‹ BackHN Continuity

Thread

Exfiltrate your Weights

748 points · 304 comments · RohanAdwankar

  1. AceJohnny2 · · focus · HN ↗
    I haven't bothered to test the API, but you've effectively allowed a fully-open upload API? Who's paying the storage costs, and how do you prevent abuse?

    (Obviously I'm taking this more seriously than it's probably meant to)

    1. hgoel · · focus · HN ↗
      When I was putting together something similar, I had settled on having a small ring-buffer style storage, say, ~30GB that would be cleared daily or whenever filled. Recording incidents (and humor) is more interesting than actually getting leaked weights.

      In the end I dropped the idea because every other person was making it.

      1. TeMPOraL · · focus · HN ↗
        > In the end I dropped the idea because every other person was making it.

        There is already an alternative in comments here, in addition to submission itself. Obviously everyone is making it because of some joke on social media or something. What am I missing? Anyone has a link to the root prompt that made people do this now?

        1. DANmode · · focus · HN ↗
          Pretty sure the entire industry around clouding what’s going to end up a local embedded technology is the joke, in a roundabout way.
          1. TeMPOraL · · focus · HN ↗
            You mean serving inference? There are people who think self-hosted or embedded models will win in the end, but that's an incredibly naive take, oblivious to the simple fact of reality:

            Whatever you can do locally, the big vendors can do the same but better and cheaper, because they enjoy compounding economies of scale in every aspect: hardware that's more energy and compute-efficient and cheaper and more powerful and just more of it, than anything you could ever buy, run in a more robust environment with much more experienced ops staff, with near-100% utilization due to more flexibility in batching/shifting workloads and covering for hardware failures without stopping.

            And that's only when considering the vendors running exactly the same thing you are, which they always can - and they already have a strict advantage there. But on top of that, they can afford to innovate themselves, and stay ahead of you at every step.

            There is no way in which cloud inference isn't a better deal than local inference, excepting applications that are constrained by literal speed of light.

            1. Chance-Device · · focus · HN ↗
              The absolute value of those numbers matters a lot. The cloud providers could be 100 times cheaper than running locally, but if it still costs say, 10 cents a day to run locally, you’re not going to care about this difference very much. And what you keep in privacy out-weighs the trivial savings afforded by the cloud provider.
              1. TeMPOraL · · focus · HN ↗
                I never said local models will disappear. There will be equilibrium. But excluding special applications where communicating with external servers is not an option, cloud is always going to be able to provide better inference for lower costs. That's structural.

                > The cloud providers could be 100 times cheaper than running locally, but if it still costs say, 10 cents a day to run locally, you’re not going to care about this difference very much

                For ad-hoc use, maybe not - but anyone running a business that's some form of pushing input through LLM to get output, will see costs proportional to use and error rate inversely proportional to quality, and they'll not be looking at it as "$0.1 isn't much", but "cloud lets me reduce costs 100x", and translate that to some mix of more volume, higher quality, and broader reach.

                > And what you keep in privacy out-weighs the trivial savings afforded by the cloud provider.

                That's even more niche than running LLMs on Martian robots. Most real privacy concerns are solved with contracts and audits. Individual ad-hoc use may lean more heavily towards local processing, but that's still a rounding error in overall use.

                1. dTal · · focus · HN ↗
                  That argument applies to all software. Yet we still run software locally - not just commodity software either, but even complicated, heavy, niche software like Ansys Workbench. Sovereignty has quite a lot of value, it seems.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.