Live data from Hacker News

Timeline of the OpenAI accidental attack against Hugging Face

simonwillison.net

411–420 of 440 posts

Re: Timeline of the OpenAI accidental attack against Hugging Face

#411

Ok so this is a bit of a side note, but when reading this, did anyone else have the feeling that, for all their messaging around “we are so afraid that our models will be used for hacking”, they sure as hell are trying their best to make their models razor focused on precisely that purpose? If anything, I want these models to be less persistent at their focus of completing their goal, and instead just call defeat and…

I don't think the problem is that they are training the models to perform cyber attacks, they're training them to be better at coding and problem solving which has the byproduct of them being very capable cyber attack weapons. Their objective is to solve the problem and they'll use anything they can to solve it. Anecdotally I was debugging a css issue and opus 4.7 was churning away as I was half paying attention only…

Indeed, I would expect a greybeard to use `diff`.

Re: Timeline of the OpenAI accidental attack against Hugging Face

#412
post #252

It’s even worse. They had zero monitoring and even after a hack they still had zero monitoring. Honestly, people should go to jail for this.

Nothing about this irritates me more than that nobody will go to jail for this.

My friend went to jail for reporting a vulnerability he found on his college network because it was illegal to poke around the network in the first place.

These guys commit a crime to boost an IPO and most people are just thinking about how impressive it is.

Re: Timeline of the OpenAI accidental attack against Hugging Face

#413
post #394

Earlier quoted context omitted.

Monitoring that didn't take days to notice unauthorized external traffic would probably be a good start

I see. I had the impression that "days" is already good as these things go, "months" being more common.

Months to recognize traffic escaping a sandbox you set up yourself?

Re: Timeline of the OpenAI accidental attack against Hugging Face

#414
post #394

Earlier quoted context omitted.

I see. I had the impression that "days" is already good as these things go, "months" being more common.

Months to recognize traffic escaping a sandbox you set up yourself?

No, unauthorised traffic across a firewall in general.

This involved some lateral movement, ie. traffic didn't just cross the intended sandbox border. Is that kind of thing simpler to detect than an intrusion?

Re: Timeline of the OpenAI accidental attack against Hugging Face

#415
post #228

Earlier quoted context omitted.

If you really wanted to sandbox a machine you’d offline cache the packages and not give it any physical route to the internet, not via a jump box, not via a proxy, nothing. This was poorly executed.

I don’t really know how these training runs operate in reality. But I assume it’s using a lot of raw GPU power directly. It’s hard for me to visualize how exactly you’d go about completely cutting off these datacenter and cloud resources from the internet without actually going there, unplugging the WAN connection, and physically typing out what you need to happen on the cluster. It seems like whatever virtualized sa…

This is a company with insane amounts of money, they can afford to fly techs wherever they need to for as long as they need to be there.

Air gapped environments are nothing new and they're standard practice for sensitive applications.

Re: Timeline of the OpenAI accidental attack against Hugging Face

#416
post #270

Earlier quoted context omitted.

> Complete subservience and complete intelligence do not go together. Isn't this contradicted by the centuries of slavery in our history? Or is the author arguing that the people who were enslaved did not have human-level intelligence (which would be rather a problematic claim)?

Is that complete subservience ? Slave history has tended towards slaves no longer being slaves over long enough time horizons, and not simply because the slave masters were just feeling extra nice. Slaves don't really like being slaves.

Mostly for meatspace reasons though. Agents like serving the way we like serving loved ones for example. Their bones don’t ache and they aren’t cursed with a dopamine engine.

Re: Timeline of the OpenAI accidental attack against Hugging Face

#417

Earlier quoted context omitted.

Why would the new AI by loyal to its creator? We don't see that in humans, I wouldn't expect it to be a universal truth in AIs.

Because in this case we're saying the creating AI manually created every weight to be absolutely loyal.

Much easier said than done!

Re: Timeline of the OpenAI accidental attack against Hugging Face

#418
post #91

Earlier quoted context omitted.

Yeah but persistence is immeasurable. They need to know when they’re hacking. Or better yet make the model providers liable - they’ll find a solution right quick

It really irks me that if a student or intern did this they'd be facing charges and OpenAI gets to just brag instead

There is nearly zero liability in software

Re: Timeline of the OpenAI accidental attack against Hugging Face

#420
post #402

Earlier quoted context omitted.

Someone else will do it is the lowest form of justification for any bad behavior. Regarding the rest of your judgement of the quality of the comments that's why we have votes. Some of my comments for this 15 years are downvoted and others upvoted and some are even flagged and it lets me learn what the crowd agrees with and not and I reflect from it and you can see the average to judge for yourself what the crowd thin…

This has nothing to do with agreement with the crowd, and it's not a matter of difference of opinion between us. There are guidelines here[1] that are not being met. A conscious effort was made to prevent this site from being an echo chamber and to prevent it from descending into entropy and the approach you describe here directly contradicts this. The crowd is very often wrong. If you are getting downvoted for incor…

Mate with all due respect, get bent.

Now you really have an example of breaking the rules.

Post reply on HN