‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. damowangcy · · focus · HN ↗
    Imagine having a virus escape a sandbox, why are we worried about the virus but not the incompetency of those who are responsible for setting up the sandbox?

    If I post something on the Internet today claiming that I asked my agent to do X but it went rogue and did Y, all I will be getting in return is a jar full of "skill issue".

    Should we worried about people using LLMs for attacks? Yes, but not in the premise of LLMs going rogue but someone with the intention of abusing it to cause harm. And this is not something we as individual or even company can deal with, responsibility should be held by those who use it, in a legal way.

    I am baffled by the fact that up until now, no one is held responsible for so many incidents reported publicly or privately. At this point, it's free marketing, if I am CEO of any AI company, I will run swarm of agents hacking all NGOs and stating that I am just looking for some random piece of data that happened to be hidden in their servers, at least that's what my LLMs think, not me. Then I will start preaching everyone how dangerous this piece of technology is and start giving out free tokens for these NGOs so they can start defending themselves and we should slow the f down.

    1. user43928 · · focus · HN ↗
      > someone with the intention of abusing it to cause harm [...] responsibility should be held by those who use it

      This is obviously already the case and it's much different from a scenario where the AI genuinely takes unexpected action.

      I frankly find it ridiculous how many suggest OpenAI or its employees should face criminal charges, without actual legal basis at the time.

      It's also hardly outrageous that they ran training and/or benchmarks with only network-isolated VMs with access to a package repository.

      This being the first well-known incident of its kind, I wouldn't expect them to have done more than that.

      The idea that AI labs will now intentionally have their models hack companies in order to market their models, well, I don't even know what to say.

      That's ridiculous and what you describe would obviously be criminal behavior under existing law.

      1. kotaKat · · focus · HN ↗
        > I frankly find it ridiculous how many suggest OpenAI or its employees should face criminal charges, without actual legal basis at the time.

        Sam already committed other criminal acts and violations, but nobody wants to believe the victim because they were a woman and Sam The Golden Family Child Could Do Nothing Wrong(tm).

        If Altman was in prison we wouldn't be this blatantly far out in the open with OpenAI's continual nonconsensual assault on the open Internet.

        1. Marha01 · · focus · HN ↗
          > Sam already committed other criminal acts and violations, but nobody wants to believe the victim because they were a woman

          Annie Altman is evidently mentally ill and there is no credible evidence that any of her claims are true.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.