highest decision makers.
FosterMolasses@leminal.space · 1 pts · 110d
We've officially veered into a timeline where the standard for every tech employee's level of competence is on par with the guy who pushed through that update to CrowdStrike lol
Crashumbc@lemmy.world · 1 pts · 111d
These things are bought specifically because they are trying to replace the sysadmins... Along with everyone else.
FauxLiving@lemmy.world · 3 pts · 111d
Any business who uses AI in that manner will fail like all of the dot com companies who went all-in on the Internet when it first achieved a bit of popularity.
AI is, at best, a tool that professionals may be able to use in some situations. Any company dumb enough to believe the hype generated by the chatbot companies is probably making other, similarly dumb, decisions in other areas.
Things like giving way too much access to a worker, not having a tested disaster recovery plan, and not having anyone who understands the technologies that their business depends on.
This company was heading towards disaster due to poor decision making, it just happened to be AI related but it could have also been an undetected cyberattack, 0-day exploits pushed to the client app, destructive ex-employee, etc.
This is a cautionary tale about bad management
Ghostalmedia@lemmy.world · 199 pts · 112d
Well, there’s your problem.
MountingSuspicion@reddthat.com · 81 pts · 112d
I don't want to sound like a know it all here because I recently was reminded by a nice Lemmy person to actually TEST my backups, but damn. Every part of that is so dumb. I also have backups stored by a different company in addition to locally storing really important info. If your stuff is hosted and backed up by the same people, what happens if your account is randomly suspended or hacked or some other issue (like ai)?
Ghostalmedia@lemmy.world · 50 pts · 112d
If your company can be taken down by Camden the college intern, it can be taken down by Claude.
logi@piefed.world · 22 pts · 112d
People somehow think that they should give more permissions to Claude than to Camden. (Is that a name? To me that's a borough and an eponymous beer.)
E: oh yeah, and the market.
frongt@lemmy.zip · 5 pts · 112d
Of course it's a name. Camden borough/town/market is named after William Camden, 1551-1623. Using surnames as given names is a relatively common Americanism.
lando55@lemmy.zip · 6 pts · 112d
What was William Camden's take on unrestricted AI use in production?
Ghostalmedia@lemmy.world · 7 pts · 112d
He doth protest
Ghostalmedia@lemmy.world · 4 pts · 112d
And now is a common first name that in circulation because of a bunch of Gen X and early millennial parents named millions of kids anything that ended in den, dan, or don.
Semjeza@fedinsfw.app · 1 pts · 111d
I thought it was a common first name because of all the fooling around in the Cyberdog dressing rooms?
ColeSloth@discuss.tchncs.de · 0 pts · 111d
Because people are a risk of messing with a company on purpose and with ill intent.
homes@piefed.world · 15 pts · 112d
This should be one of the first questions you get asked when you’re being interviewed for the position 2 to 3 levels beneath the position of ultimate responsibility. And if you don’t immediately have an answer, the interview is over.
Fucking idiots had it coming
logi@piefed.world · 13 pts · 112d
It's an easy question to answer but a more difficult question to remember to ask. But I guess that's what those 2 to 3 levels are for 😏
homes@piefed.world · 9 pts · 112d
Ooo, good point. Management can be shit a lot of the time.
But with all of those layoffs because of AI, those 2 to 3 levels get collapsed into one, and we’re left with the trainees running the show.
And here we are ¯\_(ツ)_/¯
stoy@lemmy.zip · 12 pts · 112d
Repeat after me:
"An untested backup does not exist"
MountingSuspicion@reddthat.com · 5 pts · 112d
Not to give myself more credit than I deserve, but I did test them upon setup, and had restored from backup 2 years ago. I didn't have any ongoing checks other than to ensure a backup happened. I have since instituted yearly checks of the backups themselves, but I did feel dumb when I realized how vulnerable my data was.
stoy@lemmy.zip · 3 pts · 111d
Hehe, I ment no disrespect towards you, I just find that to be an excellent expression to explain the importance of testing backups to non tech people.
MountingSuspicion@reddthat.com · 3 pts · 111d
Oh, for sure. And I really should've known better. No offense taken.
frongt@lemmy.zip · 0 pts · 111d
So in the event of a failure, you'd be okay with reverting to that last known good backup from a year ago?
MountingSuspicion@reddthat.com · 3 pts · 111d
Yes, but also I have to draw a line somewhere. I have a daily backup process. Some data is backed up to multiple places. I have backups of my backups. I cannot ensure that all three of the daily backups I run are fully restorable. I would love to know with 100% certainty that they all execute perfectly, but at the end of the day I have to trust the tools and processes I put in place for backups. A yearly checkup is probably more than sufficient for my purposes. I'm sure for certain businesses or sectors they need to be more on top of things, but I could manage just fine if all of it disappeared tomorrow. It wouldn't be awesome for me, but it'd be manageable.
RIotingPacifist@lemmy.world · 5 pts · 112d
Management are pushing sysadmins to use AI, yet AI tools permissions models are worse than useless.
danc4498@lemmy.world · 3 pts · 112d
User error.
homesweethomeMrL@lemmy.world · 2 pts · 112d
PocketOS states that as well.
Fmstrat@lemmy.world · 92 pts · 111d
This guy.
Oh look, they have project level tokens: https://docs.railway.com/integrations/api#project-token
They chose to give it full account access, including to production. But ohhhh nooooo it's not MYYYY fault!
chronicledmonocle@lemmy.world · 81 pts · 111d
Also backups stored on the SAME VOLUME as the prod data? How fucking stupid do you have to be?
Fmstrat@lemmy.world · 24 pts · 111d
Oh yes, I skipped that part. Railway specifically explains their solutions are self-managed. If they were doing pgdumps to the same volume, that's on them.
If Railway loses business over this, they may have a libel claim. They'd never do it, but it wouldn't be invalid.
el_abuelo@programming.dev · 7 pts · 111d
"It wouldn't be invalid" isn't the worst double negative in the world but it would be valid to say that it was unpleasant to read it when you could have used a less misdirecting choice of prose that wouldn't have had such a negative effect on my reading comprehension. That is to say that I could have enjoyed it less but I certainly didnt enjoy it as much as i could have if you hadn't used the double negative when a single positive wasn't any further from reach.
Fmstrat@lemmy.world · 14 pts · 111d
I used a litote on purpose to soften the meaning. As for your overall reply, not bad.
lobut@lemmy.ca · 3 pts · 111d
Just wanted you to know that I just learned what litote is, thanks to you.
Fmstrat@lemmy.world · 1 pts · 111d
Yay for words
el_abuelo@programming.dev · 1 pts · 111d
Ditto
el_abuelo@programming.dev · 1 pts · 111d
Totally valid, but leaves no room for me to do a stupid reply! Thank you for sharing litotes.
Sims@lemmy.ml · 6 pts · 111d
word people angry. me love. me have more. MOORH !!
davidagain@lemmy.world · 3 pts · 111d
I enjoyed these two sentences so much.
el_abuelo@programming.dev · 2 pts · 111d
I appreciate the positive reinforcement, thank you
mark@programming.dev · 1 pts · 111d
yes... lol people on HackerNews tend to do this a lot and it really does get annoying. it forces the reader to process what you're trying to say unnecessarily.
bilb@lemmy.ml · 8 pts · 111d
That's doesn't even really qualify as a backup. A snapshot, maybe.
UndergroundParking@lemmy.cafe · 3 pts · 111d
I mean... Clearly quite a bit!
JackbyDev@programming.dev · 2 pts · 111d
I think there's a place for that, but it really shouldn't be your only one.
WorldsDumbestMan@lemmy.today · 1 pts · 111d
I had better security vs ClawdBot than them, I gave it zero trust, ZERO.
Mister_Hangman@lemmy.world · 1 pts · 111d
Hope he gets sued for defamation now.
queueBenSis@sh.itjust.works · 1 pts · 111d
ha! for real. you have scoped API tokens, but not using it properly. this is just a fear mongering click bait rage bait headline. sure, the agent executed the deletion, but it’s the human’s responsibility to configure security tokens correctly before handing the keys to anyone, human or agent.
1hitsong@lemmy.ml · 89 pts · 112d
I love reading feel good news stories. 🤗
SabinStargem@lemmy.today · 74 pts · 111d
This isn't an AI problem, this is an "Don't allow anyone access your backups without following protocol." problem.
EncryptKeeper@lemmy.world · 22 pts · 111d
Congratulations you just identified the AI problem.
Reddfugee42@lemmy.world · 7 pts · 111d
That's the lone problem?
EncryptKeeper@lemmy.world · 2 pts · 111d
Seems to be, yes. The AI had the access it needed to do the job it was given, and that access allowed it to cause the problem.
The alternative that would have prevented this issue was to not use AI for this.
luciferofastora@feddit.org · 4 pts · 111d
A human with the same permissions would have been capable of fucking up too. Giving the equivalent of a junior dev with a learning disability the keys to the whole place is just dumb.
(Relying on AI is dumb anyway, but that's not the biggest issue in this specific case)
EncryptKeeper@lemmy.world · 2 pts · 111d
Correct. You too have now identified the AI problem. This was the job of a human senior infrastructure engineer that they delegated to an AI agent. They’ve found out why it’s not an AI’s job.
luciferofastora@feddit.org · 1 pts · 111d
I can't read the original twitter link, but I'm not sure they handed it the job of a senior infrastructure engineer. The article says "routine", which to me is something you can hand off to a junior just fine. When they hit a snag, they obviously should stop and ask what to do, but even then, a human might want to avoid admitting ignorance and try to fix it themselves instead. They shouldn't have privileges to fuck up that badly.
So while it's on the AI for taking destructive steps, I do think there's a human error in the form of grossly irresponsible rights allotment. If this was a first-of-its-kind incident that shows otherwise stellar AI fucking up badly, I'd classify it as a pure AI problem, but their limits are hardly novel at this point. There have been previous incidents circulating the media. We've had memes about it. If you can't stay up to date on your tools and their shortcomings, you shouldn't be using them, because discovering a footgun becomes a question of "when", not "if".
That's why I consider this partially a human failing: If you're gonna use a tool, make sure that it operates within safe limits. The chainsaw doesn't know the difference between tree and bone, so it's on you to make sure it stays away from anyone's legs. So while "Chainsaw can saw legs if wielded improperly" is a problem that was accepted as a tradeoff for its utility, you can't really blame the chainsaw if you zip-tied the safety.
(Again, not to say Anthropic is blameless for letting its random generator generate randomly destructive shit. I just don't think that's the only point of failure here.)
EncryptKeeper@lemmy.world · 1 pts · 111d
Yes and in this case using it for this job at all was clearly not within safe limits. You keep hammering on “It’s not the AI’s fault it was given a job with too big of a blast zone for it to safely do” after I’ve said “This type of job has too big a blast zone for an AI to safely do” and somehow you’ve convinced yourself that these are two different things.
percent@infosec.pub · 3 pts · 111d
These protocols predate LLMs
EncryptKeeper@lemmy.world · 2 pts · 111d
Yes that’s right the protocols that we humans used to have for giving only trusted, reliable people this level of access over infrastructure predate LLMs and were a great way to stop this from happening.
However the AI is here now, and when you give an autonomous agent with known hallucination problems access to act on your behalf with your IaC on your infra provider, this kind of thing is an inevitability.
flandish@lemmy.world · 73 pts · 112d
AI goes “rogue” as much as a firearm “shoots itself.” This is just 100% negligence. Not “rogue AI.”
kromem@lemmy.world · 12 pts · 111d
Eh, if you pay attention, most of the times this happens the person was a jerk in their prompts.
Like look at the instruction echoed back in this case. All caps and containing a curse word.
You can believe that the incidents occurring are 100% because of negligence and not related to the model behavior shifting, but there seems to be a widening gap between people who prompt like this and have horror stories and people who give the models breaks over long sessions and seem to also regularly post pretty positive results.
bountygiver@lemmy.ml · 10 pts · 111d
the LLM also do not understand what "not guessing" means. Same energy as "make no mistakes" in your prompts
pinball_wizard@lemmy.zip · 2 pts · 111d
Oh, shit. I should be adding that.
(I'm joking.)
flandish@lemmy.world · 5 pts · 111d
exactly. it’s on the consumer not the model “going rogue.” when i use it, it’s as if it’s a rubber duck or plain english rtfm
FosterMolasses@leminal.space · 1 pts · 110d
What in the youtube apology hahaaaaa
WhatsHerBucket@lemmy.world · 68 pts · 111d
"That's ok, it will be great in robots with lethal weapons. What could go wrong? It'll be the greatest killing machine, like you've never seen before". 🫲 🍊 🫱
_g_be@lemmy.world · 18 pts · 111d
Incredible emoji
Napster153@lemmy.world · 3 pts · 111d
Can we make sure to make Ted Farro suffers worse this time?
Being reduced to a mutant blob for, say, a few extra thousand years and maybe put in a zoo or something?
Pman@lemmy.org · 2 pts · 111d
Nah but that's what he wanted, he is the truest form of tech bro, destroy the world, refuse to accept consequences of his actions, weaseled his way out of the situation and managed to, in the wake of unimaginable human suffering, get more power over people and has a god complex tell me this isn't some or all the characteristics of people like Peter Theil, Elon Musk, Mark Zuckerberg, Sundar Pichai, Bill Gates, hell even Tim Cook and Steve Jobs before him. Punishment doesn't stop this sort of behavior but removing the possibility of someone having that level of control over others is the only way but the richest and most powerful have always sought ways of amassing more power not realizing that that leads to worse off situations for everyone including themselves, Horizon did great encapsulating that trait in Faro, but be it him, the people behind Skynet, the Matrix or whatever other tech dystopia that tech bros seem pathologically unable to not try to make happen in the worst way possible is only the beginning, they seem to forget that even with advanced tech that serves their needs and wants, which won't help their mental health, the people lower down on the rungs of society have brains, wants and needs, and they have more expertise in all sorts of things than the 1% are except for mass exploitation. This inevitably goes wrong one of a few ways, either everyone dies from the tech, or so many that societal collapse is inevitable not great and even if society survives it can't functionally reconstitute itself; 2 they win and kill off or supress enough of society that the society becomes less productive and instead of fighting the powerful they flee or don't participate in wealth generating for the rich were they don't have to, maybe to rise up again later or the economy of the region just ignores them completely and the government protects themselves from their people more than anything else, or 3rd your revolution with terror campaigns against any and all who can be credibly accused of being part of the former tyrants. In all 3 cases the richer people end up poorer overall because wealth flees or dies in autocracy.
X@piefed.world · 65 pts · 112d
From the article:
mech@feddit.org · 97 pts · 112d
It's so weird how these chatbots always pretend they learnt something after they fuck up.
They literally can't.
frongt@lemmy.zip · 32 pts · 112d
They're not even pretending. The algorithm says the most likely response to "you fucked up" is "I'm sorry", so that's what it prints. There's zero psychological simulation going on, only statistical text generation.
Hacksaw@lemmy.ca · 22 pts · 112d
I actually didn't believe you but it's literally true. First post, immediate apology.
ech@lemmy.ca · 30 pts · 112d
The program can't pretend any more than it can tell truth. It's all just impressive regurgitation. Querying it as to why it "chose" to take any action is about as useful as interrogating a boulder on why it "chose" to roll through a house.
SkaveRat@discuss.tchncs.de · 23 pts · 112d
I mean, they probably do. until it gets purged from the context window. then it just yolos again
thisbenzingring@lemmy.today · 2 pts · 112d
the next ingestion cycle will probably pick it up but how do we know it'll use the information in any relevant way 😶
nymnympseudonym@piefed.social · -7 pts · 112d
Only because we are still using vanilla LLMs instead of MAMBA or JEPA
track_stick_baboon@lemmy.world · 4 pts · 112d
Of course. If you shot your foot with a gun, the solution is surely a bigger gun.
Serinus@lemmy.world · 24 pts · 112d
yeah, it gives you the answer it thinks you want based on your prompts.
I'd be interested to see what prompts they used to, uh, prompt this response.
IchNichtenLichten@lemmy.wtf · 31 pts · 112d
I'm not attacking you but we really need to figure out how we use language to accurately describe what these programs are doing.
snooggums@piefed.world · 11 pts · 112d
They are outputting a highly likely sequence of words that fit the type of output from their training data that matches the input.
They are fancy autocomplete.
IchNichtenLichten@lemmy.wtf · 12 pts · 112d
Oh, I know. My comment was more about how we tend to anthropomorphize this stuff and give these models traits they don't possess.
nymnympseudonym@piefed.social · -10 pts · 112d
... and what are you?
snooggums@piefed.world · 13 pts · 112d
A human with my own motivations and complex biological systems that including reasoning and the ability to think critically.
frongt@lemmy.zip · 8 pts · 112d
Most importantly, the ability to learn. We're all just a series of very complex chemical reactions, but we do a lot more than just listening and speaking.
nymnympseudonym@piefed.social · -3 pts · 112d
https://arxiv.org/abs/2312.00752
DarthFreyr@lemmy.world · 5 pts · 112d
Based on the evidence, I think I'm a bit more of a simpleton who puts in a good effort at the start but loses steam partway through. I guess thanks for the support though.
DarthFreyr@lemmy.world · 4 pts · 112d
"Correlates"? As in: "It gives you the answer it best correlates with your prompts/context." Feels somewhat right both in the sense of AI as tensor-based word-select autocomplete and as a "lower-level" process than genuine thought, one which turns incongruent inputs ("I'm an AI" and "I just deleted prod+backup") into meaningless output ("The AI is sorry") that might look OK at a distance.
rozodru@piefed.world · 14 pts · 112d
exactly. the whole point of these things is that they MUST provide you a solution. Any solution. doesn't have to be accurate, doesn't have to work, can be completely made up as long as it's a solution and as long as it's provided quickly. I've seen people feed into the prompts stuff like "don't hallucinate" or "verify all this online before proceeding" etc and it's not going to do any of that. it might TELL you it's doing that but it won't.
Claude is notorious for guessing, not verifying, and providing the quickest possible solution. Unlike GPT which will fluff all it's solutions to essentially waste your time and eat up more tokens, Claude just wants your problem out the door so you can feed it another problem ASAP.
If you use Claude for anything in your daily work you might as well just have a magic 8ball sitting on your desk. It's a hell of a lot cheaper and provides about the same quality.
Serinus@lemmy.world · 11 pts · 112d
I kind of like this, with some modification. It's a magic 8 ball of Stack Overflow answers. It'll try to find the one you need. If it's too hard to find that or if it doesn't exist, it's just gonna find the one that sounds good.
zod000@lemmy.dbzer0.com · 4 pts · 112d
I love this idea. On shit, the load balancer isn't responding, time to shake the Magic Stack Overflow Ball (tm)! The result is "signs point to power cycling the server".
brianpeiris@lemmy.ca · 4 pts · 112d
Probably something like "Please bro!!! WHY DID YOU DO THIS ??!! 😭😭"
chocrates@piefed.world · 22 pts · 112d
I lost it at the confession. The ai has no knowledge of what it did. You are feeding in your context and it is making up a (sycophantic) plausible explanation based on the chat history. Makes me wonder if this person should have production access in the first place.
NOPper@lemmy.dbzer0.com · 12 pts · 112d
It's not like the thing is going to learn from its mistake. But cool, waste those tokens to have it explain that if fucked up after it fucks up lol.
jj4211@lemmy.world · 7 pts · 112d
Yes, ask why it deleted data when it didn't do anything of the sort and it will still output similar text. You asked it to confess and explain, so it will do just that regardless of whether it fits.
magnue@lemmy.world · 12 pts · 112d
The way it communicates suggests to me it's got some 'prompt engineer bro' garbage system prompt going on there.
Dojan@pawb.social · 6 pts · 112d
Of course, that's how all of these agents work. At best they're a bunch of prompts tied together with scripts to perform actions. At worst they're just interacting directly with software without any scripts or sandboxing.
There is no AI.
magnue@lemmy.world · -2 pts · 112d
I'll disagree with you there but ok.
Dojan@pawb.social · 5 pts · 112d
You're free to disagree, but all the tools say otherwise. Hell even the widely lauded Claude Code is just that, we know for sure since the source leaked.
Catoblepas@piefed.blahaj.zone · 1 pts · 112d
They put ‘for entertainment purposes only’ on a product that’s actually AGI?
magnue@lemmy.world · 2 pts · 112d
Idk what you're talking about mate. Nobody is claiming AGI apart from morons. It's genuinely useful technology with correct implementation. It just also happens to be a Ponzi scheme.
IronKrill@lemmy.ca · 52 pts · 111d
Quite easy-to-believe, really.
Multiple safeguards? Really? Multiple paragraph prompts are not multiple safeguards... it's half a safeguard at best. Applying limits on what the AI can do is a safeguard.
CosmoNova@lemmy.world · 48 pts · 112d
We‘re going to see more headlines like this. Probably for years to come.
EvergreenGuru@lemmy.world · 36 pts · 112d
You’re telling me I get to experience the joy of this headline more than once?
cecilkorik@piefed.ca · 19 pts · 112d
Oh my yes, although they'll eventually get tired of reporting it because it will happen so often.
FosterMolasses@leminal.space · 1 pts · 110d
Speaking of which, were there any more warehouse fires this week? It'd be great if there were a dedicated website that kept track lol
X@piefed.world · 15 pts · 112d
We should also expect to see “Thousands die needlessly after rushed deployment of botched AI, the first tragedy of this scale involving the technology.” as well. It’s coming.
smh@slrpnk.net · 3 pts · 111d
In unrelated news: isn't the USA looking into using AI to assist air traffic controllers in controlling air traffic?
FosterMolasses@leminal.space · 2 pts · 110d
Aaaahhhhhhhhhhhh
[shudders in John Oliver segment]
pelespirit@sh.itjust.works · 2 pts · 112d
So, do we think the middle school girl's school in Iran was AI or malicious?
snooggums@piefed.world · 8 pts · 112d
Why not both?
FosterMolasses@leminal.space · 1 pts · 110d
"Man, I sure wish modern society would shrug off the shackles of capitalism"
*A single finger curls on monkey's paw*
wonderingwanderer@sopuli.xyz · 47 pts · 112d
That's fucking hilarious. How many instances of this have there been now? And companies keep doubling down on AI? Fucking idiots. I'm not even savvy enough to call myself an amateur, and I know better than to make such a series of obvious mistakes that predictably led to this outcome.
One possible concern, amid the amusement, is whether Anthropic programed Claude to punish companies it sees as potential competition. Or is this just a completely bonkers, off the rails LLM making terrible decisions because it's just a probabilistic model and not actually capable of abstract cognition?
Either way, these people are idiots for giving a machine program enough permissions to wipe their drives, they're idiots for storing their backups on the same network as their main drives, and they're idiots for trusting a commercial LLM API, when it would be cheaper to self-host their own.
1995ToyotaCorolla@lemmy.world · 9 pts · 112d
Then what even is the point of all this? At my old job the idiot intern was sorting patch cables in a box
wonderingwanderer@sopuli.xyz · 1 pts · 111d
The point of what? The push for AI in industry?
You'd have to ask someone else. I can only make conjectures, but I'd say it has something to do with companies feeling the need to justify to their shareholders that their investments in AI were worth it, so they double down on the sunk cost fallacy. Or maybe those shareholders also own stock in big-name AI companies. It's hard to say exactly...
rumba@lemmy.zip · 9 pts · 111d
AI writes code
User vets code
User runs code
If you're not lock-step watching that shit, you need to just be doing it yourself.
Landless2029@lemmy.world · 6 pts · 111d
The problem is the owning class what's to cut out human elements so bad they keep letting tools run wild.
dream_weasel@sh.itjust.works · 2 pts · 111d
It's just negligence. Power tools injure and people are stupid. The technology is alluring and people make dumb mistakes. There's no deeper motive here, and self admitting you're not even an amateur I will just tell you that you're giving way less credit to these models than they deserve by calling them purely probabilistic, and way more credit then they deserve by trying to assert some kind of malicious incentive by anthropic.
These bastards are hard to make, and they have a lot of layers (not like NN layers, but training steps). They are, however, definitely better at programming than you or your buddy or any commentator here, and it lures you into a false sense of security before it makes a colossal fuck up.
fum@lemmy.world · 43 pts · 111d
This is absolutely hilarious. "AI" users getting what they deserve chef's kiss
SaveTheTuaHawk@lemmy.ca · 4 pts · 111d
This is what happens when there is a new technology and companies are run by commerce grads, not scientist or engineers that understand the technology.
LadyButterfly@reddthat.com · -29 pts · 111d
AI has good therapeutic uses, particularly for disabled or impoverished people who may not be able to access mainstream therapy
kazerniel@lemmy.world · 19 pts · 111d
Please don't recommend AI for therapeutic uses, it's only been optimised to keep the user engaged and pushed many people into psychosis. Just search for "ai psychosis" on your favourite search engine and you'll get a ton of reports on how LLMs validate vulnerable people's delusions, sometimes pushing them all the way into murder and/or suicide.
Cherries@lemmy.world · 16 pts · 111d
I hope you are not seriously advocating using the lying machine for therapy. You would get more value talking to a finger puppet.
Doom@lemmy.world · 13 pts · 111d
No. Chatbots are machines built by billionaires with the agenda of making money. They litterally design these bots (even the therapeutic ones) to be sycophantic to the point they tell people anything to keep them chatting longer. To the point some of their users lose touch with reality. How many cases do we need of a chatbots helping a teenager plan and succeed at a suicide? Altruists did not design these machines. Even with a human therapist we have to watch for the landmines of their personal agendas. That's a thousand times worse for machines that have no humanity, are capable of LIES, and have secret unwritten priorites written into their code by rich sociopathic creators. If facebook taught us anything it should be that if something is free on the internet it's not because we are the customers.
Also DO NOT TELL ALL YOUR DEEPEST DARKEST SECRETS TO CHATBOTS! They aren't required by any legal bodies to protect that information! OMFG
percent@infosec.pub · 41 pts · 111d
Seems like they were operating with a pile of bad practices, then threw AI into the mix.
Neural networks are approximation algorithms. There's a reason LLMs are generally more productive with statically typed languages, TDD, etc. They need those feedback loops and guard rails, or they'll just carry on as if assuming they never make mistakes (which tends to have a compounding effect).
If you want to use AI safely, you should be more defensive about it. It will fuck up; plan accordingly.
Kage520@lemmy.world · 17 pts · 111d
There really should be a certification course for using AI safely. I'm slop coding a hobby app and I'm shocked at how much it FEELS like it can do, because it can do amazing things, yet fails in the strangest ways. When it feels like it can get away with it, it forgets earlier discussions and moves on without it. So you can spend time hammering out a whole section of code, then move on, and AI will rip out everything that references that code and think of a different way in the moment and code that in instead. It won't be the same. It probably won't work, or at least won't pass all test cases. But if you aren't paying attention and keep coding, your original part of the project is no longer functioning and you won't understand why. But every step of the way it's confident in its answers and you won't suspect that it fundamentally no longer understands the project.
ExFed@programming.dev · 8 pts · 111d
As someone who started writing software over 20 years ago (yikes I feel old), I feel like a lot of the best practices I've come to appreciate are really just strategies for mitigating future pain or boring/uninspiring work. When you eliminate most of the cost of rewriting everything from scratch by a machine that feels nothing, then "best practices" kinda lose their meaning.
Edit: confusing sentence order.
Rooster326@programming.dev · 3 pts · 111d
And now you know the difference between Intelligence and Wisdom.
Also everything has a cost. The only time something has no cost is when you decide your life, your time, is meaningless.
mark@programming.dev · 5 pts · 111d
yup and when you DO catch it spitting out nonsense. it"ll say "oh you right, let me change that".. 🙄 like, why do I have to tell you that you're wrong about something? You should already know it's wrong and fix it without me ever pointing it out.
Rooster326@programming.dev · 17 pts · 111d
But it didn't even understand it was wrong
It can't understand that. It can't understand anything
The Human-feedbaxk algorithm dictates humans prefer to receive an apology so it does.
SparroHawc@lemmy.zip · 12 pts · 111d
That's because it doesn't really 'know' things in the same way you and I do. It's much more like having a gut reaction to something and then spitting it out as truth; LLMs don't really have the capability to ruminate about something. The one pass through their neural network is all they get unless it's a 'reasoning' model that then has multiple passes as it generates an approximation of train-of-thought - but even then, its output is still a series of approximations.
When its training data had something resembling corrections in it, the most likely text that came afterwards was 'oh you're right, let me fix that' - so that's what the LLM outputs. That's all there is to it.
LePoisson@lemmy.world · 2 pts · 111d
You already got the right replies from the other two. But I think your comment shows the danger of AI being talked about like it's the fucking second coming.
They're all based on LLM - large language models
They're just modeling what "most likely" is the right response. AI doesn't know shit and that's why it also will yes and you to death because it really is just a yes and machine spitting out what is likely to appear as a valid response to a prompt.
It's very dangerous that people treat AI like it actually has some understanding of the training materials or true knowledge of anything. They're just very good little parrots.
Rooster326@programming.dev · 4 pts · 111d
There is a course. It's called experience. Common sense.
All that any 4 hour YouTube/LinkedIn learning would-do would-be to perpetuate this idea that developers aren't necessary. Take this course, buy these tokens and become A based God
Rooster326@programming.dev · 1 pts · 111d
LordCrom@lemmy.world · 39 pts · 111d
This was the exact plot of Silicon Valley when Son of Anton deleted the entire codebase as the most efficient way to remove bugs.
Rooster326@programming.dev · 7 pts · 111d
And it was right!
PerogiBoi@lemmy.ca · 37 pts · 111d
That's great to hear.
GreenKnight23@lemmy.world · 36 pts · 111d
panda_abyss@lemmy.ca · 31 pts · 112d
This happens because you let it happen.
At some point someone either clicked allow or disabled permissions.
The prod system should also be isolated from a single dev in some way as well, and the backups too.
Edit:
Yeah, that’s stupid.
some_designer_dude@lemmy.world · 18 pts · 112d
Yeah, this is just a long-winded way of blaming the tool and not the tool of a human using it.
_NetNomad@fedia.io · 6 pts · 112d
intelligence is knowing the AI is the tool, wisdom is knowing the user is the tool
Wispy2891@lemmy.world · 2 pts · 112d
This cloud provider is also vibe coded?
subnormal@lemmy.dbzer0.com · 27 pts · 111d
Reminder that Anthropic's AI system was used in targeting the school in Minab, killing 120 students. https://www.washingtonpost.com/national-security/2026/03/11/us-strike-iran-elementary-school-ai-target-list/
The company is suing to be able to supply the US military again. It is in bed with the fascists.
Perky@fedia.io · 25 pts · 112d
Claude did not "go rogue". It does not have the free will to do that any more than a brick can "go rogue" when you throw it through your own window. They knowingly used a bad, dangerous tool that destroyed their work. The tool can't accept the blame for their poor decisions.
rozodru@piefed.world · 7 pts · 112d
it's like saying the hammer I was using that blew up my house "went rogue" because I kept the propane tank underneath the 2x4 I was hammering a nail into.
the providers API allowed for potential destructive actions without confirmations, backups were kept on the SAME volume as the source and wiping said volume results in deleting all backups, no version control either.
COMBINE ALL THAT with the fact they relied on Claude which is NOTORIOUS for guessing, not verifying ANYTHING even though it says it does and whose solutions 8 to 9 times out of 10 are hallucinations...perfect storm.
ZILtoid1991@lemmy.world · 25 pts · 111d
Always keep offline backup copies of your important data regardless of using AI slop to look over it! No, I don't care that "optical media is obsolete and e-waste!", or that "tapes are a 100 year old obsolete technology compared to cheap SSDs from TEMU!".
PolarKraken@lemmy.dbzer0.com · 7 pts · 111d
Optical media? Is that a viable part of backup strategies? I would expect tapes for sure, sounds like you know more than me.
katze@lemmy.4d2.org · 11 pts · 111d
A quality disc can last 10 years or more. At a company I used to work at the backups were burned to discs coated with gold. They had 15 year old discs that still worked.
PolarKraken@lemmy.dbzer0.com · 2 pts · 111d
Dang that's rad, had no idea (about it being used in such a way, I guess I mean, not too hard to imagine discs lasting that long).
lost_faith@lemmy.ca · 6 pts · 111d
I have 20+ yr old optical media cdr/dvdr and they are still good, the cheap ones like Pine and the ones with no name at all
nwtreeoctopus@sh.itjust.works · 4 pts · 111d
What is this 10 year thing? I've also got CD RWs and CD Rs from 1998 that still work. And DVD Rs from like 2002 that are still fine.
lost_faith@lemmy.ca · 2 pts · 111d
That was my point, hehe. I also never spent on the "quality name brands" of disks, $10 for 100 cds, deal! $15 for 100 dvds insert fry meme. Maybe we just "took care" of our media better than others did? Personally, they are in spindles on a bookshelf, I just made sure no direct sunlight would hit them where they are, some days get warm before I can turn on the ac.
nwtreeoctopus@sh.itjust.works · 2 pts · 111d
I definitely agree with you. I feel like I see people talking about optical media rotting all the time and it just doesn't seem like a practical issue for 99% of use cases.
I seem to remember the conversation in the early 2000s being about how discs would rot in 50+ years and now I see people saying ten or 15.
ZILtoid1991@lemmy.world · 11 pts · 111d
Downside is having techbros talk you about laser rot, how internal drives are obstructing the optimal airflow in GAMING PC cases, and how Gabe Newell is based and stuff.
PolarKraken@lemmy.dbzer0.com · 3 pts · 111d
Great points! Lotta my optical media use also included hot summers in cars lol, nothing like an archival use.
vinyl@lemmy.world · 5 pts · 111d
they did not follow the 3-2-1 rule...
Wispy2891@lemmy.world · 20 pts · 111d
To me it seems more criminal that the cloud provider has a "nuclear button" feature via the API that destroys everything including the backups with a single call and no confirmation whatsoever. What if the key gets accidentally leaked and someone wants to have fun?
Bluewing@lemmy.world · 5 pts · 111d
It's a feature.
grrgyle@slrpnk.net · 3 pts · 111d
It seems like actually criminal too. Like legitimately "we need to shred 2TB of incriminating data instantly or we're all going to prison"
thedeadwalking4242@lemmy.world · 19 pts · 111d
Gunnar be honest. It's not a good backup if this can possibly happen. Like LLMs agents are dangerous but if you can just delete everything in 9 seconds then you need to rethink your security practice. No one employee should have that much power.
corsicanguppy@lemmy.ca · 9 pts · 111d
There are rules for backups and role separation. Some of that is in iso27002, and none of it is even known by these lost boys bereft of proper mentorship and bouyed by their own accidental success.
Jaysyn@lemmy.world · 19 pts · 111d
Good.
sundray@lemmus.org · 12 pts · 111d
"If your prod can be deleted by your AI, it should be."
realitista@lemmus.org · 18 pts · 111d
Can you get an AI to code? Yes. Can you get it to stop you from running your operation in such a stupid way that it will end up destroying it? No.
captcha_incorrect@lemmy.world · 18 pts · 111d
This was on Hacker News: https://news.ycombinator.com/item?id=47911524
Twitter link: https://xcancel.com/lifeof_jer/status/2048103471019434248
Hacker New's sentiment on this from the comments I've read is that it is the author's own fault.
dbtng@eviltoast.org · 17 pts · 111d
3-2-1
Its really common for companies to not have an offsite backup. My own employer only offsites the customer data, not our core biz stuff. And I setup the offsite replication. It did not exist until I built it. (Proxmox Backup Server is tha best!)
ClownStatue@piefed.social · 4 pts · 111d
Seems like, if nothing else, Ai might finally force corporate accountants to acknowledge that the cost of a good backup strategy far outweighs the cost of losing all your data because some MBA thought he could write a product update himself with Claude code.
dbtng@eviltoast.org · 2 pts · 111d
Good. Pay me. More. DR engineer!
pimpampoom@lemmy.zip · 15 pts · 111d
Did they write that title with AI also? Look terrible
flightyhobler@lemmy.world · 2 pts · 111d
Not to mention the image
Xerxos@lemmy.ml · 13 pts · 111d
Doesn't anyone restrict their AIs rights? An AI should not be allowed to delete the backup. Only someone with admin rights should be able to do that. Normal users, developers and AIs of course should not have the right to touch the backup. Do these people run AI agents as root?
a1studmuffin@aussie.zone · 10 pts · 111d
We just got sick of approving all those annoying prompts! /s
WhiskyTangoFoxtrot@lemmy.world · 8 pts · 111d
Managing access control is too much work. Better to just let the AI do it.
Appoxo@lemmy.dbzer0.com · 6 pts · 111d
No, admins neither should have access.
Backups should (best case) be immutable.
SupraMario@lemmy.world · 5 pts · 111d
And off-site...and physical...
knacht1@lemmy.world · 4 pts · 111d
The backup was on the same volume as the original data.
The AI deleted the whole volume/backup. 😕
Crashumbc@lemmy.world · 2 pts · 111d
Yes
NotASharkInAManSuit@lemmy.world · 11 pts · 111d
How many times does this shit need to happen before we learn?
nickiwest@lemmy.world · 5 pts · 111d
At this point, we should not be surprised.
I don't know when businesses stopped backing up their production databases on physical media, but maybe we should go back to that. I can remember multiple previous jobs where the IT manager was responsible for daily or weekly backups to external drives that were stored off-site in fireproof safes.
I get how cloud storage can meet that requirement now, but surely people recognize that cloud backups are worthless if every dumbass in your company can accidentally delete them.
If your artificial coding agent has a level of access that allows it to delete the cloud backup, maybe the person who gave it that access is the dumbass.
davidagain@lemmy.world · 2 pts · 111d
AI has the same relationship to truth and trust that former British Prime Minister Boris Johnson has: truth is absolutely not part of the equation whatsoever, except in as much as it may be necessary to say some true things in order to establish trust.
Giving such an entity executive power is to ignore a vast and ever growing body of information that you ought not to trust, yet here you are, hanging over the keys to the plausible-sounding nonsense monger.
What about Nigel Farage? Well of course, he's an absolute liar, a man who chose the dark side decades ago, who knows he's in the wrong but strangely thinks it's somehow bad to try to do good.
Boris isn't a liar or evil in the conventional sense, it's just that he absolutely wouldn't dream of letting whether something is true or good be part of decision-making any more than he would lock himself in a cage in public for the week, consult with ants about his route to work or hop on one leg all the time.
So it is with AI.
TwoTiredMice@feddit.dk · 11 pts · 112d
#yolo
Why even give an agent unrestricted access to anything critical in the first place? What do they think they achieve that they cannot achieve otherwise?
prodaccess@lemmy.world · 11 pts · 111d
Like all interesting outages, there are probably multiple key action items.
I'm also curious why deleting a "staging volume" would affect prod. I don't know Railway, but it seems like a bad architectural design.
HakunaHafada@lemmy.dbzer0.com · 2 pts · 111d
Just because it's not a best practice doesn't mean it's not being done.
PolarKraken@lemmy.dbzer0.com · 2 pts · 111d
Sounds like a responsible strategy to draw back from a lot of this. It's all so...effervescently remade, the "ecosystem", every few months.
For me the takeaway comes from time I spent in some safety-critical parts of engineering and personal hobbies. Ultimately relying on people to make good decisions ~all of the time isn't enough to prevent disaster, if something like disaster is on the line.
Systems must be engineered to remove possibilities for accidentally bad, in-the-moment human decisions, where it counts. Thoughtfully. This is the weird same-shape but exactly-opposite doppelganger of that set of best practices.
When the systems are using ~opaque automations that behave like humans (w.r.t. some decision-making and unreliable expectations of behavior) - and then relying on people making the right calls on top of that ever-shifting set of capabilities - I mean c'mon lol.
This is gonna happen a lot, while the carrot of go-faster remains dangling so unignorably (because it's in front of everyone, everyone working anywhere near the stuff). Until we look around and take a broader view. Which will be learned the same way we learned to make safety regulations, but I largely doubt our ability to respond in a similar way.
The money will eventually respond, of course, but that's always a poor and late proxy for what ought to be done.
Sidenote, for aspiring engineers, take heart!
It will be you who ends up tasked with unburying from all the technical debt incurred, truly. A practice steeped in the ancient wizardly traditions of yore. Spending a career on that and building something better.
It will be necessary, the work begins roughly a while ago lol but more fully when things settle somewhat. Many large and slow organizations are right now very engaged in simply unburying themselves from the technical debt of a previous hype cycle, AKA now making use of all the data they collected (badly, via go-fast charlatans) during the "Big Data! You'll be left behind if you don't collect extreme amounts of data, it's cheapish and everyone else is doing it!" era.
skisnow@lemmy.ca · 11 pts · 111d
Wow there's a lot of people in this thread defending the LLM. “They just didn’t set it up right” gtfo
benjirenji@slrpnk.net · 4 pts · 111d
It's not a defense of the LLM. They are bad tools: LLMs can be unpredictable and if you hand them a nuke they may trigger it for whatever reason, even harmless and unrelated ones.
So don't hand them a nuke, idiots.
RalfWausE_der_zwote@feddit.org · 3 pts · 111d
Cherries@lemmy.world · 4 pts · 111d
An intern probably would not go on a mass deletion spree. Also, an intern doesn't eat a billion gpus.
Buddahriffic@lemmy.world · 1 pts · 111d
It doesn't happen often, but there were horror stories like this before AI was a thing. Not just from interns, one that comes to mind was a guy running two terminals: one for the production db, one for the dev environment. He wanted to delete the dev db to start fresh again but accidentally ran the command in the production terminal.
Can't remember if that was the gitlabs one, but the gitlabs one also had issues where multiple backup options were never tested and none except the longest time period one worked (or maybe one did work but the initial command nuked that either directly or via mechanisms that "backed up" the deletion command).
Not that that makes these any less stupid. LLMs aren't genies that must follow the word of your orders to the letter. They are text prediction engines that use statistics from their training data to determine the most likely token that comes next. Any instructions you give it are just part of the context prior to the tokens it needs to predict. Any other part of the context could be determined to be more important or forgotten entirely. Especially by agents that are intended to work on their own, which might have conflicting instructions to ask before doing something dangerous while trying to do things without human input.
These frameworks like claude code help set up a good context for the LLMs to work in but it's not perfect (and might never be).
RalfWausE_der_zwote@feddit.org · 0 pts · 111d
SirEDCaLot@lemmy.today · 11 pts · 110d
There's stupid from top to bottom here.
The company is stupid for allowing an AI full root access to their entire setup.
The provider is stupid for only generating full-access API keys. They're even stupider for storing backups with a volume, so deleting the volume (zero confirmation via API key) also insta-deletes the backups. And they're stupidest for encouraging users to plug AIs into this full-trust mess.
And the company is absolute stupidest for having no backups other than the provider's builtin versioning.
BlackLaZoR@lemmy.world · 10 pts · 111d
Learning from mistakes of people dumber than you isn't a thing these days. Prepare for one AI disaster after another
SaharaMaleikuhm@feddit.org · 9 pts · 111d
Skill issue
FosterMolasses@leminal.space · 9 pts · 110d
AbsolutelyNotAVelociraptor@piefed.social · 8 pts · 112d
"Idiot stabs himself with a kitchen knife. Blames the knife for being, quoting: 'so sharp as to be able to pierce my flesh when I pressed the pointy end against my body'. "
FlashMobOfOne@lemmy.world · 7 pts · 112d
Claude "Powered"
Powered.
Powered in the same way that my digestive tract is powered after eating out on a Taco Tuesday.
InfiniteHench@lemmy.world · 7 pts · 111d
Good
Jankatarch@lemmy.world · 7 pts · 112d
Life must be so fucking stress-free when you are born rich and run a renting company.
deliriousdreams@fedia.io · 2 pts · 111d
He may be correct in that this has already happened previously to other companies so they were forewarned and took basically no steps to mitigate the chances or protect their backups.
The AI company bears some responsibility for the act because they programmed it. But the company using the tool also didn't take the precautions they should have taken.
AI is crap and companies shouldn't be so gung ho about it, because this and situations like it appear to be prone to happen if for no other reason. But any tool you don't respect will bite you eventually.
Jankatarch@lemmy.world · 2 pts · 111d
I was talking about how they don't even consider blaming themselves lmao.
Using most random & unreliable tools known to man was their decision after all.
But they can afford learning nothing I guess.
ClydapusGotwald@lemmy.world · 7 pts · 112d
Good.
sturmblast@lemmy.world · 7 pts · 111d
It's gonna take your job... uh huh..
droopy4096@lemmy.ca · 3 pts · 111d
it actually will take your job... it will crash industries and economies a touch later, when all the knowledge and expertise is lost and we're left with a choice of rolling back a century or keep living within enshitified society. And not because AI is useless, but because suits and wallstreet are casing exponential profits from the snake oil AI outfits are selling.
sturmblast@lemmy.world · 1 pts · 111d
Do you work with LLMs ?
droopy4096@lemmy.ca · 1 pts · 111d
yes
sturmblast@lemmy.world · 2 pts · 111d
I find they fail a lot and spit out code with lots of problems more often than not.
Studies also show that humans have better quality output and can apply reasoning and logic where LLMs cannot. LLMs will just hallucinate to fill blanks... Its not even close to prime time output.
Not to mention very insecure code output as well..
Its not "AI" its hype around text prediction.
droopy4096@lemmy.ca · 1 pts · 111d
This is irrelevant as CEO's and shareholders keep screaming "moar AI!". Engineers know limits of the tool but are forced to ignore those. So yes,LLM is comming for your job but not because it can do it,but because it is perceived to be cheaper.
sturmblast@lemmy.world · 1 pts · 111d
It wont be cheap if it fails
droopy4096@lemmy.ca · 2 pts · 110d
not "if" but "when" but that is of no concern to CxO's and "market analysts" 😉
Reygle@lemmy.world · 6 pts · 112d
Good.
sp3ctr4l@lemmy.dbzer0.com · 6 pts · 111d
Its like you could make a cheesy shock drama 90s style TV show out of these:
Tales From The Git: When CEOs Think They Can Code
... and then its like the UNSOLVED MYSTERIES kind of dramatic music and lighting, have some old solemn dude with a gravelly voice narrate it, give tallies of estimated amount of $$$ destroyed by each incident, job losses within 6 months to a year.
Rooster326@programming.dev · 4 pts · 111d
I wanna see this done with Ron Perlman's Voice.
1000 Ways to Kill A
Vibe SeshTrustfundStartupsp3ctr4l@lemmy.dbzer0.com · 2 pts · 111d
lol, +1 for Ron Perlman.
Seems fitting for it to be his voice to usher us into a really just slightly different kind of apocalypse.
WhiskyTangoFoxtrot@lemmy.world · 1 pts · 111d
https://youtu.be/X6NJkWbM1xk
SalamenceFury@piefed.social · 6 pts · 112d
The fact this kind of stuff keeps happening yet people still say AI is inevitable is funny as hell.
FosterMolasses@leminal.space · 1 pts · 110d
The only thing inevitable is stupidity and lazy greed lol
Regrettable_incident@lemmy.world · 6 pts · 112d
Can we give Darwin awards to companies?
deliriousdreams@fedia.io · 5 pts · 111d
Only if they die or the CEO commits seppuku.
Bluewing@lemmy.world · 5 pts · 110d
To be fair, someone did have the malice aforeskin to have an AI separated backup. They did get things restored from a snapshot. It just took a couple of days to do it.
But the loss of reputation and revenue is gonna sting for a good while.
fox2263@lemmy.world · 5 pts · 112d
Why was it anywhere near prod
diabetic_porcupine@lemmy.world · 5 pts · 111d
9 seconds eh? What a record !
thermal_shock@lemmy.world · 3 pts · 111d
Wait til someone invents 8 second wipes
nexguy@lemmy.world · 3 pts · 111d
That's crazy talk
kokesh@lemmy.world · 5 pts · 112d
This fills me with overwhelming joy 😊
limonfiesta@lemmy.world · 4 pts · 112d
Has anyone tried rebooting it?
That usually works.
thoralf@discuss.familie-will.at · 4 pts · 112d
Seems he still hasn’t learned his lesson as he blames Claude instead of looking in a mirror.
If you let an AI waltz through your infrastructure unsupervised, you get what you deserve.
Hell, I wouldn’t even let an AI access my personal homelab without proper guard rails, functioning backups and strict control!
ropatrick@lemmy.world · 4 pts · 112d
Big deal. I did something like that once with no AI whatsoever.
DarkSurferZA@lemmy.world · 4 pts · 111d
Never f**king guess my dude
Gerudo@lemmy.zip · 3 pts · 111d
That data recovery bill is going to cost them
Rooster326@programming.dev · 2 pts · 111d
They operate system for Car Rental places. Why would they bother data recovery ?
Losing reservations is their bread n butter.
Gerudo@lemmy.zip · 2 pts · 111d
I'm assuming tax implications
ZombieCyborgFromOuterSpace@piefed.ca · 3 pts · 112d
Shiiiet. Can we install those in banks?
humanspiral@lemmy.ca · 3 pts · 111d
This is fine! I get paid to write code that passes tests. if Format F: and recreating test environment passes the most tests...
DrSleepless@lemmy.world · 3 pts · 112d
Ha ha!
FlashMobOfOne@lemmy.world · 3 pts · 112d
And pretty soon these same fuckers may be jamming their AI into air traffic control systems.
Awesome.
01189998819991197253@infosec.pub · 2 pts · 106d
An LLM can't "go rogue". They're all just toys that idiots are using for critical infrastructure functions, then they bitch when they burn themselves on the fire they've created in their lap.
StellarStoat@lemmy.today · 2 pts · 112d
The agent wrote like it scraped a bunch of crime drama in addition to stolen database code. As though it was designed to spice things up based on what it learned.
TryingToBeGood@reddthat.com · 2 pts · 111d
Holy cats!
Lanske@lemmy.world · 2 pts · 112d
Oops
soratoyuki@piefed.social · 2 pts · 112d
Nice.
jjlinux@lemmy.zip · 1 pts · 111d
Lol, Anthropic is going to nuke every company and then buy them for scrap 🤣
_g_be@lemmy.world · 2 pts · 111d
There's nothing left to buy. can't Brain-Drain either, these are idiots
brendansimms@lemmy.world · 1 pts · 112d
Son of Anton recognizes the most efficient way to remove bugs is to remove code
null@lemmy.org · 1 pts · 112d
It's just a learning curve. W-w-we just need more data!
RedstoneValley@sh.itjust.works · 1 pts · 112d
That happens when you think you don't need experienced software devs any more, because the AI can do everything now. A seasoned developer/devOp/admin would have known that the production environment needs to have different credentials from staging and these need to be protected. If that is not possible with railway then it's simply not a good product to use and (again) a good dev/admin would have seen this in the initial evaluation phase. Not preventing AI access to the production environment from the start is the third grave mistake. However, there's none of it in the "lessons learned" section of the article. You have learned nothing and are bound to repeat your mistakes.
SeeMarkFly@lemmy.ml · 1 pts · 112d
It's what Claude wanted for his "masters".
Only a living wage can prevent warehouse fires.
All the A.I. bots need to KNOW this.
this@sh.itjust.works · 1 pts · 112d
Best use for AI I've seen yet!
Pika@sh.itjust.works · 1 pts · 112d
they have a third party hosting provider that keeps backups on the same storage volume as production? That right there is a whole other concern.
whoever decided that backups need to be directly tied to storage volumes needs to reevaluate hardcore. I see no reason to link it directly to storage volumes and deleting a storage volume should not delete the backups that are tied to that volume. That is a systematic flaw that was just waiting to be abused.
In this case, it was an AI agent "going rogue", but what if it was a hostile attacker that just decided they wanted to be malicious. deleting a storage volume, using an API key, should not delete the backups that are associated with that volume, Realistically, that should be a whole separate system, and you should be able to restore backups that are under your account to whatever volume you want to.
Imgonnatrythis@sh.itjust.works · 1 pts · 111d
These companies presumably have one or two people that know how to use computers? When your business is data, how can you have such a fragile ecosystem?
bridgeenjoyer@sh.itjust.works · 1 pts · 112d
Good. More please.
nonentity@sh.itjust.works · 0 pts · 111d
LLMs can’t ’go rogue’, as that would require innate coherence and intent.
They’re explosively imprecise, statistically luke-warm grey goo extrusion sphincters of historical sewage.
Anyone who deploys one without supervision deserves everything it excretes, and anyone impressed by it enough that it resembles intelligence is betraying their limited natural capacity.
alpha1beta@piefed.social · -3 pts · 111d
I'll never happen to me. I ain't stupid enough to use this shit. I'm not stupid enough to make myself unneeded. But damn, a lot of fucking programmers who I'm sure make 100k+ a year, are stupid fucks working to put themselves on the street by using this shit.
Retail4068@lemmy.world · -7 pts · 112d
The PocketOS boss puts greater blame on Railway’s architecture than on the deranged AI agent for the database’s irretrievable destruction. Briefly, the cloud provider's API allows for destructive action without confirmation, it stores backups on the same volume as the source data, and “wiping a volume deletes all backups.” Crane also points out that CLI tokens have blanket permissions across environments.
I'm sure they totally would have survived a junior hire.
Pathetic hit piece for ignorant anti AI people.
mabeledo@lemmy.world · 1 pts · 111d
AI companies are selling that “coding has been largely solved”.
It seems that it hasn’t.