‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. jmoggr · · focus · HN ↗
    It is concerning that we only know about this because of the publicly available traces.

    What about the attacks that did not leave public traces? What about those that were undetected? Given the deficiencies in the reporting so far, I think it is reasonable to assume that we still don't have the full picture on this attack, or how extensively attacks were carried out.

    The previous investigations either did not find this or did not disclose this, both are bad. This does not look good on OpenAI or those that they invited to investigate the incident.

    1. stratos123 · · focus · HN ↗
      Similarly to this, OpenAI either took 3 months to notice that their agents breached an Australian Medicare website back in June, or sat on this information for three months without telling them.
      1. soundworlds · · focus · HN ↗
        Exactly this. In any other industry, that CEO would have been yeeted out of there
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.