Live data from Hacker News

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

effort.news

231–240 of 260 posts

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#231

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

Use a basic firewall? Not a single outbound byte should leave the machine, except inside a virtual network towards in-scope test subjects. That's not going to be infallible because hypervisor exploits still exist, but it's the lowest bar and they failed to even meet that.

> If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system

- The intermediate system shouldn't have outbound access to the internet

- You should ideally be using a proxy that filters the set of endpoints that clients are allowed to access to reduce the exposed surface area.

It's odd to find out that I use a higher level of isolation in my unimportant home network to stop IOT devices from doing funny things to HomeAssistant than big AI labs use to keep their possibly-world-ending AIs contained.

I know that the people working there aren't idiots so the most likely explanation is that the incredibly weak security was intentional because its inevitable breach would make for great marketing.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#233

Earlier quoted context omitted.

Air gap?

There has to be a route to where the LLM is running, and if there's a route for that there's probably a way for the machine to use it to route traffic somewhere else.

There doesn't have to be. You can easily block all outbound traffic, or the VM can exist without any network interface at all - you can control it through its host using a serial console.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#234
post #230

Earlier quoted context omitted.

Was that a real title, or are you referring to “The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups”?

On the About page : """ Brian Chau Founder and CEO, Effort News """ https://www.effort.news/about --- On the "Auron Show" Podcast : """ How Biden Used Religious Charities to Fund the Great Replacement | Guest: Brian Chau | 8/12/26 """ https://podcast24.fi/jaksot/the-auron-macintyre-show/how-bid...

Thanks. I thought the other commenter was referring to a story on the site.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#235

Earlier quoted context omitted.

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

Use a basic firewall? Not a single outbound byte should leave the machine, except inside a virtual network towards in-scope test subjects. That's not going to be infallible because hypervisor exploits still exist, but it's the lowest bar and they failed to even meet that. > If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system - The intermediate system shouldn't have outbou…

> I know that the people working there aren't idiots so the most likely explanation is that the incredibly weak security was intentional because its inevitable breach would make for great marketing.

It's more likely to be different specialisations. Most of the people doing the evaluations are more data sciencey ML type people, rather than software engineers. This isn't helped by their culture which is very much driven towards alignment as the only possible solution to super-intelligence (which may be true, but I have my doubts that this will happen in any reasonable time frame).

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#236

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

This really misses the forest for the trees.

The point is that a single company is making a deliberate effort to create a false impression about a technology which is now a key part of the US economy.

This is equivalent to overt stock market manipulation.

The technological aspects are much less important than knowing it’s the result of a single company.

That the company is Israeli and likely has ties to that government is just another layer of alarms - given that countries existential reliance on US aid which requires ongoing leverage to apply to US governments.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#237
post #133
post #100

Earlier quoted context omitted.

We really need a better board for talking about this stuff on.

fwiw HN has some involvement of those interested in speaking hard truths about israeli power dynamics: https://www.timesofisrael.com/snippy-twitter-exchange-expose...

"12 years ago PG tweeted something" is an extremely low impact data point.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#238

Why was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.

Probably because the site promotes far-right agendas.

[deleted]

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#239

Earlier quoted context omitted.

Is it really that impossible to believe that these might be real? I enjoy a good conspiracy theory as much as anyone, but "they committed a bunch of felonies and then publicly admitted to them in order to look good " just makes 0 sense. Where are these mythical people who admire companies more when they commit felonies? I haven't seen them…

>Where are these mythical people who admire companies more when they commit felonies? everywhere, I talked to a Palantir guy once and he said "every time someone paints us as a Bond Villain the stock prices go up", have you already forgotten how Cambridge Analytica marketed itself to clients?

Palantir markets to governments. OpenAI and Anthropic aim to get ordinary people to purchase their services, too

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#240
post #100

Earlier quoted context omitted.

We really need a better board for talking about this stuff on.

I sent an email to dang about the problem of people flagging comments just because they disagree. I think he's unaware that it is such a severe problem. I've been collecting a list of example comments to send him. I think if an account is frequently flagging comments which get vouched by others, that is a red flag for ideological flagging and they need to have their flagging ability reviewed.

It should be changed so flagged comments are still viewable, just hidden. This would somewhat counteract the disagreement flagging. Maybe show who flagged too.
Post reply on HN