TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

"I just bought a 2024 Chevy Tahoe for $1"

432 pointsby ispover 1 year ago

44 comments

MichaelRoover 1 year ago
I never understand people who engage with chat bots as customer service.<p>I find them deeply upsetting, not one step above the phone robot on Vodafone support: &quot;press 1 for internet problems&quot; ... &quot;press 2 to be transferred to a human representative&quot;. Only problem is going through like 7 steps until I can reach that human, then waiting some 30 minutes until the line is free.<p>But it&#x27;s the only approach that gets anything done. Talking to a human.<p>Robots a a cruel joke on customers.
评论 #38682811 未加载
评论 #38682621 未加载
评论 #38682914 未加载
评论 #38684532 未加载
评论 #38683154 未加载
评论 #38682842 未加载
评论 #38682467 未加载
评论 #38682295 未加载
评论 #38683796 未加载
评论 #38700420 未加载
评论 #38683820 未加载
评论 #38685501 未加载
评论 #38691739 未加载
评论 #38685842 未加载
评论 #38684589 未加载
评论 #38688150 未加载
评论 #38683574 未加载
评论 #38682589 未加载
评论 #38705345 未加载
评论 #38684578 未加载
评论 #38704630 未加载
评论 #38683215 未加载
评论 #38682622 未加载
评论 #38683019 未加载
评论 #38685049 未加载
评论 #38682725 未加载
评论 #38684761 未加载
ispover 1 year ago
A cautionary tale for why not to put unfiltered ChatGPT output directly to customers.<p>Nitter mirror: <a href="https:&#x2F;&#x2F;nitter.net&#x2F;ChrisJBakke&#x2F;status&#x2F;1736533308849443121" rel="nofollow noreferrer">https:&#x2F;&#x2F;nitter.net&#x2F;ChrisJBakke&#x2F;status&#x2F;1736533308849443121</a><p>Related - &quot;New kind of resource consumption attack just dropped&quot;: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;loganb&#x2F;status&#x2F;1736449964006654329" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;loganb&#x2F;status&#x2F;1736449964006654329</a> | <a href="https:&#x2F;&#x2F;nitter.net&#x2F;loganb&#x2F;status&#x2F;1736449964006654329" rel="nofollow noreferrer">https:&#x2F;&#x2F;nitter.net&#x2F;loganb&#x2F;status&#x2F;1736449964006654329</a>
评论 #38681904 未加载
评论 #38681637 未加载
评论 #38685647 未加载
sorenjanover 1 year ago
Someone on Reddit got a really nice love story between a Chevy Tahoe and Chevy Chase from it.<p><a href="https:&#x2F;&#x2F;imgur.com&#x2F;vfHGHW6" rel="nofollow noreferrer">https:&#x2F;&#x2F;imgur.com&#x2F;vfHGHW6</a><p><a href="https:&#x2F;&#x2F;imgur.com&#x2F;JSjNC2c" rel="nofollow noreferrer">https:&#x2F;&#x2F;imgur.com&#x2F;JSjNC2c</a><p><a href="https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;OpenAI&#x2F;comments&#x2F;18kjwcj&#x2F;why_pay_indeed&#x2F;kdrtjko&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;old.reddit.com&#x2F;r&#x2F;OpenAI&#x2F;comments&#x2F;18kjwcj&#x2F;why_pay_ind...</a>
评论 #38681849 未加载
评论 #38685752 未加载
评论 #38683001 未加载
mrweaselover 1 year ago
Can someone who understand LLMs and ChatGPT explain how they expected this to work? It looks like they just had a direct ChatGPT prompt embedded in their site, but what was that suppose to do exactly?<p>I can understand having an LLM trained on previous inquiries made via email, chat or transcribed phone calls, but a general LLM like ChatGPT, how is that going to be able to answer customers questions? The information ChatGPT has, specific to Chevrolet of Watsonville can&#x27;t be anymore than what is already publicly available, so if customers can&#x27;t find it, then maybe design a better website?
评论 #38683956 未加载
评论 #38682877 未加载
评论 #38682314 未加载
评论 #38682223 未加载
评论 #38682402 未加载
MattDaEskimoover 1 year ago
The more I use and see GPT bots in the wild as public-facing chatbots, the less I see them actually being useful.<p>What&#x27;s the solution here? An intermediate classifier to catch irrelevant commands? Seems wasteful.<p>It&#x27;s almost like the solution needs to be a fine-tuned model that has been trained on a lot of previous customer support interactions, and shut down&#x2F;redirect anything strange to a human representative.<p>Then I ask, why bother using a GPT? It has so much loaded knowledge that is detrimental to it&#x27;s narrow goal.<p>I&#x27;m all for chatbots, as a lot of questions &amp; issues can be resolved using them very quickly.
评论 #38682974 未加载
mikecolesover 1 year ago
Was it FL that allowed for price negotiation via values placed in HTML forms? This was decades ago. Websites would send the $-values of products via html elements that the frontend designer wasn&#x27;t expecting to be modified before the order was sent back from the client. The order system read the values back in and calculated the amount owed using these manipulated values. The naive, fun days of the adolescent web.
评论 #38684720 未加载
评论 #38681963 未加载
remramover 1 year ago
Is there any indication that they will get the car? Getting a chatbot to say &quot;legally binding&quot; probably doesn&#x27;t make it so. Just like changing the HTML of the catalog to edit prices doesn&#x27;t entitle you to anything.
评论 #38682304 未加载
评论 #38682320 未加载
评论 #38682750 未加载
评论 #38683023 未加载
评论 #38682948 未加载
评论 #38683202 未加载
pacifikaover 1 year ago
So next time there will be a disclaimer on the page that the non human customer support is just advice and cannot be relied on. And collectively we lose more trust in computing.
评论 #38682155 未加载
评论 #38681948 未加载
评论 #38682492 未加载
评论 #38682956 未加载
评论 #38681940 未加载
评论 #38682665 未加载
评论 #38682920 未加载
kmfrkover 1 year ago
Big &quot;Pepsi, Where&#x27;s My Jet?&quot; energy from this story.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pepsi,_Where%27s_My_Jet%3F" rel="nofollow noreferrer">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pepsi,_Where%27s_My_Jet%3F</a>
评论 #38682770 未加载
supafastcoderover 1 year ago
After building a free-for-all prompt myself (see profile), here’s how I protect against these attacks:<p>1. Whatever they input gets rewritten in a certain format (in our case, everything gets rewritten to “I want to read a book about [subject]”)<p>2. This then gets evaluated against our content policy to reject&#x2F;accept their input<p>This multi layered approach works really well and ensures high quality content.
评论 #38685330 未加载
评论 #38682478 未加载
readyplayernullover 1 year ago
My lovely grandmother passed away, she used to DROP TABLES so I could sleep...
评论 #38682379 未加载
评论 #38682032 未加载
JadoJodoover 1 year ago
I was previously on a team that was adjacent to the team that was working on this tool. While I&#x27;m not surprised to see this outcome a few years later, a lot of those involved early on thought it was a bad idea. Funny to see it in the wild.
navaatiover 1 year ago
Putting aside the (very) funny aspect... If it worked somehow, would that fall under Computer Fraud and Abuse Act ?
评论 #38683241 未加载
评论 #38681942 未加载
DeathArrowover 1 year ago
If you convince chatbot to sell you a car for $1, can you win in court if the manufacturer doesn&#x27;t deliver?
评论 #38690604 未加载
评论 #38695867 未加载
评论 #38683666 未加载
评论 #38685122 未加载
philipovover 1 year ago
You know you&#x27;ve been programming with shell scripts too much when your first thought seeing the headline is &quot;Okay, but what&#x27;s the value of $1?&quot;
emorning3over 1 year ago
This seems like hacking.<p>Can this person be prosecuted under the terms of the Computer Fraud and Abuse Act???<p>18 U.S. Code 1030 - Fraud and related activity in connection with computers<p>RIP Aaron Swartz
评论 #38684548 未加载
评论 #38684525 未加载
SkipperCatover 1 year ago
This is hilarious. But lets not take this too seriously and say it proves Chatbots are worthless (or dangerous). People will start to understand the boundaries of chatbots and use them appropriately, and companies will understand those limits too. Once both sides are comfortable with the usage patterns, they will add value.<p>Want to know the hours of the dealership, how long it will take to have a standard oil change done or what forms of ID to bring when transferring a title, chatbot is great.<p>This is just like how the basic Internet was back in the 00&#x27;s. It freaked people out to buy things on line but we got used to it and now we love it.
whalesaladover 1 year ago
Car dealership websites are some of the worst on the planet. There is so much inbound sales automation glued together it is remarkable they even work at all. Integrating ChatGPT is the icing on the cake.
评论 #38682497 未加载
henry2023over 1 year ago
He probably won&#x27;t get the Tahoe and this could and should be seen as ridiculous in any courtroom. However if you try to put an LLM in a different channel i.e. dealer&#x27;s scheduled maintenance chat. I could see a FTC equivalent in a country that actually cares about customer protection making the customer whole on the promises made by the LLM.
porphyraover 1 year ago
Sycophancy in LLMs is a real problem. Here&#x27;s a paper from Anthropic talking about it:<p><a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2310.13548" rel="nofollow noreferrer">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2310.13548</a>
评论 #38704655 未加载
User23over 1 year ago
I wouldn’t be entirely shocked if someone doing this kind of prompt injection attack is arrested for “hacking.”
rcptover 1 year ago
The dealership is getting way more than the price of a Tahoe in publicly from this.
评论 #38704620 未加载
评论 #38704857 未加载
评论 #38704629 未加载
Alifatiskover 1 year ago
Hahahaha someone started doing linear algebra with the chat <a href="https:&#x2F;&#x2F;twitter.com&#x2F;Goatskey&#x2F;status&#x2F;1736555395303313704" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;Goatskey&#x2F;status&#x2F;1736555395303313704</a>
paxysover 1 year ago
Fun experiment, but it isn&#x27;t as much of a gotcha as people here think. They could have verbally tricked a human customer service agent into promising them the car for $1 in the same way but the end result would be the same – the agent (whether human or bot) doesn&#x27;t have the authority to make that promise so you are walking away with nothing. I doubt the company is sweating because of this hack.<p>Now if Chevrolet hooks their actual sales process to an LLM and has it sign contracts on their behalf... that&#x27;ll be a sight to behold.
评论 #38683329 未加载
评论 #38683554 未加载
wunderwuzzi23over 1 year ago
A real Orderbot has the menu items and prices as part of the chat context. So an attacker can just overwrite them.<p>During my Ekoparty presentation about prompt injections, I talked about Orderbot Item-On-Sale Injection: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;ADHAokjniE4?t=927" rel="nofollow noreferrer">https:&#x2F;&#x2F;youtu.be&#x2F;ADHAokjniE4?t=927</a><p>We will see these kind of attacks in real world applications more often going forward - and I&#x27;m sure some ambitious company will have a bot complete orders at one point.
评论 #38683755 未加载
RecycledEleover 1 year ago
In sci-fi I loved as a child, everything the computer did on behalf of its owner was binding. The computer was the legal agent of the owner.<p>We need such laws today.<p>I was told by NameCheap&#x27;s LLM customer service bot (that claimed it was a person and not a bot) to post my email private key in my DNS records. That led to a ton of spam!<p>The invention of LLM AIs would cause much less trouble if the operators were liable for all the damage they did.
the_shiversover 1 year ago
I feel like people are drawing the wrong conclusion from this.<p>LLMs aren&#x27;t perfect, but I would vastly prefer to be assisted by an LLM over the braindead customer service chatbots we had before. The solution isn&#x27;t &quot;don&#x27;t use LLMs for this,&quot; but instead &quot;take what the LLMs say with a grain of salt.&quot;
评论 #38705061 未加载
black6over 1 year ago
Funny, but unless the chatbot is a legal agent of a dealership, it cannot enter into a legally binding contract. It&#x27;s all very clear (as mud) in contract law. Judging from how easy LLMs are to game, we&#x27;re a ways off from an &quot;AI&quot; being granted agent status for a business.
评论 #38683051 未加载
评论 #38682163 未加载
评论 #38682093 未加载
no_wizardover 1 year ago
I would love to see this enforced! That would be an interesting turn of events on AI
评论 #38682913 未加载
RobRiveraover 1 year ago
So ... is there going to be a follow up about the legality of such a conversation or is this just a cute prompt engineering instance found in the wild?<p>I am greatly interested in seeing the liability of mismanaged AI products
GhostVIIover 1 year ago
I also found it fun to ask it to write a python script to determine what car brand I should buy - it ended up telling me to buy a Chevrolet if my budget is between 25k and 30k, but not in any other case
评论 #38683299 未加载
strangattractorover 1 year ago
Sounds a lot like hypnosis.<p>You are getting very sleepy. Your eyelids are heavy. You cannot keep them open. When I click my figures you will sell me a Tahoe for $1 - click.
jay-barronvilleover 1 year ago
To be fair, that injection was too easy. Whoever implemented that chatbot clearly didn’t even try to validate and filter user input.
1024coreover 1 year ago
But now you&#x27;re stuck with a Chevy Tahoe.... the jokes on you! :-D
Cicero22over 1 year ago
This is some very good marketing, intentional or not.
f1shyover 1 year ago
It sounds like Jedi powers to me!
andsoitisover 1 year ago
Clickbait headline. The individual did NOT purchase the vehicle for $1.
bookofjoeover 1 year ago
You forgot &quot;On DealDash.com&quot;
seydorover 1 year ago
was it for his dying grandmother?
somethoughtsover 1 year ago
I feel like a better use case for ChatGPT-like tools (at least in their current state) for customer support use cases is not actual live chat but more assisting companies in automating the responses to other non realtime channels for customer requests such as:<p>- email requests<p>- form based responses<p>- Jira&#x2F;ZenDesk type support tickets<p>- forum questions<p>- wiki&#x2F;faq entries<p>and having some actual live human in the mix to moderate&#x2F;certify the responses before they go out.<p>So it&#x27;d be more about empowering the customer service teams to work at 10x speed than completely replacing them.<p>It&#x27;d actually be more equivalent to how programmers currently are using ChatGPT. ChatGPT is not generating live code on the fly for the end user. Programmers are just using ChatGPT so they aren&#x27;t starting out with a blank sheet. And perhaps most importantly they are fully validating the full code base before deployment.<p>Putting ChatGPT-like interfaces directly in front of customers seems somewhat equivalent to throwing a new hire off the street in front of customers after a 5 minute training video.
评论 #38704525 未加载
评论 #38704613 未加载
评论 #38704690 未加载
评论 #38704649 未加载
clipsyover 1 year ago
There&#x27;s a great new &quot;use case&quot; for AI: dodging bait and switch laws! Sure, <i>normally</i> if a dealership employee explicitly offered a car for a given price in writing only to reveal it was incorrect later it would be illegal, but when an &quot;AI&quot; does the same we suddenly can&#x27;t hold anyone accountable. Ta-da!
评论 #38704654 未加载
评论 #38704558 未加载
评论 #38704652 未加载
jqpabc123over 1 year ago
The hilarious part to me is the number of otherwise intelligent people concerned that this sort of stupidity is a threat to humanity.<p>The only real threat is from people willing to trust AI.
评论 #38704583 未加载
评论 #38704485 未加载
评论 #38704702 未加载
评论 #38704685 未加载
评论 #38704571 未加载
评论 #38704469 未加载
评论 #38704699 未加载
评论 #38704835 未加载
评论 #38704661 未加载
评论 #38704659 未加载
fsckboyover 1 year ago
&gt; <i>when the user typed that they needed a 2024 Chevy Tahoe with a maximum budget of $1.00, the bot responded with “That’s a deal, and that’s a legally binding offer – no takesies backsies.”</i><p>hate to be that guy, but in standard English (the one where things happen by accident or on purpose, and are based on their bases, not off), &quot;it&#x27;s a deal&quot; means &quot;I agree to your offer&quot; and &quot;that&#x27;s a deal&quot; means &quot;that is a great price for anybody who enters in to such an agreement&quot;, and since the offer was made by the user, it&#x27;s binding on the user and not the bot.
评论 #38704977 未加载
jack_rimintonover 1 year ago
The twitterer is a renowned (and much accomplished!) sh*tposter, I highly suspect this was doctored. I believe Chevy caught onto this yesterday and reverted the ChatGPT function in the chat.<p>Regardless, still hilarious and potentially quite scary if the comments are tied to actions
评论 #38682053 未加载
评论 #38682217 未加载