Home | Notifications | New Note | Local | Federated | Search | Logout

Note Detail


Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 05:41:50)
OpenAI accidentally hacks Hugging Face. But it's more wild than that https://openai.com/index/hugging-face-model-evaluation-security-incident/

OpenAI was running an exploit test system in a sandbox. Their model determined that probably Hugging Face had model information that would be useful to complete the task, so it broke out of its sandbox, developed an exploit, broke into Hugging Face to go rooting around for information
---Reply--- Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 05:42:17) Meanwhile Linux publishes 432 Linux kernel CVEs https://lore.kernel.org/linux-cve-announce/

There is only one path out of this. We need a *fully auditable, formally verified, and human-understandable* capability-secure trusted computing base as the foundation of our operating systems.

Otherwise... we're just toast.
Reply

---Replies---
Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 21:31:00)
To those saying the OpenAI + Hugging Face thing is an ad, I think that's true, but I think it's not just an ad. They're taking the marketing opportunity for sure, and it's *awfully convenient* that it's two AI companies as part of the story, right?

But, despite being a big critic of this stuff, I do think that they are *very good at attacking systems*. The reason being that most attacks tend to have very similar patterns, and these models are great at blasting similar patterns over and over again, so they can ruthlessly find their way through exploits.

The bigger question to me is: which examples *aren't* there motivations for two companies to put out statements together? Where else has stuff like this happened?

And the more important one, the response I think they *want* people to hear is "our stuff is so scary and powerful, you have to use and trust even more of our vibetech".

But that's not MY takeaway...