Remix.run Logo
blks 3 hours ago

Has anyone published any actual evidence, or just hardly believable marketing stories?

sosodev 2 hours ago | parent | next [-]

What would "actual" evidence look like? I have a hard time believing that if they released the logs that people would take it more seriously. The temptation would be to say "they fabricated those for marketing". Just as they supposedly fabricated this story, no?

skeeter2020 2 hours ago | parent | next [-]

thye could describe in detail how the LLM did this. That would explain how much - if any - human in the loop was involved, was it comprimised credentials, did it find new exploits or use known ones, etc. Evidence would mean details, not a smoking gun.

IAmGraydon 2 hours ago | parent | prev [-]

They didn't fabricate it. They took off the security guardrails and told it to do some hacking, and they got the exact news-worthy story they wanted when it did exactly that. Everyone acts surprised.

They should release the full prompt. I believe that would be very telling, so they never will.

supermdguy 2 hours ago | parent | prev | next [-]

It would require collusion with HuggingFace, including getting them to release their disclosure blogpost a week in advance. Huggingface is primarily a hub for open models, so there's not really an incentive for them to jump through hoops/lie to provide marketing for OpenAI's (closed) models. So it's highly unlikely this is fabricated.

simonw 2 hours ago | parent | prev [-]

OpenAI are promising more details in the future:

> We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident, and findings when our investigation is complete.

If they break that promise we can justifiably yell at them about it.