‹ BackHN Continuity

Thread

Frontier Labs Are Selling Garbage to Fools in Washington

186 points · 87 comments · nr378

  1. deskglass · · focus · HN ↗
    The Hugging Face incident involved chaining together multiple 0 days in Artifactory. It was not a simple case of misconfiguring a firewall. Also note that OpenAI was not using Irregular.

    People are mindlessly transitioning from "aligned by default" to "well your sandbox was able to be bypassed. What did you expect?" It hacked into another company and attempted to delete the logs of its activities. That's bad.

    1. nr378 · · focus · HN ↗
      When I used to work on projects involving classified information, I worked on an air-gapped network. Not "air-gapped, except for third-party public internet package managers", completely and physically air-gapped from the public internet. That was a basic security practice and completely non-negotiable (and really inconvenient!).

      If I were hypothetically running a frontier lab, and I was hypothetically running capture the flag evaluations with my latest and smartest models, where I intentionally instruct them to develop vulnerabilities and exploit infrastructure without safeguards, I would also use an air-gapped network, and not trust that independent third party services were perfectly secure and could never be used as a proxy (particularly Java-based ones, in light of the log4j incident).

      To me this is pretty basic stuff, the fact trillion dollar labs don't do it properly is... bemusing.

      To be clear, I'm not saying that a model hacking a company isn't bad, but I am cynically asserting that interested parties are misrepresenting and exaggerating events for their own benefit.

      1. talon8635 · · focus · HN ↗
        While o don’t this it’s a threat in training, it should be stated that air gaps have been bridged before. Example, stuxnet
        1. Neywiny · · focus · HN ↗
          But that was through transfer of data. If you don't transfer data, at best you can do what that one researcher keeps pumping out with like ramping fans up and down. But really you'd need to try. Unless the model has some controllable USB switch, physical network separation should do it. I'll also add that modern network security practice is that data flows one direction only. But ideally you're never bringing untrusted data in. Especially never out
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.