‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. damowangcy · · focus · HN ↗
    Imagine having a virus escape a sandbox, why are we worried about the virus but not the incompetency of those who are responsible for setting up the sandbox?

    If I post something on the Internet today claiming that I asked my agent to do X but it went rogue and did Y, all I will be getting in return is a jar full of "skill issue".

    Should we worried about people using LLMs for attacks? Yes, but not in the premise of LLMs going rogue but someone with the intention of abusing it to cause harm. And this is not something we as individual or even company can deal with, responsibility should be held by those who use it, in a legal way.

    I am baffled by the fact that up until now, no one is held responsible for so many incidents reported publicly or privately. At this point, it's free marketing, if I am CEO of any AI company, I will run swarm of agents hacking all NGOs and stating that I am just looking for some random piece of data that happened to be hidden in their servers, at least that's what my LLMs think, not me. Then I will start preaching everyone how dangerous this piece of technology is and start giving out free tokens for these NGOs so they can start defending themselves and we should slow the f down.

    1. crocowhile · · focus · HN ↗
      Would you rather have the model encounter the internet for the first time once is been deployed?

      You don't test a bullet proof vest with rubber bullets. Also, all these arguments about the sandbox being too weak are good in hindsight anyway.

      1. lelanthran · · focus · HN ↗
        > You don't test a bullet proof vest with rubber bullets.

        You also don't test with live humans wearing the vest.

      2. rakel_rakel · · focus · HN ↗
        Hindsight for some, not for everyone <a href="https:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-misc&amp;m=119318909016582" rel="nofollow">https:&#x2F;&#x2F;marc.info&#x2F;?l=openbsd-misc&amp;m=119318909016582
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.