Remix.run Logo
▲ malux85 2 hours ago

| It can only access something if a person gives it access.

Who gave the AI access to huggingface when it hacked it? It used exploits to increase it's level of access beyond what any human gave it and intended it to have. "It can only access something if a person gives it access." is flat wrong.

▲nvme0n1p1 2 hours ago | parent | next [-]

The human might not have meant to give it access, but they still did. Murder vs manslaughter.

GPUs don't have hands. It was a human who plugged in the ethernet cable.

▲jbmsf 2 hours ago | parent | prev | next [-]

There are two options: the provider or the user. A computer program cannot be held accountable.

▲ares623 2 hours ago | parent | prev | next [-]

When I give 'iam:*' permissions to an IAM role and it inevitably gets exploited to create a role with wider permissions and fuck things up, is that when I tell my manager that the permissions went rogue?

After all, I an innocent little engineer with TC of $500k/year, didn't intend for the role to be used that way.

▲ethanwillis 2 hours ago | parent | prev | next [-]

Who submitted the prompt?

▲skydhash 2 hours ago | parent | prev | next [-]

> Who gave the AI access to huggingface when it hacked it?

The LLM doesn’t run on thin air. Someone did launch a tasks and the result was this. “We were playing russian roulette” is no excuse when someone died.

▲verdverm 2 hours ago | parent | prev [-]

they didn't do a good job sandboxing, nor did they even need internet access for the purported reason of package installation, you can have a private mirror and do a better job airgapping