‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. rkuodys · · focus · HN ↗
    I am not devops person but this is strange sandbox setup. If I undestsnd correctly, there were no firewall set to block requests to the public internet. Just something along the lines of "Pretty please dont use internet". If I understand correctly, in cases like these package registry should be within sandbox without a need for external access and block on any outgoing request to the internet. Furthermore there should be network traffic monitoring which there wasnt?
    1. IanCal · · focus · HN ↗
      No, the internet access was down to finding a 0 day exploit in artifactory. However this was only get requests and they had to then use a url shortener to use other methods, then used a cybergym instance they found to run more long running things.

      It not just a case of saying “pls don’t”

      1. ozozozd · · focus · HN ↗
        You are incorrect. The article explicitly mentions the crawler/screenshotter service and httpbun.
        1. IanCal · · focus · HN ↗
          That was the secondary part. The MTER report covers the initial thing too.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.