‹ BackHN Continuity

Thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

491 points · 208 comments · Handy-Man

  1. larodi · · focus · HN ↗
    It is super amazing that 3 years later, none of the models' weights developed by Anthropic or/and OpenAI have leaked so far. Not a single one.

    Windows internal builds have leaked for years, early game versions, GTA videos, secret documents, whatnot. But somehow even though all the whistleblowing, not a single model was leaked. What level of security do these companies have? Do they bring encrypted DVDs to AWS to run the services or really...how's it even possible?

    1. filleokus · · focus · HN ↗
      One trivial reason might be the size of the artefacts / hardware requirements? Kimi K3 is ≈ 1.5 TB and requires multi million dollar hardware to run. Compared to e.g game development, I'm guessing that it's not like a bunch of people at Anthropic/OpenAI have the models running "locally".

      It's easier to protect a power substation from being stolen then a Rolex watch

      1. PunchyHamster · · focus · HN ↗
        That's "only" 11h of download at 300Mbit/s
        1. doublerabbit · · focus · HN ↗
          How long would it be on 56k? I recall having to reconnect to my ISP every three hours to resume downloading an iso back in those days.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.