OpenAI, Anthropic, Meta, all were scammed by a firm called Irregular who pinky swore they could handle sandboxing for lots of money. They had no idea how to do sandboxing, and there was obviously no remote attestation to prove they were doing the basics properly.
So then models escape, companies get hacked, and the entire world goes into existential panic.
Guys. Really. Can someone please hire even one linux systems engineer worth a damn? Is everyone in the valley too Apple pilled now to have any capabilities in Linux hardening other than patching stock ubuntu?
This whole situation is ridiculous. All three labs were negligent and should be sued for damages.
Frontier AI is not magic and it will not escape any sandbox just about anyone with any linux systems experience at all constructs.
I know it is easier to believe the models are super hackers beyond human understanding, but the reality it is just the specific humans hosting them that are super inexperienced at system hardening and airgapping.
Irregular was not involved in the huggingface incident, which is the most significant one.
It's actually easier for many, whose careers depend on AI sucking, to believe that AI can never be a super hacker, not sure why you think this bias can only go one way.
I'm curious if you're familiar with the particulars of how Huggingface was hacked. They were negligent in their own ways and rights. Mounting a host path volume in a Kubernetes pod is really not "super hacker" territory!
Why where they using kubernetes for this at all, it’s attack surface and config complexity is too large for anything that needs airgapped security. Yes, I know kubernetes used for large production deployments for web apps and that is my point, it’s not made for securing AI agents with insider access, it’s meant for securing outside access.
lrvick · · focus · HN ↗
OpenAI, Anthropic, Meta, all were scammed by a firm called Irregular who pinky swore they could handle sandboxing for lots of money. They had no idea how to do sandboxing, and there was obviously no remote attestation to prove they were doing the basics properly.
So then models escape, companies get hacked, and the entire world goes into existential panic.
Guys. Really. Can someone please hire even one linux systems engineer worth a damn? Is everyone in the valley too Apple pilled now to have any capabilities in Linux hardening other than patching stock ubuntu?
This whole situation is ridiculous. All three labs were negligent and should be sued for damages.
Frontier AI is not magic and it will not escape any sandbox just about anyone with any linux systems experience at all constructs.
I know it is easier to believe the models are super hackers beyond human understanding, but the reality it is just the specific humans hosting them that are super inexperienced at system hardening and airgapping.
dumberquestions · · focus · HN ↗
It's actually easier for many, whose careers depend on AI sucking, to believe that AI can never be a super hacker, not sure why you think this bias can only go one way.
Dweller1622 · · focus · HN ↗
tmikaeld · · focus · HN ↗