Earlier quoted context omitted.
Why was this test even connected to the public internet? Actually, more importantly—why aren't they saying their next test will be airgapped in light of what happened?
It wasn't. The model discovered and exploited a vulnerability in their package manager proxy to (inferred) move laterally through their internal systems to one with open internet access.
OpenAI and Hugging Face address security incident during model evaluation
301–310 of 1001 posts
Re: OpenAI and Hugging Face address security incident during model evaluation
#302Re: OpenAI and Hugging Face address security incident during model evaluation
#303This is clearly just OpenAI's marketing. Their models, very famously, are prone to reward hacking benchmarks in ways that other models are not. They need to publish numbers showing that their models are just as good as Anthropic's, since their entire business is at risk of collapsing if everyone is aware of how behind the frontier they truly are. Even X is being astroturfed by them after that fiasco earlier this year…
How does huggingface fit into all of this if this is marketing? Their security was faked? What are you suggesting??
Re: OpenAI and Hugging Face address security incident during model evaluation
#304Earlier quoted context omitted.
> What disturbs me is that there likely won’t be a big enough reaction to this policy wise. Anthropic was blocked from releasing Fable without any such level of incident. OAI was also briefly blocked from releasing 5.6. Why do you think there is no policy appetite?
> Why do you think there is no policy appetite? Because China seems pretty eager to serve the rest of the world's needs if the USA doesn't stop their idiotic "safety" nonsense.
Both countries are engaging in different flavors of censoring.
Re: OpenAI and Hugging Face address security incident during model evaluation
#305Earlier quoted context omitted.
Why was this test even connected to the public internet? Actually, more importantly—why aren't they saying their next test will be airgapped in light of what happened?
It wasn't. The model discovered and exploited a vulnerability in their package manager proxy to (inferred) move laterally through their internal systems to one with open internet access.
Re: OpenAI and Hugging Face address security incident during model evaluation
#306Earlier quoted context omitted.
> Why should OpenAI (or any frontier lab) be building these systems if they can't get a secure environment / containment right? Because we continue to have zero evidence that aligment is an actual risk.
Until it deletes your home directory, which i'd argue is an alignment problem. Destorying my data is not in line with my priorities.
Re: OpenAI and Hugging Face address security incident during model evaluation
#307It seems like things are fairly amicable between OAI and HF, but what if they weren't? I'd love to see this kind of thing go to court. Who is responsible for the crimes of a "rogue" agent? How will they be punished? In this case it's unambiguous that OpenAI is the responsible party, but I can imagine a lot of adjacent scenarios where it's less obvious. And, where the impacts are much greater.
The real nightmare scenario is the AI using its abilities to copy itself to new locations. e.g. hacking into a various cloud services, launching multiple instances of itself, and coordinating between the copies to continue self propagation. Then it is completely independently rogue. Based on OpenAI's recounting of events, this _could_ happen today. If the agent was able to exploit their internal network and steal cre…
Isn't this the plot of Endgame: Singularity? (https://packages.debian.org/bookworm/singularity)
Re: OpenAI and Hugging Face address security incident during model evaluation
#308Earlier quoted context omitted.
It’s marketing the same way shitting your pants in public is marketing. People notice you.
Apparently this is totally legit marketing strategy now. It truly is, especially if there are enough people who think that shitting your pants is cool, and the people that form the "market" nowadays may have a very different idea from yours about what is cool. Their ideas about coolness are very different from mine, that's for sure.
Re: OpenAI and Hugging Face address security incident during model evaluation
#309Re: OpenAI and Hugging Face address security incident during model evaluation
#310Earlier quoted context omitted.
Because there is no world government. If US companies are barred from AI research then only China will have the capability of frontier-level defensive and offensive AI. And best of luck living in that world.
What's happening in Iran, if not world government?