Live data from Hacker News

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

effort.news

111–120 of 260 posts

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#111
The Irregular post mortem comes down to lack of basic security controls

"Ultimately, most of the issues we’ve discovered were due to internet access controls."

That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that.

https://www.irregular.com/research/addressing-recent-inciden...

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#112

Earlier quoted context omitted.

I'm not familiar with the hacks this article is actually referring to, but I don't see how the HuggingFace attack could have worked based on that premise. They knew they had internet access, they knew they had working credentials for HF, they knew they were uploading malicious files, they knew they were trying to open PRs that HF would review. You obviously could build a simulator with fake HF infrastructure, but I'm…

Digging back into the HF report. It looks like the initial prompt told Claude that it was in a simulated environment. However, there is also evidence from the traces that the bots figured out that they were not in the sandbox but kept using it as an excuse to pursue their goal. It sounds like a little of Column A and a little from Column B. Like most things.

that it knew and ignored/forgot, sounds pretty typical agentic patterns

attention is all you need, but it's never enough

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#113

Earlier quoted context omitted.

Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. The model believing it was in a sandbox is why it behaved the way it did (against its normal alignment rules) ... at least that was my reading of the incidents. I have yet to see evidence that indicate it thought it was ok to do these hacks on the public network. I think most misalignment is 'Human…

> Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. As I've said before on this website, fool me once on this. If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed. Why is 'it thought it wasn't doing damage so it figured it might as well try to do damage' an acceptable sta…

red team humans do this every day, it's not the discrepancy that is the real issue, it's that they are unreliable and we will never know why it did because it has no intent

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#114
post #108
post #97

Earlier quoted context omitted.

I mean, I get your thought process and don't disagree. That said... Would it be an affirmative defense if we had a defendant who said "but your honor, I was told that when I hacked this system, I was operating in a sandbox. I had no idea that I actually had Internet access!" The frontier is spiky and all, but you have to suspend disbelief quite a bit to, on one hand, have a model that can produce a novel math theory,…

> Would it be an affirmative defense if we had a defendant who said [...] Maybe replace it with playing a sort of FPS game then learning you were, in fact, directing a real drone/robot.

I think you just recapitulated the plot of Ender's Game.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#115
Genuinely: what is with everyone saying “headline is misleading, none of this had to do with Hugging Face”, when nothing about the article makes any claims with regards to Hugging Face whatsoever? Is it supposed to be the article's (or headline's?) fault that you hallucinated additional context that was never there?

It's very strange seeing this take on this article being repeated here and elsewhere on the Internet.

I'm very sensitive to slanted reporting (regardless of the direction of the slant!)—and, hey, maybe my bullshit detector is broken or something, I dunno—but I've found effort.news reporting to be very even-handed, straightforward, well-sourced, and easy to read and parse so far!

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#116

Earlier quoted context omitted.

Maybe because the headline is misleading? (because there's no connection to the Hugging Face attack) That said, it's the second day and it's still on the front page.

Maybe the title was changed, but the current title does not reference a Hugging Face attack.

After reading the article, the title doesn't seem all that off and definitely nothing to be a pedant about.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#117

Why was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.

I'm confused by the headline being a headline here at all. Irregular being involved in OpenAI, Anthropic, and Meta incidents has been well-known for over a month[0][1]. It's literally the only thing I know about the Meta incident.

[0] https://x.com/jtcbrule/status/2085443180191715780

[1] https://x.com/RaconteurR2D2/status/2086932963829125185

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#120

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

[flagged]
Post reply on HN