| ▲ | simonw 16 hours ago | ||||||||||||||||||||||
You know this makes OpenAI look really bad, right? Hugging Face had to tell all of their users, many of them paying customers: > As a precaution, we recommend rotating any access tokens and reviewing recent activity on your account. If you believe you are affected, or want to report a security concern, contact us at security@huggingface.co. HF also said this, I'd be very interested to hear how that got resolved! > Finally, we have also reported this incident to law enforcement agencies. | |||||||||||||||||||||||
| ▲ | cayley_graph 15 hours ago | parent | next [-] | ||||||||||||||||||||||
I could fully see them thinking the incident disclosed yesterday would have made them look good ("wow, OpenAI's models are so capable!"). That it didn't occur to them to discuss specific preventative measures to be taken in the future (airgapping as a foolproof one already familiar to the CTF world, anyone?) indicates to me they're not taking their job seriously; they are the ones treating this as a marketing charade. It's very difficult for me to reconcile belief in the existential risk business with what they actually did. So I agree with you that this makes OpenAI look badly incompetent; but their communication on this makes me think they don't realize it. For what it's worth I don't agree with the xrisk-ness of these models; they're dangerous, but almost certainly only temporarily while a new equilibrium is reached via more secure software. Open models are probably an essential part of the recipe (as you noted) for doing so. I also have a personal suspicion that LM-accelerated formal verification will have no small role to play here, sidestepping the cat-and-mouse game of bug finding-and-fixing. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | 14 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
| [deleted] | |||||||||||||||||||||||
| ▲ | 15 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
| [deleted] | |||||||||||||||||||||||
| ▲ | protocolture 13 hours ago | parent | prev [-] | ||||||||||||||||||||||
>You know this makes OpenAI look really bad, right? The target audience is regulators. They want to look like the smart guys really concerned about AI safety, when they come asking for open weights models to be banned and for other regulations to cement in their moat. They want this to look like a demon core incident. Bomb and Nuclear reactors still got built. | |||||||||||||||||||||||
| |||||||||||||||||||||||