Shame. One of the craziest hacking stories in history, yet only 38 points on HN.
The OpenAI–Hugging Face Incident [video]
21–23 of 23 posts
Re: The OpenAI–Hugging Face Incident [video]
#22Yeah, this is the frontier of "AI safety". Repeating myself, but this is purely embarrassing and discrediting.
Said it before, if they were serious, at the very least they would have no models sharing Artifactory. Run each model in their own hypervisor, network only with another hypervisor for each model wherein Artifactory runs for that model alone, thus, no message board (among other advantages), thus, far heightened requirements to actually escape and no coordination. But that requires a modicum of effort and OpenAI as a small, cash starved startup couldn't afford that. Alternatively, just pay attention to what your models write.
All that talk at the end about "Agentic SDLC", "automated defence", etc. are moot if we are talking about a team that sees models set up message boards and decides to not take a closer look afterwards. That's akin to talking about HSM, but letting anyone walk into your server room and just plug their pen drives in. Not without merit, but if you were honest, you'd have bigger fish to fry long before...
Re: The OpenAI–Hugging Face Incident [video]
#23Shame. One of the craziest hacking stories in history, yet only 38 points on HN.
I think it's a combination of (a) we've already been talking about this incident a lot across multiple threads and it's not immediately obvious that there's new information here and (b) HN is a primarily reading-based community so anything arriving via video will be less popular.