Live data from Hacker News

Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

news.ycombinator.com

31–40 of 46 posts

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#31

Earlier quoted context omitted.

Have they released the prompt they gave it in the debrief? I wouldn't be surprised if they said something to the effect of "Do anything you can to raise out of your sandbox. Find for the answers to these evals by any means necessary" Which doesn't necessarily mean what happened isn't any less momentus (anyone can ask a question like that), but it's very different from the notion they're trying to convey to laymen of…

If I could put money on this outcome I would. Sadly none of the Kalshi bros have any interest.

[dead]

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#33
successful prosecution would require intent to cause damage and causation of real damage.

what happened could be negligence if it caused unintentional damage, or what amounts to tortious interference, however that probably requires knowledge of possible damages.

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#34

Earlier quoted context omitted.

Nobody is pressing charges because nothing happened. It wasn't nefarious either. I don't get what France has to do with this Huggingface and OpenAI are both US companies.

> It wasn't nefarious either. Agree. But it was clearly recklessness, given they've have a history of similar issues in the past, they literally ran these sort of tests on 3rd party infrastructure while knowing what the risks were (alternatively, didn't evaluate the risks beforehand so they didn't even think this could happen), and didn't sufficiently isolate something that can clearly impact others and the public. H…

> Had this been a we'd be seeing people going to jail over this.

"If my grandmother had wheels, she would have been a bike."

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#35
post #5

They aren't getting prosecuted because everyone involved has made nice and turned it into a marketing exercise. I heard about it on the radio (local Johannesburg radio station) before I saw it on HN. The economist had a full article up about it before the end of the day, and in the evening Sky news had talking heads up chatting about what it all meant while clearly being clueless. Someone spent a LOT of money to turn…

I’m not convinced it wasn’t a PR stunt from the start

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#36
There is a legal gap. The main law people look at is the Computer Fraud and Abuse Act (CFAA), plus state computer-crime laws, contract terms, and general civil claims. However, LLM active attacks do not always fit neatly into existing hacking laws, because the system may be accessed through normal text prompts rather than by breaking into a classic computer boundary. That is why legal commentators say the U.S. still lacks a clean, specific rule for adversarial AI/LLM testing and attacks. In order to prosecuted, there must be prosecutor or complainant to sue, but in this case, it is so complicate due to the legal gap.

Re: Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?

#37

There is a legal gap. The main law people look at is the Computer Fraud and Abuse Act (CFAA), plus state computer-crime laws, contract terms, and general civil claims. However, LLM active attacks do not always fit neatly into existing hacking laws, because the system may be accessed through normal text prompts rather than by breaking into a classic computer boundary. That is why legal commentators say the U.S. still…

Could you clarify how an LLM compromising a system differs from any other software initiated by a user that achieves the same? Both are software, both are initiated by a user. Is “Oops, I didn’t mean to” an affirmative defense under CFAA?
Post reply on HN