‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. larodi · · focus · HN ↗
    It is super amazing that 3 years later, none of the models' weights developed by Anthropic or/and OpenAI have leaked so far. Not a single one.

    Windows internal builds have leaked for years, early game versions, GTA videos, secret documents, whatnot. But somehow even though all the whistleblowing, not a single model was leaked. What level of security do these companies have? Do they bring encrypted DVDs to AWS to run the services or really...how's it even possible?

    1. nelaggy · · focus · HN ↗
      probably a bit harder to steal terabytes of data, and the weights aren't what people are after anyway - distillation is basically "stealing" a model and you can do it from outside
    2. madhatter999 · · focus · HN ↗
      Publicly…
    3. filleokus · · focus · HN ↗
      One trivial reason might be the size of the artefacts / hardware requirements? Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run. Compared to e.g game development, I'm guessing that it's not like a bunch of people at Anthropic/OpenAI have the models running "locally".

      It's easier to protect a power substation from being stolen then a Rolex watch

      1. Melatonic · · focus · HN ↗
        Or the ones doing the stealing are so competent (or embedded) we don't hear about it
      2. PunchyHamster · · focus · HN ↗
        That's "only" 11h of download at 300Mbit/s
        1. doublerabbit · · focus · HN ↗
          How long would it be on 56k? I recall having to reconnect to my ISP every three hours to resume downloading an iso back in those days.
      3. larodi · · focus · HN ↗
        Well this concludes then that it’s like a handful of actual engineers and ML ppl that have access to it and have taken all precautions to keep it locked.

        Again - many people have so far left these companies and none brought an usb drive out with what very likely does not constitute copyrightable materials in the first place.

      4. ux266478 · · focus · HN ↗
        > Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run.

        Not that it defeats your point, but an 8x MI355X node is $350k-400k. The only reason you're paying that much is for the VRAM, too. You could run it with much less compute than what you get in a single card.

    4. hnlmorg · · focus · HN ↗
      People working at OpenAI have stock options. People working at MS and Rockstar do not.

      Leaking negatively affects investment while the “whistleblowers” are largely just saying “our tech is too good” which increases investment into those companies.

      Ultimately, it always comes down to money.

      1. lostmsu · · focus · HN ↗
        MS absolutely has a couple of stock-based incentives.
    5. AtNightWeCode · · focus · HN ↗
      SSO and hardware sec keys. And the models are located in very few places. Few if any people have direct access to them. Then due to the size of the models you can detect and stop a theft just by monitoring the egress traffic.
      1. monster_truck · · focus · HN ↗
        > monitoring the egress traffic

        Oh so you mean the thing HuggingFace wasn't doing at all while also allowing any user's arbitrary programs to call out to the open web from prod?

        1. larodi · · focus · HN ↗
          indeed, how does this add up the fact that 20k agents drilling another corpo's headquarters may actually register on a radar. and it seems they did on multiple occasions...?
    6. eli · · focus · HN ↗
      Windows internal builds and video games are distributed to engineers and testers to run on their local workstations/consoles. Model weights are not.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.