Live data from Hacker News

Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

jfrog.com

21–30 of 40 posts

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#21
post #15
post #13

Earlier quoted context omitted.

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.

[dead]

This seems unlikely as it would mean JFrog knew the vulnerability before OpenAI, which this blog posts clearly says the opposite

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#22
post #19
post #16

Earlier quoted context omitted.

I don’t see how it can’t be both. Yes, it is a felony, unarguably, but it’s also a first of its kind and I’ll be very interested in who law enforcement prosecutes and what the judiciary says about this. Almost everything is a precedent here except ‘somebody got hacked’.

If someone invents a new weapon to hurt someone, is the first inflicted injury unprecedented?

Intent is a major part of a crime severity, and it's hard to attribute intent to OpenAI here

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#23
post #16
post #9

The part I find the strangest in that whole affair is the way OpenAI is framing a felony (their systems accessed other company servers and exfiltrated private data, for multiple days, by exploiting vulnerabilities) as a successful partnership with jfrog and huggingface. Aren’t we now in a situation where a large AI vendor can engineer a similar situation against another corporation, then if caught committing a crime,…

I don’t see how it can’t be both. Yes, it is a felony, unarguably, but it’s also a first of its kind and I’ll be very interested in who law enforcement prosecutes and what the judiciary says about this. Almost everything is a precedent here except ‘somebody got hacked’.

White-hat hackers go to prison for running a scanner on a website and reporting the found vulnerabilities to the website owner without exploiting them. I don't see why this should be any different.

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#24
post #9

The part I find the strangest in that whole affair is the way OpenAI is framing a felony (their systems accessed other company servers and exfiltrated private data, for multiple days, by exploiting vulnerabilities) as a successful partnership with jfrog and huggingface. Aren’t we now in a situation where a large AI vendor can engineer a similar situation against another corporation, then if caught committing a crime,…

They also did felony copyright infringement many times over. Seems we're all rediscovering the iron law of politics: the only rule is that the most powerful people make the rules.

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#25
post #13
post #7

What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification. https://www.youtube.com/watch?v=q2KCrmQz9WE

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.

Are you suggesting issue should've been resolved *after* it was made public?

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#26
post #10

The JFrog article is so sweaty...sort of "actually this is _good_ news". This whole mess points to the fundamental problem of running critical infrastructural services on open networks, and hoping that keeps you safe. Just don't.

Right. There are a few projects that can be generally trusted with internet exposure - like OpenSSH, Wireguard, nginx/Apache. Most other stuff should be kept behind some kind of firewall because it is just too likely to contain a serious vulnerability.

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#27
post #13

Earlier quoted context omitted.

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.

Are you suggesting issue should've been resolved *after* it was made public?

I'm suggesting that you can't release a fix for an issue that hasn't been reported to you yet.

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#28
post #2

So they are the proxy in the hugging face hacking incident? Way to bury that lede.

My guess is someone was going to release a very unflattering article about them so they tried to get ahead of it by doing this

Yeah. But it's 10 paragraphs of AI nonsense that barely mentions the actual story.

Who could have thought this was a good idea? It literally reads like "ai security is important, btw we're the reason hugging face got hacked, we're awesome at securing things"

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#29
post #22
post #19

Earlier quoted context omitted.

If someone invents a new weapon to hurt someone, is the first inflicted injury unprecedented?

Intent is a major part of a crime severity, and it's hard to attribute intent to OpenAI here

The intent is something that has to be determined as part of the investigation and following judgement. But will we see an actual investigation by law enforcement?

Re: Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

#30
post #16

Earlier quoted context omitted.

I don’t see how it can’t be both. Yes, it is a felony, unarguably, but it’s also a first of its kind and I’ll be very interested in who law enforcement prosecutes and what the judiciary says about this. Almost everything is a precedent here except ‘somebody got hacked’.

White-hat hackers go to prison for running a scanner on a website and reporting the found vulnerabilities to the website owner without exploiting them. I don't see why this should be any different.

It's different since there was no single physical person who executed the hack or even asked for it. Intent is the difference between manslaughter and murder and we couldn't technically in any reasonable way commit an accidental hack into a computer system before approximately last month (or last quarter if we consider Mythos previews to be capable of this.)
Post reply on HN