Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. No, OpenAI's new magic models did not autonomously hack Huggingface.

No, OpenAI's new magic models did not autonomously hack Huggingface.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
44 Indlæg 28 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • tante@tldr.nettime.orgT This user is from outside of this forum
    tante@tldr.nettime.orgT This user is from outside of this forum
    tante@tldr.nettime.org
    wrote sidst redigeret af
    #1

    No, OpenAI's new magic models did not autonomously hack Huggingface.

    Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

    "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

    So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

    The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

    hagen@mastodon.socialH davidgerard@circumstances.runD pascoda@chaos.socialP gurre@mastodon.nuG valpackett@social.treehouse.systemsV 14 Replies Last reply
    1
    0
    • tante@tldr.nettime.orgT tante@tldr.nettime.org

      No, OpenAI's new magic models did not autonomously hack Huggingface.

      Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

      "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

      So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

      The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

      hagen@mastodon.socialH This user is from outside of this forum
      hagen@mastodon.socialH This user is from outside of this forum
      hagen@mastodon.social
      wrote sidst redigeret af
      #2

      @tante but it was impossible to envision that their zero day machine would be able to escape their vibecoded sandbox that ran on a machine connected to the internet. nobody could ever guess that this would happen!

      sonofsuntzu@mastodon.socialS 1 Reply Last reply
      0
      • tante@tldr.nettime.orgT tante@tldr.nettime.org

        No, OpenAI's new magic models did not autonomously hack Huggingface.

        Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

        "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

        So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

        The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

        davidgerard@circumstances.runD This user is from outside of this forum
        davidgerard@circumstances.runD This user is from outside of this forum
        davidgerard@circumstances.run
        wrote sidst redigeret af
        #3

        @tante a friend suggests it's co-marketing with Huggingface, if you look at the timeline of announcements

        tante@tldr.nettime.orgT rogerbw@discordian.socialR erlenmayr@chaos.socialE resuna@ohai.socialR 5 Replies Last reply
        0
        • davidgerard@circumstances.runD davidgerard@circumstances.run

          @tante a friend suggests it's co-marketing with Huggingface, if you look at the timeline of announcements

          tante@tldr.nettime.orgT This user is from outside of this forum
          tante@tldr.nettime.orgT This user is from outside of this forum
          tante@tldr.nettime.org
          wrote sidst redigeret af
          #4

          @davidgerard 100%.

          1 Reply Last reply
          0
          • davidgerard@circumstances.runD davidgerard@circumstances.run

            @tante a friend suggests it's co-marketing with Huggingface, if you look at the timeline of announcements

            rogerbw@discordian.socialR This user is from outside of this forum
            rogerbw@discordian.socialR This user is from outside of this forum
            rogerbw@discordian.social
            wrote sidst redigeret af
            #5

            @davidgerard @tante "The last 213 times it was blatant lies and spin, but this time you should be scared!"

            1 Reply Last reply
            0
            • tante@tldr.nettime.orgT tante@tldr.nettime.org

              No, OpenAI's new magic models did not autonomously hack Huggingface.

              Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

              "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

              So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

              The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

              pascoda@chaos.socialP This user is from outside of this forum
              pascoda@chaos.socialP This user is from outside of this forum
              pascoda@chaos.social
              wrote sidst redigeret af
              #6

              @tante
              what the HELL are cyber capabilities.

              (OTOH, why am I trying to seek meaning in an OpenAI PR release.)

              tante@tldr.nettime.orgT valpackett@social.treehouse.systemsV 2 Replies Last reply
              0
              • pascoda@chaos.socialP pascoda@chaos.social

                @tante
                what the HELL are cyber capabilities.

                (OTOH, why am I trying to seek meaning in an OpenAI PR release.)

                tante@tldr.nettime.orgT This user is from outside of this forum
                tante@tldr.nettime.orgT This user is from outside of this forum
                tante@tldr.nettime.org
                wrote sidst redigeret af
                #7

                @pascoda don't it was mostly generated by an LLM.

                supermoosie@mastodon.auS 1 Reply Last reply
                0
                • davidgerard@circumstances.runD davidgerard@circumstances.run

                  @tante a friend suggests it's co-marketing with Huggingface, if you look at the timeline of announcements

                  tante@tldr.nettime.orgT This user is from outside of this forum
                  tante@tldr.nettime.orgT This user is from outside of this forum
                  tante@tldr.nettime.org
                  wrote sidst redigeret af
                  #8

                  @davidgerard I can't imagine Huggingface's financials are looking too hot, either.

                  1 Reply Last reply
                  0
                  • tante@tldr.nettime.orgT tante@tldr.nettime.org

                    No, OpenAI's new magic models did not autonomously hack Huggingface.

                    Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

                    "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

                    So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

                    The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

                    gurre@mastodon.nuG This user is from outside of this forum
                    gurre@mastodon.nuG This user is from outside of this forum
                    gurre@mastodon.nu
                    wrote sidst redigeret af
                    #9

                    @tante
                    Hadn't heard of "Hugging Face" before. Running out of evil things in Tolkien to name companies & systems for, I guess so here's the face hugger from Alien to be an AI overlord. Lovely.

                    txo_elurmaluta@mastodon.eusT 1 Reply Last reply
                    0
                    • pascoda@chaos.socialP pascoda@chaos.social

                      @tante
                      what the HELL are cyber capabilities.

                      (OTOH, why am I trying to seek meaning in an OpenAI PR release.)

                      valpackett@social.treehouse.systemsV This user is from outside of this forum
                      valpackett@social.treehouse.systemsV This user is from outside of this forum
                      valpackett@social.treehouse.systems
                      wrote sidst redigeret af
                      #10

                      @pascoda @tante government / three letter agency / military speak for "offensive security tools n shit"

                      1 Reply Last reply
                      0
                      • tante@tldr.nettime.orgT tante@tldr.nettime.org

                        No, OpenAI's new magic models did not autonomously hack Huggingface.

                        Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

                        "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

                        So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

                        The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

                        valpackett@social.treehouse.systemsV This user is from outside of this forum
                        valpackett@social.treehouse.systemsV This user is from outside of this forum
                        valpackett@social.treehouse.systems
                        wrote sidst redigeret af
                        #11

                        @tante everything is "autonomous" when you put a for loop around it

                        1 Reply Last reply
                        0
                        • tante@tldr.nettime.orgT tante@tldr.nettime.org

                          No, OpenAI's new magic models did not autonomously hack Huggingface.

                          Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

                          "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

                          So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

                          The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

                          michelin@hachyderm.ioM This user is from outside of this forum
                          michelin@hachyderm.ioM This user is from outside of this forum
                          michelin@hachyderm.io
                          wrote sidst redigeret af
                          #12

                          @tante I don't feel any particular sympathy for the target in this case, but in general ... when this happens shouldn't the company (OpenAI) be held liable?

                          If during a weapons evaluation a stray drone accidentally hit a power plant I'm sure the plant owners (and maybe the local residents) would want compensation

                          tante@tldr.nettime.orgT amethyst@chaos.socialA 2 Replies Last reply
                          0
                          • michelin@hachyderm.ioM michelin@hachyderm.io

                            @tante I don't feel any particular sympathy for the target in this case, but in general ... when this happens shouldn't the company (OpenAI) be held liable?

                            If during a weapons evaluation a stray drone accidentally hit a power plant I'm sure the plant owners (and maybe the local residents) would want compensation

                            tante@tldr.nettime.orgT This user is from outside of this forum
                            tante@tldr.nettime.orgT This user is from outside of this forum
                            tante@tldr.nettime.org
                            wrote sidst redigeret af
                            #13

                            @michelin well they worked together with Huggingface (on PR and telling them about a bug they may or may not have found). So unless Huggingface sues them who would attack OpenAI?

                            jeffgrigg@mastodon.socialJ 1 Reply Last reply
                            0
                            • michelin@hachyderm.ioM michelin@hachyderm.io

                              @tante I don't feel any particular sympathy for the target in this case, but in general ... when this happens shouldn't the company (OpenAI) be held liable?

                              If during a weapons evaluation a stray drone accidentally hit a power plant I'm sure the plant owners (and maybe the local residents) would want compensation

                              amethyst@chaos.socialA This user is from outside of this forum
                              amethyst@chaos.socialA This user is from outside of this forum
                              amethyst@chaos.social
                              wrote sidst redigeret af
                              #14

                              @michelin @tante I'm more wondering why there is not a huge public outrage about letting such models run loose... in particular in view of the current hype of using AI in weapons development this is immensively scary.

                              michelin@hachyderm.ioM 1 Reply Last reply
                              0
                              • davidgerard@circumstances.runD davidgerard@circumstances.run

                                @tante a friend suggests it's co-marketing with Huggingface, if you look at the timeline of announcements

                                erlenmayr@chaos.socialE This user is from outside of this forum
                                erlenmayr@chaos.socialE This user is from outside of this forum
                                erlenmayr@chaos.social
                                wrote sidst redigeret af
                                #15

                                @davidgerard @tante The whole story was implausible from the second sentence: Where Huggingface claims that their “AI” detected the attack.

                                abucci@buc.ciA 1 Reply Last reply
                                0
                                • hagen@mastodon.socialH hagen@mastodon.social

                                  @tante but it was impossible to envision that their zero day machine would be able to escape their vibecoded sandbox that ran on a machine connected to the internet. nobody could ever guess that this would happen!

                                  sonofsuntzu@mastodon.socialS This user is from outside of this forum
                                  sonofsuntzu@mastodon.socialS This user is from outside of this forum
                                  sonofsuntzu@mastodon.social
                                  wrote sidst redigeret af
                                  #16

                                  @hagen @tante I don't know, I'd want details on "To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy." and "the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path" before dismissing this...

                                  hagen@mastodon.socialH jeffgrigg@mastodon.socialJ 2 Replies Last reply
                                  0
                                  • sonofsuntzu@mastodon.socialS sonofsuntzu@mastodon.social

                                    @hagen @tante I don't know, I'd want details on "To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy." and "the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path" before dismissing this...

                                    hagen@mastodon.socialH This user is from outside of this forum
                                    hagen@mastodon.socialH This user is from outside of this forum
                                    hagen@mastodon.social
                                    wrote sidst redigeret af
                                    #17

                                    @SonOfSunTzu @tante that’s what mythos did as well though? you point at something and say go and if you’re willing to pay for compute it goes. it literally did what it was meant to do – and was explicitly told to do. what’s the news here?

                                    sonofsuntzu@mastodon.socialS 1 Reply Last reply
                                    0
                                    • tante@tldr.nettime.orgT tante@tldr.nettime.org

                                      @pascoda don't it was mostly generated by an LLM.

                                      supermoosie@mastodon.auS This user is from outside of this forum
                                      supermoosie@mastodon.auS This user is from outside of this forum
                                      supermoosie@mastodon.au
                                      wrote sidst redigeret af
                                      #18

                                      @tante @pascoda

                                      Ohh look how powerful our model is. It can hack things

                                      If only there was a government military intelligence organisation that could give us a nice big fat contract

                                      1 Reply Last reply
                                      0
                                      • tante@tldr.nettime.orgT tante@tldr.nettime.org

                                        No, OpenAI's new magic models did not autonomously hack Huggingface.

                                        Per OpenAI's PR blog post (https://openai.com/index/hugging-face-model-evaluation-security-incident/😞

                                        "This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity."

                                        So they prompted their model running without guardrails to hack some shit. OpenAI told it to do that, the model didn't do shit autonomously (no LLM ever does anything autonomously, it's always prompted).

                                        The whole story is PR. We know that from Anthopic's Mythos: "Look we have this super secret new model and it's so powerful. We are scared ourselves. And you will soon be able to rent it!"

                                        miles_leif@mastodon.socialM This user is from outside of this forum
                                        miles_leif@mastodon.socialM This user is from outside of this forum
                                        miles_leif@mastodon.social
                                        wrote sidst redigeret af
                                        #19

                                        @tante How Tagesschau is reporting about it can only be described as refusal to practice journalism. 7 out of 9 paragraphs say "Open AI says" and the other two quote nameless "Experts" and Anthropic's product. And tomorrow I have to discuss with someone again about the possibility of consciousness in token generator software https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html

                                        jeffgrigg@mastodon.socialJ yhancik@thereisno.computerY h0ru2@cyberplace.socialH 3 Replies Last reply
                                        0
                                        • gurre@mastodon.nuG gurre@mastodon.nu

                                          @tante
                                          Hadn't heard of "Hugging Face" before. Running out of evil things in Tolkien to name companies & systems for, I guess so here's the face hugger from Alien to be an AI overlord. Lovely.

                                          txo_elurmaluta@mastodon.eusT This user is from outside of this forum
                                          txo_elurmaluta@mastodon.eusT This user is from outside of this forum
                                          txo_elurmaluta@mastodon.eus
                                          wrote sidst redigeret af
                                          #20

                                          @Gurre @tante No to defend anyone but more to take that concern from you (I would also hate if they start using Alien universe names). The company is named after the hugging face emoji https://en.wikipedia.org/wiki/Hugging_Face

                                          jeffgrigg@mastodon.socialJ 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper