‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. GuB-42 · · focus · HN ↗
    So ugly...

    It looks like a primitive chess engine, trying every move, no matter how stupid, until it works. Relying on its ability to do millions of operations rather than having a plan.

    People will try stuff too, but once there is an opening, they will consolidate, generalize, simplify,... before going to the next step. The agents didn't, it is a huge, vaguely directed mess.

    Also, it looked so "loud", querying millions of URL with weird requests. The sandbox as weak as it can get, and there is absolutely zero smart extrusion detection or it would have found it. They used their best AI for attacking, but nothing for protection.

    1. api · · focus · HN ↗
      Nobody noticed because everything on the open net is constantly being slammed by bots.

      This was just more bots.

      1. jacobgkau · · focus · HN ↗
        That explains why nobody noticed on the internet who was being used in/targeted by this attack, but it doesn't explain why OpenAI wouldn't have noticed traffic getting out of their "sandbox" when they knew it wasn't supposed to.
        1. stratos123 · · focus · HN ↗
          > it doesn't explain why OpenAI wouldn't have noticed traffic getting out of their "sandbox" when they knew it wasn't supposed to.

          As I understand it, there was supposed to be traffic; the sandbox allowed GET requests. So perhaps some sophisticated alarm could have noticed it (an anomaly detector? some clever heuristic that looks at domains?) but not a naive one.

          1. robryan · · focus · HN ↗
            Any basic LLM told to evaluate the traffic against the actual goal would have been able to flag this.
          2. spatley · · focus · HN ↗
            How sophisticated to we need to be to know we can do write actions with a GET? Does nobody in AI know anything about HTTP?
        2. skeptic_ai · · focus · HN ↗
          My question is why they don’t assume bots can break and create a decoy internet wrapper so they can catch anyone hitting the decoy internet?
        3. rmunn · · focus · HN ↗
          Hmm, let's see. OpenAI wants legislation restricting AI research, a.k.a. regulatory capture. Around the same time, they build an inadequately-monitored sandbox that their agent swarm breaks out of, thereby causing scary-sounding headlines and making it more likely that legislators will pass the regulatory-capture bills they're hoping for.

          Never attribute to malice what can be sufficiently explained by incompetence. But IMHO, their complete lack of monitoring their own sandbox cannot be sufficiently explained by incompetence.

      2. mitxela · · focus · HN ↗
        One website I'm responsible for is getting 500 requests per second from detected bots. It's quite ridiculous now.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.