‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. tripzilch · · focus · HN ↗
    > This access seems to have only allowed the agents to make ‘GET’ requests, meaning they could fetch and read websites, but not interact with them, submit forms, or send data to them.

    honest question, but almost literally everyone doing anything with web technology knows this is simply not true, right?

    there's no such thing as "read only Internet" and restricting an agent to GET-requests only to accomplish that, is akin to using base64 for "encrypting" your password

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.