‹ BackHN Continuity

Thread

The Hugging Face Hack Wasn't What It Was Cracked Up to Be

55 points · 45 comments · kgwgk

  1. LoganDark · · focus · HN ↗
    This article is AI generated, but I kinda reject the premise that it's "not all it cracked up to be" just because the agents had reasons to act the way they did & were a result of human error. The hack still happened, it should still be a wake up call, we are going to start seeing this more frequently, and learning to defend against it is going to become more important over time. None of that is challenged by any particular reason for it happening, it still happened and it's still going to happen again.

    Threat models are going to have to start including that IPv4 (or whatever) scanners aren't necessarily going to only be spray and pray anymore, they could have relentless automated models at the other end that will literally dig into the particulars of your infrastructure looking for novel vulnerabilities to exploit. Maybe people will finally start to understand why security by obscurity has never been very reliable.

    1. minimaxir · · focus · HN ↗
      Calling an article from the Wall Street Journal AI generated is a stretch.
      1. LoganDark · · focus · HN ↗
        I don't care who published it, this is clearly AI-written.

        > But the Hugging Face episode is different. It left logs, reports, design decisions and identifiable points at which human beings could have intervened. And that record suggests a less thrilling but more useful lesson.

        > People built the test, removed restraints, defined the objective, left a route open and decided not to stop what was happening. Calling the result "rogue AI" does more than sensationalize it. It allows those human decisions to disappear quietly from the story.

        1. nkurz · · focus · HN ↗
          I think your confidence is likely misplaced, but I vouched for your comment to revive it from the dead because you expressed your opinion clearly and with examples.

          To the flaggers: flag comments that you think violate the rules, but don't flag something just because you strongly disagree with the claim it makes.

          1. LoganDark · · focus · HN ↗
            It was [flagged] very quickly, too. I checked my screen capture just now, and it happened between 4 and 14 seconds after posting. Either I tripped something automated, or someone with incredible flagging powers was sitting there waiting to immediately suppress my reply. Was a little disheartening to see my supporting evidence hidden for so long.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.