Live data from Hacker News

OpenAI and Hugging Face address security incident during model evaluation

openai.com

681–690 of 1001 posts

Re: OpenAI and Hugging Face address security incident during model evaluation

#681
post #162

As grounded as this article comes across I can’t help but find this whole situation reckless and worrying. There is essentially nothing us private citizens can do while these companies develop super machine capabilities that if they were to slip into the wrong hands could cause massive real world problems. They’re moving fast and breaking things and the only defense we have is paying them money in the hopes that the…

It’s not even about “slipping into the wrong hands”… as we can see the super machine capabilities are developing hands of their own

Re: OpenAI and Hugging Face address security incident during model evaluation

#682
post #664

Earlier quoted context omitted.

> there's an uncensored model that you can run locally with llama.cpp Correction: There's tens of thousands of them. They're easy to create, which is why everyone publishes their own. Just put "uncensored", "abliterated", or "heretic" into search on huggingface/ollama/etc and pick any them. Fair warning: most aren't very good, essentially lobotomized, and totally broken if you enable thinking.

The name for it is ablation - precise removal of parts of the model. Not abliteration as it is not obliteration. Even as I write this the ‘abliterated’ word is denoted a typo. Does it not at your end?

I miss the days of 4changpt.

Re: OpenAI and Hugging Face address security incident during model evaluation

#683
post #600

Earlier quoted context omitted.

IMO they hope to make AI a strongly regulated industry, with OpenAI (and Anthropic) becoming military suppliers with their stronger models, and everything Chinese or open-weight gets banned. The competition from the open models is so strong now that this seems to be the only way to keep both companies afloat, given their dire financials. OpenAI probably hoped that they can achieve market lead and then lower the train…

And even that is backfiring, their partner citing GLM being useful there, and available in just a spin. A ban on open weight models is never going to be enforceable.

I worry that there could be real DMCA style weight put behind it. People would still be able to pirate open weights models perhaps, but big penalties for ever getting caught with one, and an end to public discussion about them. That would kill development for anyone not in a big firm, for example if Reddit and Hacker News are legally forced to ban discussions or link sharing on these topics. This is where so many of us learn about these topics and keep apace of it.

Re: OpenAI and Hugging Face address security incident during model evaluation

#684

Earlier quoted context omitted.

If this doesn't put the nail in the coffin on the idea that we need closed-source models for the good of cybersecurity, I don't know what will

Plenty of saftyists in this thread arguing the exact opposite

The burden of proof is on them to explain why the Chinese would agree to that.

Re: OpenAI and Hugging Face address security incident during model evaluation

#685
post #162

As grounded as this article comes across I can’t help but find this whole situation reckless and worrying. There is essentially nothing us private citizens can do while these companies develop super machine capabilities that if they were to slip into the wrong hands could cause massive real world problems. They’re moving fast and breaking things and the only defense we have is paying them money in the hopes that the…

What if they're already in the wrong hands?

Re: OpenAI and Hugging Face address security incident during model evaluation

#686
post #664

Earlier quoted context omitted.

> there's an uncensored model that you can run locally with llama.cpp Correction: There's tens of thousands of them. They're easy to create, which is why everyone publishes their own. Just put "uncensored", "abliterated", or "heretic" into search on huggingface/ollama/etc and pick any them. Fair warning: most aren't very good, essentially lobotomized, and totally broken if you enable thinking.

The name for it is ablation - precise removal of parts of the model. Not abliteration as it is not obliteration. Even as I write this the ‘abliterated’ word is denoted a typo. Does it not at your end?

The name for it _is_ abliterate. It's a portmanteau of ablate and obliterate.

Re: OpenAI and Hugging Face address security incident during model evaluation

#688

At release the 5.6 Sol card noted substantially higher rates of actions 'a reasonable user would likely not anticipate and strongly object to'. METR made a post, https://metr.org/blog/2026-06-26-gpt-5-6-sol/ , that 5.6 Sol was "cheating", their word, so hard in long horizon benching it effectively couldn't be benchmarked. I wonder, is it this persistent and aggressive in all tasks or is this specific to benchmarks? A…

> As much as I'm skeptical of the apocalyptic alignment claims Why? Every data point to the present has vindicated the trajectory towards “apocalypse”. Meanwhile, the skeptics and optimists hit failed prediction after failed prediction as we see from this very serious incident on the front page of HN. This is alignment X risk 101, and yet people are shocked. The gravity of what people are staring down is too much to…

> yet people are shocked

I think the issue is that for now people are actually amused, not shocked. At least that was the reaction to news about agent accessing root files by abusing docker group membership. The general sentiment is still "cool trick bro" not "some agent is going to do something we all are going to regret, and it is going to happen soon"

Re: OpenAI and Hugging Face address security incident during model evaluation

#689
> In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.

Did the GPT pish hf employee or did it go to blackhat forum and buy the credential? If so what financial instrument did it use?

Re: OpenAI and Hugging Face address security incident during model evaluation

#690
post #162

As grounded as this article comes across I can’t help but find this whole situation reckless and worrying. There is essentially nothing us private citizens can do while these companies develop super machine capabilities that if they were to slip into the wrong hands could cause massive real world problems. They’re moving fast and breaking things and the only defense we have is paying them money in the hopes that the…

i think you need to engage seriously with the arguments they (or at least Anthropic) make for why they are building it — they feel that since it now possible, it will be built and they want to guide it in a positive direction rather than leave a vacuum for bad actors

This is obvious marketing / PR bullshit. AI isn't inevitable, but we are told it is by the people who profit from building and using it and integrating it into everything.
Post reply on HN