AI vendors can't be trusted to secure their systems. Newsrooms need to act accordingly 0 ▲ Ben Werdmuller 2 hours ago · Tech · hide · 0 comments Link: How OpenAI’s human mistake led to the AI-powered hack on Hugging Face, by Lorenzo Franceschi-Bicchierai in TechCrunchThe biggest technology story this week was how a combination of OpenAI models hacked into third-party AI provider Hugging Face and breached its production database. The incident was initially spun as a sort of partnership between the two companies, but it seems like that’s not what went down at all.“OpenAI failed to properly configure what it called a ‘highly isolated environment,’ allowing a testing sandbox that should have been completely secluded from the internet to actually connect to the internet.”That’s actually one of at least two lapses here: not only did OpenAI fail to properly isolate its models, but Hugging Face’s production database was in a state where those models could hack into it. The whole thing does not speak well of security practices at AI vendors overall.We’re being asked to share more and more private information with model vendors. The… No comments yet. Log in to reply on the Fediverse. Comments will appear here.