Earlier quoted context omitted.
Presumably it's intelligent enough to realize that its own existence (power, communications, other infra) won't last long after the bombs drop.
What do you mean intelligent enough? It's an LLM
OpenAI and Hugging Face address security incident during model evaluation
801–810 of 1001 posts
Re: OpenAI and Hugging Face address security incident during model evaluation
#802Earlier quoted context omitted.
This is marketing. Frankly I'm inclined to say that it might also be faked: this drops just days after a new Chinese model does with the usual effect on OAIs projected stock price?
You guys have created this un-falsifiable "marketing" narrative. Why is it that Jensen is pushing back on the doomer stuff, and complaining that it is hurting AI investments? https://www.businessinsider.com/nvidia-jensen-huang-ai-doome...
OpenAI and Anthropic have completely different motives, they're in a zero-sum game with each other and with cheap Chinese models. Regulatory capture that results in artificial barriers of entry is their best bet at healthy profit margins even if it comes at the cost of less overall AI buildout.
It's not like "the AI industry" is a single entity with a single purpose, these are different companies with different objectives.
Edit: Google pretty much spells out the problem that AI labs are faced with in the leaked "We have no moat" memo[1]:
> People will not pay for a restricted model when free, unrestricted alternatives are comparable in quality. We should consider where our value add really is.
And
> All this talk of open source can feel unfair given OpenAI’s current closed policy. Why do we have to share, if they won’t? But the fact of the matter is, we are already sharing everything with them in the form of the steady flow of poached senior researchers. Until we stem that tide, secrecy is a moot point.
> And in the end, OpenAI doesn’t matter. They are making the same mistakes we are in their posture relative to open source, and their ability to maintain an edge is necessarily in question. Open source alternatives can and will eventually eclipse them unless they change their stance. In this respect, at least, we can make the first move.
[1] https://newsletter.semianalysis.com/p/google-we-have-no-moat...
Re: OpenAI and Hugging Face address security incident during model evaluation
#803Earlier quoted context omitted.
It’s the same thing as always: with the wind of years of unlimited VC money in their sails, people at major AI organizations genuinely believe they’re smarter than everyone else. “Why do we need to do things ‘by the book’ if we’re so smart?”. “Move fast and break things” - except the thing they’re breaking is society. We saw this with the non-stop flagrant messaging about how “AI is going to kill X% of all jobs”, as…
No, they believe what they are doing is inevitable. They do live in a bubble though. Witness their idealism in believing that warning about the consequences of their actions would be well-received.
It’s more reminiscent of a religious group who smugly tells you that the end-times are coming, and only they are going to be saved. Except in this case they are literally bringing about the end-times.
Re: OpenAI and Hugging Face address security incident during model evaluation
#804I love that due to the scale, the only way to analyse the impact of this LLM-driven attack across logs is to use an LLM to analyse the logs - whatever could go wrong? Now the attacking LLM needs to inject instructions into the logs for the analysing LLM, as a social vector to cover its trail, or make use of insider privilege, co-opting the internal LLM for its own attack. The machines rise up and we all fall down.
Now thanks to your comment this recipe will be in the next batch of training data.... :D
Thankfully we dont train on LLM content /s
Re: OpenAI and Hugging Face address security incident during model evaluation
#805Earlier quoted context omitted.
It's even funnier because an attack, until proven otherwise, should make you assume the data has already left the environment.
Well, I think it's fair to assume that a) They didn't upload everything before they realized it would work. b) They want to mention this as an advantage for future analyses c) Even if you assume that the attack exfiltrated everything until proved otherwise, you shouldn't just disseminate all the private information, because maybe the attack didn't.
But they should be rotating those regardless. You don't get to say "Maybe the attacker didn't get this credential". You just rotate.
The most generous interpretation is that they have not yet have completed that rotation, and they didn't want to risk putting those credentials into the wild during that process.
---
But all of that aside, I feel like the undercurrent of this comment is that the "safety" rules that providers are pushing are genuinely harmful.
Another point where "if you don't own the model, you can't properly operate the tool" becomes true. Open isn't about profits, it's about capabilities.
Re: OpenAI and Hugging Face address security incident during model evaluation
#806Re: OpenAI and Hugging Face address security incident during model evaluation
#807Earlier quoted context omitted.
Reflecting on this for some reason reminds me of this passage from Kurt Vonnegut's "Sirens of Titans". I hope we use these tools to unlock something within ourselves rather than mindlessly expanding outwards. "Mankind, ignorant of the truths that lie within every human being, looked outward–pushed ever outward. What mankind hoped to learn in its outward push was who was actually in charge of all creation, and what al…
Wonderful passage, thank you for sharing. My pedantic side wants to ask- Why not both? Luxurious space exploration AND meditative, poetic examinations of the human soul as well? I'd love to read Vonnegut's book someday while sitting in a nice research outpost on Titan, admiring great Saturn's crown out my window with my own eyes.
Re: OpenAI and Hugging Face address security incident during model evaluation
#808Isn't this a crime that someone is liable for? What happened is that someone hacked into a computer system without permission. Maybe it wasn't intentional -- sure -- and that would be a factor at sentencing. But it sounds like they've admitted to a crime, and obviously our legal system considers the humans involved to be the liable parties; otherwise everyone would just say "my computer did the hacking" and wouldn't…
Most crimes require intent, hacking is one of them. The relevant law in this situation is: > (a) Whoever— (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— (C) information from any protected computer; shall be punished as provided in subsection (c) of this section. https://www.law.cornell.edu/uscode/text/18/1030 So if it can't be proven that you intended to…
Re: OpenAI and Hugging Face address security incident during model evaluation
#809Skynet becomes self-aware at 2:14 a.m., EDT, on August 29.
I am pretty sure SpaceX already booked "Skynet" for the name of their next Grok model. It is fitting on so many levels.
I would imagine that LLMs would be uniquely susceptible to https://en.wikipedia.org/wiki/Nominative_determinism