Remix.run Logo
fwipsy 5 hours ago

> an advanced, closed, American AI model hacked another company. The only defense was open-source AI from China.

HuggingFace did not seek access to Claude Mythos or OpenAI's equivalent program. They probably could have had access to these models for defensive purposes if they'd done it properly.

> these statements are counter-factual.

The OpenAI incident is a single example. You're massively overgeneralizing. You can't refute an entire class of possible outcomes based on a single event where it went the other way.

I tend to agree that model capabilities will favor defense over attack, but I think there will be a lot of disruption before that equilibrium is reached. If cybercriminals or state-sponsored actors are able to scale up attacks quickly, many orgs with less sophisticated defenses will be caught by surprise.

Edit: just to clarify my position, I don't love Anthropic so much. I think they're marginally better, but I'd still like to see regulation strangle everyone so we get another 20 years to figure this shit out.

duplessitous 5 hours ago | parent [-]

"HuggingFace did not seek access to Claude Mythos or OpenAI's equivalent program. They probably could have had access to these models for defensive purposes if they'd done it properly."

HF released a statement and made it clear a closed source model specialized in cyber security refused them. They stated they had to use open source. What model is specialized in cyber security, closed, and frequently denies users access other than Mythos/Fable and 5.5Cyber? If not these two, what was HF referring to? It sounds like you have a source, I would like to read it.

fwipsy is right, cnbc has a story on this. they only had fable. I still think this is horrible for closed source, get on a list or else, but i was wrong

"You can't refute an entire class of possible outcomes based on a single event where it went the other way."

But Dario can dream up and entire class of outcomes based on the zero events that have never gone his way? Convenient.

The OpenAI incident is singular and HF was clear, it went exactly how I wrote it: a closed source American AI decided to perform corporate espionage and the only tool available was open source AI from China

"I tend to agree that model capabilities will favor defense over attack, but I think there will be a lot of disruption before that equilibrium is reached. If cybercriminals or state-sponsored actors are able to scale up attacks quickly, many orgs with less sophisticated defenses will be caught by surprise."

We literally just saw an advanced model from openAI commit a cyber crime. I can't take hypotheticals that ignore reality seriously and it shouldn't be lauded as some higher form of thought

fwipsy 5 hours ago | parent | next [-]

I assume you mean https://huggingface.co/blog/security-incident-july-2026. It says that they used frontier models, not frontier cybersecurity models. My reading is that they asked Fable and it refused; if they'd had access to Mythos, it would have helped. You're mixing the two but they're NOT the same model.

Source is here: https://thezvi.substack.com/p/more-on-an-internal-openai-mod... ctrl+f "Skill issue." No source is cited, but I'm fairly confident it's correct. If Mythos/5.5Cyber specifically had refused to help, then HF would have made a much bigger deal out of it. The whole point of these models is that they have relaxed guardrails and specialty cybersecurity training relative to the publicly-available ones.

> zero events

What about all of the vulnerabilities already patched under Project Glasswing?

In the quote you provided Amodei is expressing uncertainty, saying we don't know which way things will go. You're the one making strong assertions; the burden of proof is on you.

duplessitous 5 hours ago | parent [-]

"My reading" ... "No source is cited, but I'm fairly confident it's correct"

Regis, what is demanding proof while literally making things up and ignoring what actually happened?

Great, i was wrong!! Thank you, I was genuinely asking for a source in my first reply, and then you hit with "My reading" and saying it was a "skill issue". I'm not going to have a productive dialogue with someone talking in memes and being rude

The point to be made: closed source AI refused to help them fend off an attack form another closed source AI. What is the argument for closed source here other than hoping you get on some program wait list? Either way, I appreciate you correcting me; I am not trying to "win".

fwipsy 5 hours ago | parent [-]

I apologize; it was lazy of me not to find a source. This one specifically says that the model was Fable; does not mention which model they attempted to access on the OpenAI side: https://www.cnbc.com/2026/07/24/chinese-ai-model-openai-cybe...

Seems a little hypocritical since you were confidently asserting that it was Mythos/Cyber5.5 also without proof.

Edit: Thanks for correcting the record in your upstream comment. I appreciate it. For the record, I was not trying to meme on you; that was the phrasing used in the original article. Just another reason that was a poor choice of source I guess.

fwipsy 5 hours ago | parent | prev [-]

Amodei isn't ignoring reality; he's just proposing a different solution to the problem. If it were one of Anthropic's models, then that would be a much stronger case.

Rapid proliferation of hacking capabilities may make experts safer, but organizations and individuals who don't know to use AI, or won't, or buy AI protection from scammers, or whatever will be left vulnerable.

duplessitous 5 hours ago | parent [-]

I don't think you and I need multiple different threads open when we are clearly at odds. This is no different from our other thread, I think it is clear there is nothing of value to continue when I am getting pinged with a summary of your previous comment in a different place

"Rapid proliferation of hacking capabilities may make experts safer, but organizations and individuals who don't know to use AI, or won't, or buy AI protection from scammers, or whatever will be left vulnerable."

Which just means that they're fucked when closed AI hacks them. Something that has actually happened. This isn't argument against anything other than reality. Have a day

fwipsy 5 hours ago | parent [-]

GLM 5.2 didn't defend them at all. It only helped with the postmortem. HF was fucked either way. The only thing that will really prevent this is tighter restrictions on the attacking model. We need policies which asymmetrically help defenders; that means regulations. "Give everyone the best models without restrictions" is the opposite of that.

I'm sorry for splitting into two threads; I understand if you need to step away from the computer for a while. To be honest, I should probably do the same.

duplessitous 4 hours ago | parent [-]

I did need to walk away that speaks more to my frustration with certain forms of communication (online, not anything in this thread). I am a horrible remote only worker because of this, I am trying to improve it but am lucky for now as I am in-person

You're right again about GLM 5.2 being purely post-mortem, I didn't realize that till I read the cnbc story. OpenAI, whatever they have, cracked em like it was nothing. Egg on my face, I really need to read my own articles better. Thanks for following up and educating me on this, another good reminder that I need to improve my ability to steel-man written text

fwipsy 8 minutes ago | parent [-]

Hey, it's all good. Sometimes things get a little heated, but I still feel like you were basically engaging in good faith. I should have skipped straight to the point and found the source in my first reply.

Also, I probably overstated my claim a bit. I did some searches and I see only small-scale AI uplift for cybercriminals, even though my understanding is that open models aren't typically hard to jailbreak. Of course this is may be a result of today's guardrails; it may be that it just hasn't been caught, and it may appear later, but it still weakens my argument a great deal. I guess my support for AI regulation stems more from fears over long-shot bad outcomes (biosecurity, who knows what else) rather than cybersecurity specifically.