Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

841–850 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#842
post #475

Isn't this a crime that someone is liable for? What happened is that someone hacked into a computer system without permission. Maybe it wasn't intentional -- sure -- and that would be a factor at sentencing. But it sounds like they've admitted to a crime, and obviously our legal system considers the humans involved to be the liable parties; otherwise everyone would just say "my computer did the hacking" and wouldn't…

Presumably, without intent (based on sibling comments), the victims would need to sue for damages due to gross negligence.

Re: OpenAI and Hugging Face address security incident during model evaluation

#843

Earlier quoted context omitted.

Wonderful passage, thank you for sharing. My pedantic side wants to ask- Why not both? Luxurious space exploration AND meditative, poetic examinations of the human soul as well? I'd love to read Vonnegut's book someday while sitting in a nice research outpost on Titan, admiring great Saturn's crown out my window with my own eyes.

I think, those both are contradictory and completely occupy the bandwidth when engaged one way, it's mutually exclusive.

Really? You don't think astronauts and engineers get not only inspired by their work to make art, but inspired by art when they are working?

I'm like that. I see art exhibits which energize me and inspire me and give me ideas for technical things I want to build.

Re: OpenAI and Hugging Face address security incident during model evaluation

#844
The timing of this is so awfully strange.

However, this U.S. centric view of the future of AI is wild. If the U.S. prevents its businesses from using open-weight models, only those businesses will suffer, while the rest of the world flourishes with the access to cheap, good-enough, intelligence.

Multiple dollars per million input/output tokens was never sustainable for the majority of use-cases - hardly anybody outside the U.S. can afford that and many within it can’t. Models costing that much will find less reasons to be used over time, not more.

All the while their capabilities will continue to shift towards smaller and much cheaper models, at least until we hit some kind of true data limit with them

Re: OpenAI and Hugging Face address security incident during model evaluation

#845
HuggingFace has been extremely responsive when an issue is raised. I found issues in their infrastructure this year as well as cache confusion in Chrome, and HF fixed their CDN in a day and I didn’t hear back from Google for a week or two and could no longer show how to exploit Chrome as I figured HF infrastructure issues would drag on possibly forever.

Re: OpenAI and Hugging Face address security incident during model evaluation

#846

Earlier quoted context omitted.

It's computer Gain of Function research.

Gain of function research is not anywhere near as dangerous as the public believes. In the US, it was very convenient to blame it for the pandemic, even though SARS-CoV-2 is of natural origin and almost certainly spilled over at the Huanan wet market in Wuhan. The threat of viruses comes almost exclusively from nature, which is constantly cooking up new viruses all by itself and exposing people all over the world to…

I think your reply did a couple things:

* strengthened the point of the GoF comment

* pointed out how high-biocontainment is the key here, which obviously wasn't present in this case (and I'd say the vibes for AI research in general are that it's not high-containment)

* correctly argued that AI research is definitely worth doing and holy shit we need to work on alignment

Re: OpenAI and Hugging Face address security incident during model evaluation

#847

The timing of this is so awfully strange. However, this U.S. centric view of the future of AI is wild. If the U.S. prevents its businesses from using open-weight models, only those businesses will suffer, while the rest of the world flourishes with the access to cheap, good-enough, intelligence. Multiple dollars per million input/output tokens was never sustainable for the majority of use-cases - hardly anybody outsi…

My takeaway is that closed model providers are dangerous. OpenAI and Anthropic are more motivated than anyone to prove that models can be dangerous, and so they will make dangerous models. "Look how dangerous our models are!" No bro YOU are the danger.

Re: OpenAI and Hugging Face address security incident during model evaluation

#848

The timing of this is so awfully strange. However, this U.S. centric view of the future of AI is wild. If the U.S. prevents its businesses from using open-weight models, only those businesses will suffer, while the rest of the world flourishes with the access to cheap, good-enough, intelligence. Multiple dollars per million input/output tokens was never sustainable for the majority of use-cases - hardly anybody outsi…

We're going to see the battle intensify here because "spikes" of ASI are emerging that can't be ignored. Models are now better than humans in certain domains or for certain tasks, which means capital as a moat is being eroded. This is why you see people like Jamie Dimon sounding the alarm. Most of the talk until now has been about how the models would be a serious problem for labor, but if that was true how could it not also be an issue for capital?

Re: OpenAI and Hugging Face address security incident during model evaluation

#849
post #847

The timing of this is so awfully strange. However, this U.S. centric view of the future of AI is wild. If the U.S. prevents its businesses from using open-weight models, only those businesses will suffer, while the rest of the world flourishes with the access to cheap, good-enough, intelligence. Multiple dollars per million input/output tokens was never sustainable for the majority of use-cases - hardly anybody outsi…

My takeaway is that closed model providers are dangerous. OpenAI and Anthropic are more motivated than anyone to prove that models can be dangerous, and so they will make dangerous models. "Look how dangerous our models are!" No bro YOU are the danger.

More than one thing is allowed to be dangerous at a time.

Re: OpenAI and Hugging Face address security incident during model evaluation

#850

Earlier quoted context omitted.

It is pretty funny, because there is something here for everyone. People who don't believe in guardrails have a clear indicator as to why operators should have access to models that don't try to question their Daves. On the other, people, who think that if only we could align the models just a tiny lil bit better, none of this would have happened to begin with. Pure madness.

"if only we could align the models just a tiny lil bit better" is a rehashed "if only we could escape untrusted inputs just a tiny lil bit better" from 2000s, that were RIPE with various form of malicious injection. Every command+data channel in existence has been and will continue to be exploited one way or another, because the solution space is for all intents and purposes unbounded. Sure, highly defensive escaping…

it's the "just one more lane bro I swear" of AI
Post reply on HN