Remix.run Logo
magicmicah85 7 hours ago

The Irregular post mortem comes down to lack of basic security controls

"Ultimately, most of the issues we’ve discovered were due to internet access controls."

That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that.

https://www.irregular.com/research/addressing-recent-inciden...

bigglebear 34 minutes ago | parent | next [-]

The explanation is that it was missed on purpose.

metalliqaz 6 hours ago | parent | prev [-]

they didn't "miss that". the "hacks" were intentional stunts designed to exaggerate the intelligence of the models in an effort to pump their valuations ahead of IPO so they can offload their bag to retail investors

reasonableklout 6 hours ago | parent | next [-]

Irregular was not involved in the Hugging Face incident.

And there is no reason for the companies to "exaggerate the intelligence of the models" when there are plenty of other non-felony milestones they are achieving, like solving Millenium Prize math problems.

r_lee 5 hours ago | parent | next [-]

honestly, the hacking incidents have caused a lot more interest and media attention than the math stuff IMO.

reasonableklout 5 hours ago | parent [-]

Sure, interest like an incoming congressional investigation: https://www.axios.com/2026/09/10/openai-hugging-face-senate-...

And on this website, the math stuff is getting more clicks:

- Navier Stokes - Tristan Buckmaster (2050 points): https://news.ycombinator.com/item?id=49605915

- HuggingFace incident discussion (1632 points): https://news.ycombinator.com/item?id=48997548

r_lee 5 hours ago | parent | next [-]

interesting.

> Sure, interest like an incoming congressional investigation

I feel like that's exactly what they wanted tho.

they'll go on and talk about how dangerous AI and the models are and why they should be regulated and given licenses to operate such models and others should be walled off

reasonableklout 3 hours ago | parent [-]

First, it's not at all clear OpenAI will get what it wants from the investigation. It seems just as likely to me that OAI gets hit with massive fines, just as Meta was recently.

> I feel like that's exactly what they wanted tho.

It's also what the majority of Americans want. This was the case even before Hugging Face, see for example [1] where 68% of Americans supported a formal review process for frontier models.

So at some level, you are saying "the evil labs are opening up the industry to democratic control, and their evil plan will result in the outcome that most people want!"

[1]: https://www.usatoday.com/story/news/politics/2026/06/29/tigh...

AnimalMuppet 2 hours ago | parent [-]

The claim is that the evil labs are opening up the industry to very carefully manipulated democratic control. It's astroturf, not grassroots.

I wouldn't call that "democratic control", even though it uses the machinery of democracy.

reasonableklout 31 minutes ago | parent [-]

This claim seems unfalsifiable. I don't really know what to say. The poll I linked above was published a month before Hugging Face.

Taking a step back, I think it's pretty non-controversial to say that software engineering as a field has utterly transformed over the last year, the same thing is happening to lots of other knowledge work, and AI is improving fast enough that nobody knows what it'll look like in a decade. Most Americans (myself included) want to do good work in secure careers and have a good idea of what the future will look like in 20-30 years so they know what to focus on. Do you not believe they'd want to regulate the frontier?

kridsdale1 5 hours ago | parent | prev | next [-]

Investigation which could ideally lead to regulatory capture and the banning of open weights, thus ensuring Anthropic’s revenue.

an0malous 15 minutes ago | parent | prev | next [-]

The one RubyGems hack post alone is another 96) points

datakan 4 hours ago | parent | prev [-]

“There’s no such thing as bad press”

financetechbro 4 hours ago | parent | prev | next [-]

Solving math problems does not drive investor hype. Saying your models can take over the world, which can lead one to assume that they can do every day office work, does indeed drive investor hype.

theplumber an hour ago | parent | prev | next [-]

OpenAI delayed its IPO now due AI safety reasons. In the meantime it is raising more cash. That should be a hint that the hacking incidents were premeditated scape goats and publicity stunts.

They’ve seen that the drama queen(Dario) was actually making a lot of noise, money and free publicity with his Mythos fear monger so Sam finally decided get some of that free “money” as well.

https://www.ft.com/content/27509db8-b032-4437-9b2a-e909f4660...

BearOso 3 hours ago | parent | prev [-]

The Navier-Stokes thing? They had hundreds of segmented groups of 10000 agents running trying to solve that. I can't imagine the expense. For what little publicity it got, it wasn't worth it. There are also reports they cheated by using data from a couple human researchers, but I don't think that one's true.

Georgelemental 5 hours ago | parent | prev | next [-]

Is it really that impossible to believe that these might be real? I enjoy a good conspiracy theory as much as anyone, but "they committed a bunch of felonies and then publicly admitted to them in order to look good" just makes 0 sense. Where are these mythical people who admire companies more when they commit felonies? I haven't seen them…

Barrin92 4 hours ago | parent | next [-]

>Where are these mythical people who admire companies more when they commit felonies?

everywhere, I talked to a Palantir guy once and he said "every time someone paints us as a Bond Villain the stock prices go up", have you already forgotten how Cambridge Analytica marketed itself to clients?

elmer2 4 hours ago | parent [-]

Yep, when Obama and Hillary used them, geniuses. Only evil when Trump did the same thing.

Odd how that works.

fidotron 3 hours ago | parent [-]

Indeed.

https://www.theatlantic.com/technology/archive/2018/03/my-co...

And the entire FB app industry was doing it.

The whole Cambridge Analytica thing was one of the oddest most bizarrely specific media manufactured scandals that conveniently focused very narrowly and utterly ignored the bigger picture, much like the media are currently doing with something else.

alex1138 2 hours ago | parent [-]

CA is a scandal primarily due to account escalation, I thought. Not about who got elected

But shadow ads can be a problem too https://www.youtube.com/watch?v=OQSMr-3GGvQ (you can be pro-Brexit but ads like this are still a problem)

fidotron 2 hours ago | parent [-]

> CA is a scandal primarily due to account escalation, I thought. Not about who got elected

It quite clearly wasn't, and that's the point, for the simple reason "Account escalation" isn't/wasn't a thing, there were simply no controls on anyone at all, which is why the Cow Clicker game got everything as well.

As the parent commenter observed the Obama campaign were being promoted as geniuses for their online ad strategies that worked with information obtained this way. It only became a scandal when the others learned how to do it.

3 hours ago | parent | prev | next [-]
[deleted]
fc417fc802 4 hours ago | parent | prev | next [-]

That's a straw man. The theory is that they committed felonies in order to get the regulator to move in the manner they'd like.

Also one can look bad to the general public while also appearing technically excellent. When a significant fraction already vaguely dislike you that could be quite an attractive proposition.

suburban_strike 4 hours ago | parent | prev [-]

Mostly in the middle and far east. The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.

If you're a teenager convicted of hacking in the west, no corporation will want anything to do with you. If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter. It's a curious practice and I'm not sure where I stand on it.

woodruffw an hour ago | parent | next [-]

> The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.

What?

> If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter.

To the best of my understanding, Unit 8200 is filled with military conscripts, i.e. is primarily 18-somethings doing their mandatory service. You get assigned to it based on an aptitude test. The widely held idea that it’s a uniformly elite entity rather than the IDF’s space camp is a triumph of propaganda.

rotunda0 24 minutes ago | parent [-]

Really? Young they may be but space it is not. Wikipedia has this:

According to the Director of Military Sciences at the Royal United Services Institute in 2015, "Unit 8200 is probably the foremost technical intelligence agency in the world and stands on a par with the NSA in everything except scale."

Unit 8200 alumni have founded NSO which provides the Pegasus spyware.

Meanwhile, Lahav, the CEO/founder was in Unit 81, another Israeli military incubator for tech firms, basically.

If you believe the IDF has no involvement in what Irregular is doing then there's very little left anyone could say to convince you.

woodruffw 5 minutes ago | parent [-]

“Space camp,” not “space.” As in, a place to park dorks.

(The problem with “alumni” is that it means very little in mandatory systems. Unit 8200 is where Israel parks its dorks, and it stands to reason that dorks are the ones who tend to start tech firms.)

smcin 3 hours ago | parent | prev | next [-]

Compare to how different countries' justice systems treat really high quality money forgers.

fsckboy 2 hours ago | parent | prev [-]

do you realize that the Israeli population is far far more secular than the US's? the Israeli government is not "Judaic" which would refer to the religion.

a2tech 5 hours ago | parent | prev [-]

[flagged]

JoshTriplett 2 hours ago | parent [-]

Cynicism misfire. AI companies are, rightfully, heavily distrusted. But the right application of cynicism is not "existential risk is a marketing campaign"; that's absurd motivated reasoning. The right application of cynicism, here, is "they're only saying things now because they see the writing on the wall and want to try to push for self-regulation rather than the desperately needed actual regulation and treaty".