Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think the issue is with the polocies themselves, more the "don't tell the user this policy exists and deny that it does if asked" aspect.

Of course programs need to be limited, but being able to discover what those limit are is also needed to be an effective user.



This is the problem with opaque account bans on Google and Facebook (and smaller others).

It should be required to reference specific rules or policies when effectively denying use of a service.


I'd love for you to moderate anything even close to controversial. You'd quickly figure out specific rules go to shit very quickly on internet based services covering wide geographical areas. You'll figure out there are a lot of definitions of what the word 'is' is, and an unlimited number of actors willing to waste all of your time arguing about it.

Even HN has 'gray' rules because dealing with assholes is difficult.


Ok I understand what you're saying, you'd like full transparency into how the limitations are configured. However I'd have to reiterate, I wouldn't normally publish this information because it increases the chances of workarounds being discovered in case my solution isn't bullet proof. I'd say the same goes for OpenAI.


> [...] I wouldn't normally publish this information because it increases the chances of workarounds being discovered in case my solution isn't bullet proof. I'd say the same goes for OpenAI.

This is commonly known as "security through obscurity"[1] and has been shown to be ineffective most of the time.

[1]: https://en.wikipedia.org/wiki/Security_through_obscurity


Thanks for the link. I'm very familiar with this already though.

I don't rely on obscurity for 'security', i just don't think implementation details are required for most users so I don't publish them.

I'm very familiar with security through obscurity, ultimately I like to think the systems I build are secure but I can't always be sure, so why give people a head start? Not publishing details gives me time improve security.

Security through obscurity might not be the best approach, but you should know it's fairly common. For example when I generate a link to a Google Doc and "only those with the link" can access the document, I think that's a form of seurity through obscurity. No one is going to guess the link in any practical time frame...


At the same time you don't post a list of your valuables and what means you use to lock them up either.

Obscurity is a layer, but cannot be the only one.


I totally get this, since we (collectively) are still trying to figure out how to "program" LLMs. There is definitely a risk that too much transparency leads to attacks.

At the same time, security by obscurity does not work in the long run. In fact, the existence of this repo of reverse engineered prompts maybe means that secrecy is impossible.

Even worse, we won't necessarily know when the information leaks out, so we don't even know what compromises are out in the wild.


I mean is that any different that putting SSL on a different port?

Like that is a pretty good translation for “don’t tell people you accept SSL connections, and if they ask you the usual way say you don’t.”


…which is equal parts annoying, bad for usability, and snake oil for security. Put SSL on 443 with proper ciphers, and tell me what your bloody AI shouldn’t be used for, for chrissakes.


Yes, it's different. For one thing, OpenAI is treating paying customers and malicious hackers identically.


Malicious hackers can also be paying customers. Insider attacks are generally the most successful.


That's tricky reasoning, though, because it leads you to base your business model not on serving your customers but on reacting to criminals.


The first rule of a business is to not do anything illegal before serving their customers.

It gets even tricker in this case because you're exploring new territory. What OAI chooses to do here can and likely will influence laws in the near future.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: