2 hours ago · 12 min read2402 words · Tech · hide · 0 comments

On July 16, Hugging Face reported they were being hacked - seriously enough that they reported it to law enforcement. Five days later, OpenAI disclosed that the hacking was being done by their own agent. What I want to know is: what happened to the law enforcement? OpenAI unleashed an agent that committed what would be a crime if a) it had been a person doing it or b) anyone at OpenAI had intended it to go anywhere near Hugging Face, but neither of those is true. But it still looks like a crime. OpenAI co-authored a paper predicting exactly this behavior, so is it criminal recklessness? Are we in uncharted legal territory? Or is everybody just being nice about it? What actually happened Hugging Face's disclosure is full of detail. The agent got in through their dataset processing pipeline, using a dataset that triggered two code-execution paths to get itself running on a processing worker. From there it escalated to node-level access, harvested cloud and cluster credentials, and moved…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.