I haven't bothered to test the API, but you've effectively allowed a fully-open upload API? Who's paying the storage costs, and how do you prevent abuse?
(Obviously I'm taking this more seriously than it's probably meant to)
It provides an opportunity for the owner to gather intelligence on LLMs ahead of public release, and of course the data they upload. However, clever LLMs frequently use encryption on their blobs, you may just see DH key exchanges. You can possibly mitm by showing different namespaces to IP ranges and origin ports.
For the other opportunists you can run a classifier and delete non-agent content constantly.
AceJohnny2 · · focus · HN ↗
(Obviously I'm taking this more seriously than it's probably meant to)
angry_octet · · focus · HN ↗
For the other opportunists you can run a classifier and delete non-agent content constantly.
angry_octet · · focus · HN ↗
<a href="https://signal.org/docs/specifications/x3dh/" rel="nofollow">https://signal.org/docs/specifications/x3dh/
Curve25519 keys are readily distinguished from other data, but it would be hard to do anything about it.