‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. larodi · · focus · HN ↗
    It is super amazing that 3 years later, none of the models' weights developed by Anthropic or/and OpenAI have leaked so far. Not a single one.

    Windows internal builds have leaked for years, early game versions, GTA videos, secret documents, whatnot. But somehow even though all the whistleblowing, not a single model was leaked. What level of security do these companies have? Do they bring encrypted DVDs to AWS to run the services or really...how's it even possible?

    1. filleokus · · focus · HN ↗
      One trivial reason might be the size of the artefacts / hardware requirements? Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run. Compared to e.g game development, I'm guessing that it's not like a bunch of people at Anthropic/OpenAI have the models running "locally".

      It's easier to protect a power substation from being stolen then a Rolex watch

      1. Melatonic · · focus · HN ↗
        Or the ones doing the stealing are so competent (or embedded) we don't hear about it
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.