‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. rkuodys · · focus · HN ↗
    I am not devops person but this is strange sandbox setup. If I undestsnd correctly, there were no firewall set to block requests to the public internet. Just something along the lines of "Pretty please dont use internet". If I understand correctly, in cases like these package registry should be within sandbox without a need for external access and block on any outgoing request to the internet. Furthermore there should be network traffic monitoring which there wasnt?
    1. IanCal · · focus · HN ↗
      No, the internet access was down to finding a 0 day exploit in artifactory. However this was only get requests and they had to then use a url shortener to use other methods, then used a cybergym instance they found to run more long running things.

      It not just a case of saying “pls don’t”

      1. user43928 · · focus · HN ↗
        That's also my understanding.

        This part of the article describes it poorly:

        > The agents initially had very limited access to the internet: they could load URLs

      2. sanderjd · · focus · HN ↗
        Yes but that wouldn't have worked if there were a firewall denying network access.
        1. IanCal · · focus · HN ↗
          Assuming there were no exploitable systems that had network access. We’re already talking about a case where based on software forbidding access they still had access. Why would a firewall be different? Harder sure but its only at the level of “as far as we know no way of getting past this”.
          1. sanderjd · · focus · HN ↗
            Because firewalls are explicitly designed and audited for this kind of exploit. It would be much more surprising for a mature firewall system to allow unauthorized network access, than that this package management system had an exploit that allowed this escalation of privileges.

            This isn't rocket science, this is why firewalls exist, to provide this cross cutting layer of defense.

            1. IanCal · · focus · HN ↗
              It’s not rocket science, no, and I thought the point would be clear but in fewer words - less likely is a distinctly different thing than not possible.
              1. sanderjd · · focus · HN ↗
                The specific thing that happened would not have been possible. They might have found a different exploit in the firewall system. But specifically "the package manager can be exploited to send arbitrary requests" problem could have been solved in this obvious way.
      3. ozozozd · · focus · HN ↗
        You are incorrect. The article explicitly mentions the crawler/screenshotter service and httpbun.
        1. IanCal · · focus · HN ↗
          That was the secondary part. The MTER report covers the initial thing too.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.