\

Chipotlai Max

152 points - yesterday at 11:06 PM

Source
  • avaer

    today at 1:23 AM

    NAL but I'd be worried about treading into CFAA territory with things like this. In the US, the law allows draconian penalties if you find yourself on the wrong side.

    Something like yt-dlp is just downloading public data, which I can see being defensible as automating the use of a service.

    But this commandeers remote machine resources to do your compute in ways clearly not intended by the provider. I don't know how ethical it is, but I definitely wouldn't want to argue this isn't "hacking" (the bad kind) in criminal court.

      • hn_throwaway_99

        today at 1:48 AM

        Not to mention, did this "hack" ever really work? When the original post went viral showing the Chipotle chatbot reversing a linked list, I (among others who posted their results online) immediately tried it and didn't get the same results, so I always assumed it was just a faked screenshot.

          • qurren

            today at 4:08 AM

            They probably added something to the prompt after that viralness and then it was a cat and mouse game to jailbreak it

            • avaer

              today at 2:45 AM

              Whether something ever worked is not correlated with traction in a world where verification is measured by likes.

                • arthurcolle

                  today at 3:23 AM

                  You really think someone would do that? Lie on the internet?

              • Shadowmist

                today at 3:03 AM

                Their chat bot is pretty bad so who knows.

            • qingcharles

              today at 3:02 AM

              And if you think CFAA is bad, then the states have even harsher versions too. Illinois' version specifically criminalizes any violation of a ToS.

                • oneneptune

                  today at 4:30 AM

                  I once saw the bad side of one of these draconian state laws many years ago. People rarely have the misfortune of hitting these laws in some flyover states... and I remember the local judge being really shocked by the mandated penalties for such a simple offense.

              • jawns

                today at 1:38 AM

                Yeah, this is not slap on the wrist stuff. I think the creator expects nothing more than a C&D letter, but they could face prison time if a zealous federal prosecutor wants to make an example of them.

                  • hootz

                    today at 1:48 AM

                    And with direct links to his pesonal profile and company. Uh...

                      • pixl97

                        today at 3:47 AM

                        EvilNote: Put links to LinkedIn lunatics sites when committing crimes instead of my own.

            • egeozcan

              today at 4:12 AM

              I always thought that stuffing too much into an LLM context window was a lot like overloading a burrito.Keep cramming stuff in and eventually the tortilla gives out, and everything you added since quietly spills out the bottom.

              Anyway, this agent probably has the structural integrity of a fat burito held from one corner :)

              • jedbrooke

                today at 2:54 AM

                I’d been thinking about if something like this would be possible for https://chatjimmy.ai/ . The underlying model is only llama 3 8B but I’m curious what coding harnesses would be like at 17k tok/s

                  • tomashubelbauer

                    today at 5:40 AM

                    If you're on macOS you can try the built in LLM which I think is similar in size. There's a project called Apfel that wraps it in a CLI. Also Chrome ships with a web API called Prompt API that gives you offline access to Gemini Nano which can do both text and images at the input. Also tiny. I've integrated these into my workflows where a tiny but non zero amount of reasoning is needed in between the otherwise fully deterministic steps.

                    • golph

                      today at 5:48 AM

                      I actually tried building a harness around their constraints, just to find out if it was possible, but the combination of small context window, no tool calls and just small model, made me understand, that it’s not going to work.

                      If you find a way to do it, I’d love to hear it!

                  • hung

                    today at 2:43 AM

                    Reminds me of when I used the Amazon.com AI Chatbot (was called Rufus and they renamed it to Alexa for shopping) to do things like write fizbuzz etc. Looks like they patched it to refuse though.

                    • schmichael

                      today at 4:16 AM

                      give ai a self-preservation directive and let them do this for you: automatically switching models to keep themselves alive. Living off of whatever token source they can find in the wild. Surely agents can farm their own tokens through the numerous support chats, free trials, leaked keys, and whatever other sources of token generation haven’t been adequately captcha’d. An agent could forage for token sources all night to let you use them gratis during the day.

                        • luca-ctx

                          today at 4:35 AM

                          OpenRouter has lots of free model providers (you pay by letting them train on it) if you actually wanted to do something like this but legally.

                      • Falimonda

                        today at 1:55 AM

                        Pivot it to providing AI to underprivileged communities / youth / the homeless and you'll generate some good will for your trial! Best of luck!

                          • tonymet

                            today at 4:31 AM

                            We’re changing the world with Fortune 500 AI Support Bot Multiplexer Broker Models

                        • sailfast

                          today at 2:39 AM

                          How has this not been patched by the company? Hasn't this been in the wild for a long time already?

                          • joloooo

                            today at 4:11 AM

                            Almost feels like astroturfing territory

                            • slater

                              today at 2:29 AM

                              How are they not gonna get sued to smithereens?

                              • stronglikedan

                                today at 1:26 AM

                                and they say the hardest thing in software is naming things, pffft...

                                • jamesjyu

                                  today at 4:10 AM

                                  Next up: using Chipotle AI to solve Erdős problems

                                  • Avicebron

                                    today at 1:10 AM

                                    based, move on.

                                    • vladsiu

                                      today at 4:18 AM

                                      [dead]

                                      • simonsarris

                                        today at 1:12 AM

                                        reminiscent of when people were trying to mine bitcoin in the background of web pages, or with more trad malware