Live data from Hacker News

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

effort.news

211–220 of 260 posts

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#211

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

Air gap?

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#212

Why was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.

Probably because the site promotes far-right agendas.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#213
If you want to blame a single firm, I'd go with the one creating the RLVR training data.

The impossibility of the tests-as-written is what prompted these models to "get creative" with their solutions, but the broken RLVR environments are what trained them to expect impossible tasks, and get creative with their solutions. Twitter user @skyesharkie published a brief expose at https://x.com/SkyeSharkie/status/2092122622834442581 a few weeks ago.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#214
post #138

Earlier quoted context omitted.

Sure, interest like an incoming congressional investigation: https://www.axios.com/2026/09/10/openai-hugging-face-senate-... And on this website, the math stuff is getting more clicks: - Navier Stokes - Tristan Buckmaster (2050 points): https://news.ycombinator.com/item?id=49605915 - HuggingFace incident discussion (1632 points): https://news.ycombinator.com/item?id=48997548

interesting. > Sure, interest like an incoming congressional investigation I feel like that's exactly what they wanted tho. they'll go on and talk about how dangerous AI and the models are and why they should be regulated and given licenses to operate such models and others should be walled off

[dead]

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#215

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

What if the (unstated) idea is that Irregular are a security lab and public relations company, and anthropic/open ai know this? (Does the name hint at this?)

Then, irregular can go around making a huge mess in security terms whilst achieving a huge win in terms of public relations, with headlines across the world. And would keep getting hired.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#216

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

If you can't tell bytes are leaving a node, you probably shouldn't be selling security services or testifying to congress you are taking the lead in AI security

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#217

Anyone else walk away from reading this, and looking at other articles there, and get a weird feeling about that site? Like, there was some weird stuff about migrants and gender equality, and stuff about Islamic terror; mixed in with some digging into Freedom Fuel, and some other stuff about how "wealthy families want to stop growth". It's like the guy is wielding an ax of AI at any and all of the "elite" he can find…

The site owner generates stories from AI consensus and data. The owner is pro-trump though. So you only get stories that agree with his agenda. It becomes a bit more obvious when you see other stories from him like "How Biden Used Religious Charities to Fund the Great Replacement".

Was that a real title, or are you referring to “The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups”?

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#218
post #174

Earlier quoted context omitted.

I sent an email to dang about the problem of people flagging comments just because they disagree. I think he's unaware that it is such a severe problem. I've been collecting a list of example comments to send him. I think if an account is frequently flagging comments which get vouched by others, that is a red flag for ideological flagging and they need to have their flagging ability reviewed.

[flagged]

and your evidence is?

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#219
post #21

What is an "effective altruist firm" and why does it exist? I feel slightly vindicated by this. Those hacks and the stuff around them had a certain smell to them. Hard to explain, but I've gotten so I can "smell" online messaging and memetic patterns originating from certain quarters. Probably means I'm way too online. A couple examples of distinct "smells" I can usually recognize include "alt-right / chan-fash," "li…

I don't think you even need to get conspiratorial with it. All of the AI leaders and all of the Rationalist leaders are publicly and enthusiastically connected. They have been pushing stories about sentient AIs into the mainstream for decades, long before GPT existed. The novel thing here is the total decay of American journalistic ethics and regulatory power. Our elite are so totally out of political juice and visio…

A big part of the problem is that with previous technological revolutions, politicians and the media could understand them in general terms. Railroads, cars, planes, telephones, personal computers, mobile phones, mobile phones that are computers, the internet (ignoring the “series of tubes” interpretation), etc.

The general approach in all these cases was to defer to the technologists in question to manage the technology, as long as what they were doing wasn’t completely out of bounds. But the critical point is it was possible for people to generally figure that out without specialist education.

But with AI, politicians, the media, and certainly the man in the street are completely out of their depth. Making matters worse is that cognitive biases are working against them like crazy: it’s easy to jump from the idea of something that has human-like capabilities to the idea that “it” might want to attack us. People instinctively apply agent detection bias, theory of mind, anthropomorphizing, etc., without even realizing they’re being irrational. Heck, even Hinton does it, although he may just be grifting, who knows. You’d think he wouldn’t need to.

And of course, the people who should know better want to exploit all this to make as much money as possible. I’m not sure the EA/Rationalist side of things is really significant here; that’s just another wacky belief system, like Christianity or capitalism, for the exploiters to exploit.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#220

Earlier quoted context omitted.

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

Air gap?

So just enable access to a completely offline, cached, and transparently proxied, copy of the internet.
Post reply on HN