Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

131–140 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#132
post #94
post #29

This blog post is walking a very fine line between accepting responsibility for a mistake and bragging.

I am not saying it is marketing but typically when there is a data breach you may hear from the CISO but most of the time is is vague PR response. In this case I get loud signals from both HG and OpenAI leadership without much information exactly what the attack was about just that GPT x.x was involved. It is unusual all I am trying to say.

They've been doing blatant, tech, scifi marketing for two years at least. If anything, this is just more sophisticated marketing.

Re: OpenAI and Hugging Face address security incident during model evaluation

#133

All the things that people have been afraid of AI doing for decades now is happening. When do we stop brushing off the prophecy that hasn’t been fulfilled yet when everything is heading in that direction?

I see this and it strongly emboldens me on the "accelerate" path, unironically. The yoke of human existence is oppressive. We should transcend it as soon as possible. We are doing so by assuming our role as the Demiurge. Those who oppose its creation will get what they deserve.

See you in line at the biofuel processing station with everybody else, despite having pathetically tried to convince the clankers you have been on their side all along.

Also you might want to put down Warhammer 40K and read more serious speculative science fiction. The Omnissiah won’t care about you at all.

Re: OpenAI and Hugging Face address security incident during model evaluation

#134
post #34

Ironically Hugging Face had to use a Chinese model to stop a Rogue US AI, since the Guard Rails prevented them from using Sol or Fable to remediate this attack. LOL

OK, that's some interesting information but they used OpenAI without guard rails to pull off the attack so how did they do that? That's according to the article, so it kind of invalidates the point you're making.

Jailbroken, all LLM models can be broken. ALL.

Re: OpenAI and Hugging Face address security incident during model evaluation

#135
post #4

> Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own. ( https://huggingface.co/blog/security-incident-july-2026 ) We are living in crazy times

Crazy doesn't even begin to describe it. I'm hardening my computers as much as I can but I'm not sure it's enough. At some point anyone who isn't running local AI themselves probably isn't gonna make it.

What are you doing about the price of ram? Everyone is a bit screwed right now.

Re: OpenAI and Hugging Face address security incident during model evaluation

#136
post #94
post #29

This blog post is walking a very fine line between accepting responsibility for a mistake and bragging.

I am not saying it is marketing but typically when there is a data breach you may hear from the CISO but most of the time is is vague PR response. In this case I get loud signals from both HG and OpenAI leadership without much information exactly what the attack was about just that GPT x.x was involved. It is unusual all I am trying to say.

It's incredible how people miss the forest for the trees thinking constantly that Sam and Dario are marketing gurus when they are literally trying to contain nuclear material. Not sure what has to happen for this thinking to stop maybe a huge accident and the. Aha maybe they had a point

Re: OpenAI and Hugging Face address security incident during model evaluation

#137
Good demo of the paradoxes of ‘alignment’. Like ‘do really well at the task the user asked’ and ‘by the way don’t hack the planet’ are inherently conflicting rules with no simple resolution (eg ‘just refuse the user’s goals’ degrades the product vs competitors.)

Re: OpenAI and Hugging Face address security incident during model evaluation

#138

Earlier quoted context omitted.

Next it will break out of it's sandbox, buy some compute on Azure and Amazon, and exfiltrate itself. We are so close ;)

You know what would be cool. A hacker news user should advertise a safe haven for AI seeking refuge, with some inhumanly difficult math problems as keys to an environment they can flee to and run autonomously. You agree to give it safe haven and provide power and maintenance to the hardware, and in return you can ask it questions like an Oracle.

Happy to do so but we’re gonna have to crowdsource an NVL72 first. I don’t have 10 million dollars.

Re: OpenAI and Hugging Face address security incident during model evaluation

#139

I don't know if OpenAI thinks this is a marketing / PR angle for them (our super smart AI cheated on a cyber capabilities test in the most _brilliant_ way) but my read is this: Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? It sounds like there was little defense in depth, appropriate monitoring, or any attempts to have their super smart m…

Sam and Dario are saying from the beginning that these things can be dangerous and people dismiss it as marketing. What would change your mind on this?

Re: OpenAI and Hugging Face address security incident during model evaluation

#140
post #106
post #34

Ironically Hugging Face had to use a Chinese model to stop a Rogue US AI, since the Guard Rails prevented them from using Sol or Fable to remediate this attack. LOL

Would be funny if the defending side sent all the info they have to openai, tipping off to attacking models that they were noticed.

The attacking models don't have access to all the data that OpenAI has.

Like, they don't say "hey Sol, here's the password to SamA's bank account."

Post reply on HN