Live data from Hacker News

xAI dev leaks API key for private SpaceX, Tesla LLMs

krebsonsecurity.com

71–80 of 83 posts

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#71
post #19

Earlier quoted context omitted.

Is ITAR like other compliance sort of fields where you have to store data only in compliant places, or is it just based on actual leaks etc.,?

ITAR (International Trafficking in Arms Regulation) is paranoid . Every single specific person that knows even dual-use information, such as composite wing design, must be individually authorized. I’ve been asked to leave the room when my girlfriend, who works for a passenger aircraft manufacturer, was designing a repair for a plane I have literally flew on. It doesn’t matter how the person got access to dual-use inf…

That's the people aspect of it, but what about the technical aspect of it? Can I store ITAR restricted information in plaintext on a thumb drive if I think it's safe?

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#72
This has ruined many careers in the making. The DDOS attacks happened while this breach like hotspot was open. who do we contact if any of our studies are leaked out like a publicity stunt day in day out and the x.ai hasnt responded for months after stating concern and rogue like actions on different AI services. Do we post videos, make statements or just gather and share tips and insight?

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#73

> Fourrier found GitGuardian had alerted the xAI employee about the exposed API key nearly two months ago — on March 2. But as of April 30, when GitGuardian directly alerted xAI’s security team to the exposure, the key was still valid and usable. xAI told GitGuardian to report the matter through its bug bounty program at HackerOne, but just a few hours later the repository containing the API key was removed from GitH…

Contacted the support team, DOD and FBI... nothing done a month or two ago.. its sad. But when see that studies are now sci-fi flicks.. my heart broke a little while ago. Never mind that this was swept under the radar by the DDOS attacks. Classic Oceans15 movie in the making.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#74
post #11

SpaceX data LLM being exposed is likely a recipe for a huge ITAR violation

If there's actually any proprietary rockety data, maybe. Without knowing what data went into the fine-tune there's no way to tell. This could be a "internal procedures chatbot" or an "onboarding chatbot" where new people can ask where the coolest watercooler in the company is. In my experience post-training mainly deals with "how" the model displays whatever data ("knowledge") it spits out. Having it learn new data (…

you haven't seen the releases labeled as Groks new studies yet... Its pretty clear.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#76
post #67

Earlier quoted context omitted.

I think you missed a lot of the word play. Somebody else has explained Bore[1]-ing vs boring. But they sold a blowtorch aka not a flamethrower. The difference being a flamethrower actually "throws flames" like 10+ feet. [1]: https://en.wikipedia.org/wiki/Bore

I didn't miss anything in the wordplay*, it was obvious. (As are the initials, an extra pun). I put quotemarks around "flamethrower" because that's what it was originally sold as before obvious and predictable legal issues with real flamethrowers and the fact it was obviously mimicing the prop in Spaceballs. My point is: neither weed burners nor actual flamethrowers have anything to do with digging tunnels nor any ad…

Tesla sold a surfboard and whiskey and...

Just saying. It's kinda on brand by not being on brand because the whole network of companies... well I'm trying off topic.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#77
post #23

One thing that sticks out to me is that there is an incorrect assumption from the journalists that having the API keys to an LLM can lead to injecting data. People still don’t know how LLMs work and think they can be trained by interacting with them at the API level.

> People still don’t know how LLMs work and think they can be trained by interacting with them at the API level. Unless they are logging the interactions via the API, and then training off those logs. They might assume doing so is relatively safe since all the users are trustworthy and unlikely to be deliberately injecting incorrect data. In which case, a leaked API key could be used to inject incorrect data into the…

Nobody really trains directly from logs without curation and filtering.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#78
post #77

Earlier quoted context omitted.

> People still don’t know how LLMs work and think they can be trained by interacting with them at the API level. Unless they are logging the interactions via the API, and then training off those logs. They might assume doing so is relatively safe since all the users are trustworthy and unlikely to be deliberately injecting incorrect data. In which case, a leaked API key could be used to inject incorrect data into the…

Nobody really trains directly from logs without curation and filtering.

Sure, but there is a non-zero risk that some malicious data could slip through the curation and filtering processes undetected

I agree that’s unlikely, but not astronomically unlikely

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#79
post #40

Earlier quoted context omitted.

> Guess who's going to be fired by elon :D i know, you probably just meant it as a fun comment. but i don't get how this is funny. this person probably relies on income, might have a family to feed... and just made a mistake. a type of mistake, that is not uncommon. i mean i have seen corporate projects where senior engineers didn't even understand why committing secrets might be a bad idea. yes, of course, as a engi…

If you ever visit a Bill Burr show, let me know. I wouldn't want to miss it.

It was clearly a joke and that is not the best place to come down with a morality club. It has soapbox vibes and the person who made the joke also hasn't earned that.

Re: xAI dev leaks API key for private SpaceX, Tesla LLMs

#80
post #77

Earlier quoted context omitted.

Nobody really trains directly from logs without curation and filtering.

Sure, but there is a non-zero risk that some malicious data could slip through the curation and filtering processes undetected I agree that’s unlikely, but not astronomically unlikely

Considering the costs involved in fine-tuning, nobody does it unless they are a very rich corporation. And certainly not for public-facing models…
Post reply on HN