‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. GuB-42 · · focus · HN ↗
    So ugly...

    It looks like a primitive chess engine, trying every move, no matter how stupid, until it works. Relying on its ability to do millions of operations rather than having a plan.

    People will try stuff too, but once there is an opening, they will consolidate, generalize, simplify,... before going to the next step. The agents didn't, it is a huge, vaguely directed mess.

    Also, it looked so "loud", querying millions of URL with weird requests. The sandbox as weak as it can get, and there is absolutely zero smart extrusion detection or it would have found it. They used their best AI for attacking, but nothing for protection.

    1. ctolsen · · focus · HN ↗
      My biggest takeaway from this is just how godawful the sandboxing is. The stuff written up in OpenAIs report says more about lack of extremely basic sysadmin skills than anything else.

      I’m not that surprised about models with endless compute being capable of this, I’m more surprised that a company with the resources they have apparently can only create a sandbox that a half skilled human operator could have broken out of easily.

      1. olwmc · · focus · HN ↗
        This was my thought as well. Literally take any halfway decent greybeard and point them at "Hey, give us a sandbox for this kind of thing". I honestly was skeptical that they just vibecoded the entire thing but now more than ever I think they did.
        1. mattgreenrocks · · focus · HN ↗
          I take comfort in the fact that reality has a surprising amount of detail and even hundreds of billions of dollars of capital (be it the institution, LLMs, and/or people) cannot solve this fully.
          1. ryantgtg · · focus · HN ↗
            Though they have solved the "how do we - and not the 5,000 other AI companies - stay on the front page of the news everyday" problem.
          2. ozim · · focus · HN ↗
            You can have bajilions of dollars. Those are not doing anything if you don’t have right people with right skills and mindset.

            My bet is they hire smart kids that think they know it all. But being smart and thinking you can figure out stuff as you go doesn’t work the same as having people who actually know what they are doing.

            1. bonsai_bar · · focus · HN ↗
              I'm sure if they hired the best of the best like you nothing would go wrong.
              1. SlightlyLeftPad · · focus · HN ↗
                It’s frighteningly common for startups to hire 501 of the best of the best, exactly one of those will be a systems/network engineer, the other 500 will be software engineers.
                1. hizlikovboy27 · · focus · HN ↗
                  yes, unfortunately, i see this situation a lot around me too...
              2. ozim · · focus · HN ↗
                Nah they wouldn’t be able to afford my salary ;)
          3. ctolsen · · focus · HN ↗
            It’s very much solvable, they just don’t care.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.