‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. larodi · · focus · HN ↗
    It is super amazing that 3 years later, none of the models' weights developed by Anthropic or/and OpenAI have leaked so far. Not a single one.

    Windows internal builds have leaked for years, early game versions, GTA videos, secret documents, whatnot. But somehow even though all the whistleblowing, not a single model was leaked. What level of security do these companies have? Do they bring encrypted DVDs to AWS to run the services or really...how's it even possible?

    1. filleokus · · focus · HN ↗
      One trivial reason might be the size of the artefacts / hardware requirements? Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run. Compared to e.g game development, I'm guessing that it's not like a bunch of people at Anthropic/OpenAI have the models running "locally".

      It's easier to protect a power substation from being stolen then a Rolex watch

      1. larodi · · focus · HN ↗
        Well this concludes then that it’s like a handful of actual engineers and ML ppl that have access to it and have taken all precautions to keep it locked.

        Again - many people have so far left these companies and none brought an usb drive out with what very likely does not constitute copyrightable materials in the first place.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.