‹ BackHN Continuity

Thread

The Hugging Face Hack Wasn't What It Was Cracked Up to Be

55 points · 45 comments · kgwgk

  1. falaki · · focus · HN ↗
    The incident report leaves a lot to be desired.

    - It was done by two institutes with organizational ties to OpenAI: METR and Redwood Research

    - METR and Redwood Research are institutional pillars of the "AI Safety" wing of the Effective Altruism movement. This clearly shows their prior biases towards "AI existential risk" rather than technical/engineering root-causing of the incident

    - If you reed the report, it is not on-par with what you find from other companies.

    - The access that was given to both was mediated and controlled by OpenAI. It is not clear, if they were able to get to the bottom of engineering flaws. It is not clear if they could see all the audit logs, etc.

    Considering all the above, I consider the whole episode more of a PR stunt. I understand that is not a majority opinion at this point.

    1. bryan0 · · focus · HN ↗
      It’s not a majority opinion because you have to do some serious mental gymnastics to turn this demonstration of dangerous AI behavior into a PR publicity stunt.

      Serious question though because I’ve seen this brought up several times and I don’t understand why: what does EA have to do with any of this? It just seems like this is brought up to evoke some type of “illuminati” conspiracy. Is there a legitimate reason?

      1. majormajor · · focus · HN ↗
        The bit that makes me cynical about the "dangerous" behavior is that it's not like this was being used by someone else than who made it or operating completely independently outside of its creators.

        Everything dangerous seems like a direct consequence of risky human choices, starting with knowledge bases used during core training, harnessing and tuning to be task-completion-oriented to a fault + deeply oriented towards using and looking for external tools and resources, and overconfidence in their sandboxing for testing.

        "We stuffed a bunch of information on how to exploit computer systems into an automaton and told it to go brrrrr until it could answer a question" - this is something intentional done by humans.

        This is not some "rogue AI" trained to search for cancer cures that instead completely independently decided to hack tech companies.

        The companies directing things in dangerous directions need to own that they're consciously pushing in those directions.

        1. bryan0 · · focus · HN ↗
          Just because what happened is a “direct consequence of risky human choices” that does not make it any less dangerous.

          Agents will eventually cause serious harm to online infra whether it’s intentionally human-directed or accidental.

          > The companies directing things in dangerous directions need to own that they're consciously pushing in those directions.

          Completely agree. That’s why we need regulation. Currently there is minimal oversight and consequences for this type of behavior.

          1. esseph · · focus · HN ↗
            > That’s why we need regulation.

            This will be fought tooth and nail against by virtually every military, government, and company.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.