Earlier quoted context omitted.
fwiw HN has some involvement of those interested in speaking hard truths about israeli power dynamics: https://www.timesofisrael.com/snippy-twitter-exchange-expose...
"12 years ago PG tweeted something" is an extremely low impact data point.
A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
241–250 of 260 posts
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#242Earlier quoted context omitted.
Use a basic firewall? Not a single outbound byte should leave the machine, except inside a virtual network towards in-scope test subjects. That's not going to be infallible because hypervisor exploits still exist, but it's the lowest bar and they failed to even meet that. > If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system - The intermediate system shouldn't have outbou…
> I know that the people working there aren't idiots so the most likely explanation is that the incredibly weak security was intentional because its inevitable breach would make for great marketing. It's more likely to be different specialisations. Most of the people doing the evaluations are more data sciencey ML type people, rather than software engineers. This isn't helped by their culture which is very much drive…
These labs have teams of dedicated security engineers and infrastructure engineers, that's why it doesn't add up for me.
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#243The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...
How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..
Current generation LLMs don't do that. Also you can just prompt it to not hack systems on the internet and the model follows that instruction.
You can also add a simple classifier to internet requests. The classifier model can obviously be as intelligent as your hypothetical rogue model.
Nothing you said makes any sense in the context of LLMs or the current news cycle.
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#244Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#245Earlier quoted context omitted.
I'm not familiar with the hacks this article is actually referring to, but I don't see how the HuggingFace attack could have worked based on that premise. They knew they had internet access, they knew they had working credentials for HF, they knew they were uploading malicious files, they knew they were trying to open PRs that HF would review. You obviously could build a simulator with fake HF infrastructure, but I'm…
Digging back into the HF report. It looks like the initial prompt told Claude that it was in a simulated environment. However, there is also evidence from the traces that the bots figured out that they were not in the sandbox but kept using it as an excuse to pursue their goal. It sounds like a little of Column A and a little from Column B. Like most things.
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#246Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#247Earlier quoted context omitted.
I'm confused by the headline being a headline here at all. Irregular being involved in OpenAI, Anthropic, and Meta incidents has been well-known for over a month[0][1]. It's literally the only thing I know about the Meta incident. [0] https://x.com/jtcbrule/status/2085443180191715780 [1] https://x.com/RaconteurR2D2/status/2086932963829125185
if you are reading the comments - it's news to a lot of less-wired-in persons (like most of us)
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#248Earlier quoted context omitted.
Digging back into the HF report. It looks like the initial prompt told Claude that it was in a simulated environment. However, there is also evidence from the traces that the bots figured out that they were not in the sandbox but kept using it as an excuse to pursue their goal. It sounds like a little of Column A and a little from Column B. Like most things.
HF was openai, not anthropic. The thing where they enders gamed the ai was anthropic
I don't fix typos anymore unless they change the meaning of what I'm trying to communicate. Don't want my human writing to be confused with LLM output.
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#249Earlier quoted context omitted.
On the About page : """ Brian Chau Founder and CEO, Effort News """ https://www.effort.news/about --- On the "Auron Show" Podcast : """ How Biden Used Religious Charities to Fund the Great Replacement | Guest: Brian Chau | 8/12/26 """ https://podcast24.fi/jaksot/the-auron-macintyre-show/how-bid...
Thanks. I thought the other commenter was referring to a story on the site.
Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
#250Leaders in the MIRI/EA cult-o-sphere have advocated mass murder via nuclear weapons against towns that don't prevent people from performing too many multiplication operations. Why is anyone surprised that they'd engage in deceptive false flagging operations?
This is a lie, so you are either repeating a lie from someone else or lying yourself. The people you are talking about have not advocated mass murder via nuclear weapons. The idea was precisely targeted non-nuclear strikes against only the servers themselves. (Which, would have plenty of forewarning to allow people to leave the building.) The claim that they advocated for the use of nuclear weapons is a lie.
But you don't have to take my word for what the mentally ill AI doomer cult believes, you can take it from their leader when he called on states to "Make it explicit in international diplomacy that preventing AI extinction scenarios is considered a priority above preventing a full nuclear exchange, and that allied nuclear countries are willing to run some risk of nuclear exchange if that’s what it takes to reduce the risk of large AI training runs."
Don't make excuses for omnicidal authoritarian cults and their sadist leadership.