‹ BackHN Continuity

Thread

Frontier Labs Are Selling Garbage to Fools in Washington

186 points · 87 comments · nr378

  1. DalasNoin · · focus · HN ↗
    "Every single one of these catastrophic breakouts happened inside the testing environments of the exact same vendor."

    This is incorrect, the HF incident for example (the most well known) had nothing to do with irregular. I know there has been a news site pushing inaccurate articles (effort.news) on this topic but these are the facts.

    <a href="https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;hugging-face-incident-and-the-road-ahead&#x2F;" rel="nofollow">https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;hugging-face-incident-and-the-road-...

    1. nr378 · · focus · HN ↗
      Thank you, you&#x27;re correct. Effort.news was one of my research sources, but you&#x27;re right that although OpenAI use Irregular, they were not involved in the specific HF incident (although the failure mode was otherwise identical). I&#x27;ve updated the post to make that clear.
      1. kalkin · · focus · HN ↗
        As of writing it still says:

        &gt; For Anthropic, Google, and Meta, the catastrophic breakouts happened inside the testing environments of the exact same contractor.

        If this is the level of understanding you have of the relevant incidents, there&#x27;s a lot of chutzpah in saying that other people are &quot;selling garbage&quot;, carrying out an &quot;extraordinary confidence trick&quot;, etc.

        1. nr378 · · focus · HN ↗
          &gt; As of writing it still says:

          Yes, and that is correct.

          [1] Anthropic’s Official Disclosure (All 4 Incidents at Irregular) &quot;All four incidents occurred during cybersecurity evaluations built by the same evaluation partner [Irregular]... due to a misconfiguration, it was mistakenly connected to the open internet.&quot;

          <a href="https:&#x2F;&#x2F;www.anthropic.com&#x2F;research&#x2F;alignment-assessment-cybersecurity-incidents" rel="nofollow">https:&#x2F;&#x2F;www.anthropic.com&#x2F;research&#x2F;alignment-assessment-cybe...

          [2] Google Gemini on Irregular (Disclosed Sept 18 via WSJ &#x2F; BBC) &quot;The hacks happened during a test of the model’s cybersecurity capabilities run by third-party Irregular, which was also involved in similar incidents involving Meta and OpenAI.&quot;

          <a href="https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;articles&#x2F;c607l0k72rlvo" rel="nofollow">https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;articles&#x2F;c607l0k72rlvo

          [3] Meta’s Disclosure on Irregular (Aug 6) &quot;Over roughly two weeks, three frontier labs disclosed that their models had reached the open internet during safety testing and compromised outside organisations. Every disclosure named the same evaluation partner: Irregular.&quot;

          <a href="https:&#x2F;&#x2F;www.cnbc.com&#x2F;2026&#x2F;08&#x2F;09&#x2F;israeli-startup-irregular-linked-to-ai-hacks-openai-anthropic-meta.html" rel="nofollow">https:&#x2F;&#x2F;www.cnbc.com&#x2F;2026&#x2F;08&#x2F;09&#x2F;israeli-startup-irregular-li...

          [4] Separately, OpenAI itself had an incident involving Irregular, but not the Hugging Face Incident: &quot;On July 29, one of our third party evaluation partners, Irregular, notified us of an incident involving OpenAI models during Capture-the-Flag (CTF)-style cybersecurity evaluations... a testing-environment misconfiguration allowed models to access the public internet.&quot;

          <a href="https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;third-party-cyber-evaluations-involving-openai-models&#x2F;" rel="nofollow">https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;third-party-cyber-evaluations-invol...

      2. DalasNoin · · focus · HN ↗
        thank you for this reasonable reaction
      3. aesthesia · · focus · HN ↗
        The failure mode was _not_ identical. The HF incident agents were not directly connected to the internet and had to compromise an internal package registry in order to access the internet.
    2. verdverm · · focus · HN ↗
      Can you point out an inaccuracy in the effort.news piece on the hacking incidents? HuggingFace only appears once, as a &quot;similar&quot;, not levied against Irregular

      genuinely curious, haven&#x27;t heard others raise any yet, but does not mean it is issue free

      1. DalasNoin · · focus · HN ↗
        what you read (past tense) is already the corection
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.