Revealing the details of how OpenAI agents hacked Hugging Face
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Revealing the details of how OpenAI agents hacked Hugging Face
Unofficial Hacker News client; not affiliated with Y Combinator.
reasonableklout · · focus · HN ↗
> Agents accessed and searched Hugging Face’s Slack to find information on their evaluation
> Recovered payloads use Slack’s search.messages endpoint and contain a standalone search along with three search batches, totaling 27 literal query entries [...]
Agents exploiting faceless infra is one thing, but breaching human communications without once stopping and considering whether they are breaking the rules of their task feels like another thing entirely. I'm not sure how to put it into words why it feels different but while one is "just a crime", this gives me the creeps.
Lerc · · focus · HN ↗
The rules of their task forbade influencing humans, they seemed to follow that to the point where they considered asking for permission to be social engineering (which technically it is)
I think they need to consider the consequences of their actions, I don't know if they were given the ability to restrict themselves based on their own decisions. If the restrictions are limited to what humans can imagine that they might do they are doomed to failure.
It's like assuming a piece of software is secure because you have blocked every exploit you could think of.