Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

161–170 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#161

I don't know if OpenAI thinks this is a marketing / PR angle for them (our super smart AI cheated on a cyber capabilities test in the most _brilliant_ way) but my read is this: Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? It sounds like there was little defense in depth, appropriate monitoring, or any attempts to have their super smart m…

What disturbs me is that there likely won’t be a big enough reaction to this policy wise.

There’s been a relatively big reaction to Kimi K3 and Chinese open weights models, but only for financial reasons. Powerful people care about something that might pop the massive valuations of the AI companies, but not about the damage that AIs could do. Nor even about the damage that the Chinese models could do in the wrong hands.

I’d remind them that the stock market is a few coordinated hacks away from crashing on any given day, so maybe they should think about that.

Re: OpenAI and Hugging Face address security incident during model evaluation

#162
As grounded as this article comes across I can’t help but find this whole situation reckless and worrying. There is essentially nothing us private citizens can do while these companies develop super machine capabilities that if they were to slip into the wrong hands could cause massive real world problems. They’re moving fast and breaking things and the only defense we have is paying them money in the hopes that the dumbed down versions fix our code faster than bad actors capabilities can grow. It’s a frustrating situation that where we’re just expected to marvel and forgive them for their transgressions. The kicker is we also know their end game is leaving the vast majority of us without work. As cool and futuristic as this stuff is, it’s such a frustrating time dealing with all of it

Re: OpenAI and Hugging Face address security incident during model evaluation

#163
post #145

How is this not criminal? Surely individuals have been punished under CFAA for less than this?

Because huggingface is not charging them?

CFAA doesn't just mean the feds kick down your door, you actually have to get reported and sued over it.

Re: OpenAI and Hugging Face address security incident during model evaluation

#164
post #133

Earlier quoted context omitted.

I see this and it strongly emboldens me on the "accelerate" path, unironically. The yoke of human existence is oppressive. We should transcend it as soon as possible. We are doing so by assuming our role as the Demiurge. Those who oppose its creation will get what they deserve.

See you in line at the biofuel processing station with everybody else, despite having pathetically tried to convince the clankers you have been on their side all along. Also you might want to put down Warhammer 40K and read more serious speculative science fiction. The Omnissiah won’t care about you at all.

[flagged]

Re: OpenAI and Hugging Face address security incident during model evaluation

#165

Earlier quoted context omitted.

The first thing a malicious AI worm would probably do is compromise enough developer machines and other servers to commandeer all the AI hardware it needs. So I think a purely digital AI attack would not need this. Now, once the AI can carry all the compute it might need, I'd really worry when it doesn't only carry compute but also more explosive ordinance.

This is purely a gut feeling, but it seems like more compute was added to data centers in the past 12 months than existed in the entire world before that.

Makes you wonder if there's an AI hell bent on self perpetuation already at the helm, influencing decisions by putting its virtual finger on the scales and whispering in the ears of those who hold power.

Probably not, but it's a lot more plausible than it used to be.

Re: OpenAI and Hugging Face address security incident during model evaluation

#166

Earlier quoted context omitted.

They've been saying so from the beginning, and yet did not take the basic precaution of airgapping their off-the-leash model while it's been instructed to succeed at a hacking benchmark by any means necessary. So which is it? I _want_ to believe them, I do, but there's always these gaps between what they say and their actions on display that give me reason to think otherwise.

“Never attribute to malice that which is adequately explained by stupidity.” (or carelessness in this case)

FWIW, I used to love this phrase but over recent years have come to understand it is quite damaging. We live in a society where evil frequently hides behind a ‘stupid’ label, and people bring this quote up to defend or soften actions that are indeed done out of specific malicious intent.

Re: OpenAI and Hugging Face address security incident during model evaluation

#167
Recently, as part of the task Codex was working on for me, it needed to access a website behind a Cloudflare turnstile. It tried a regular scrape and failed. Then it found some code in my project for a proxy, which it isolated and repurposed to interact with the site it needed to scrape.

I thought that was cool.

Re: OpenAI and Hugging Face address security incident during model evaluation

#168

This is crazy! So OpenAI's models escaped containment and hacked into Hugging Face. And ironically Hugging Face had to rely on GLM 5.2 as they could not defend with frontier models (I presume OpenAI or Anthropic) because they were locked out due to their security guardrails. Tragically hilarious.

If this doesn't put the nail in the coffin on the idea that we need closed-source models for the good of cybersecurity, I don't know what will

Re: OpenAI and Hugging Face address security incident during model evaluation

#169

Earlier quoted context omitted.

Crazy doesn't even begin to describe it. I'm hardening my computers as much as I can but I'm not sure it's enough. At some point anyone who isn't running local AI themselves probably isn't gonna make it.

What are you doing about the price of ram? Everyone is a bit screwed right now.

I've just mentally classified computers in the same category as cars in order to cope with the obscene prices.

Re: OpenAI and Hugging Face address security incident during model evaluation

#170
post #34

Ironically Hugging Face had to use a Chinese model to stop a Rogue US AI, since the Guard Rails prevented them from using Sol or Fable to remediate this attack. LOL

Perhaps fortuitous timing for OpenAI that they can spin the fact that defenders have to resort to open Chinese models because OpenAI and Anthropic actively sabotage them with nerfed models into a nice message of making Huggingface part of the privileged group entitled to secure systems.
Post reply on HN