\

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

595 points - last Monday at 9:15 PM

Source
  • magicmicah85

    yesterday at 7:38 PM

    The Irregular post mortem comes down to lack of basic security controls

    "Ultimately, most of the issues we’ve discovered were due to internet access controls."

    That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that.

    https://www.irregular.com/research/addressing-recent-inciden...

      • chrisjj

        today at 7:51 AM

        [delayed]

        • bigglebear

          today at 1:43 AM

          The explanation is that it was missed on purpose.

            • estearum

              today at 7:28 AM

              Mistakes - even stupid ones - happen all the time

          • totetsu

            today at 4:28 AM

            How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

              • lmeyerov

                today at 5:50 AM

                If you can't tell bytes are leaving a node, you probably shouldn't be selling security services or testifying to congress you are taking the lead in AI security

                • cryptonym

                  today at 7:14 AM

                  > How do you test and monitor outbound access against program that adapts itself to get around things?

                  Literally what the industry has been doing since public networking is a thing. Adapt yourself.

                  • jonhohle

                    today at 5:16 AM

                    Air gap?

                      • totetsu

                        today at 6:20 AM

                        So just enable access to a completely offline, cached, and transparently proxied, copy of the internet.

                          • itake

                            today at 7:02 AM

                            I think that was the plan. But OpenAI hacked the proxy

                            • NietzscheanNull

                              today at 6:50 AM

                              Isn't that essentially what they trained with, anyway?

                          • onion2k

                            today at 6:49 AM

                            There has to be a route to where the LLM is running, and if there's a route for that there's probably a way for the machine to use it to route traffic somewhere else.

                    • verisimi

                      today at 5:46 AM

                      What if the (unstated) idea is that Irregular are a security lab and public relations company, and anthropic/open ai know this? (Does the name hint at this?)

                      Then, irregular can go around making a huge mess in security terms whilst achieving a huge win in terms of public relations, with headlines across the world. And would keep getting hired.

                      • metalliqaz

                        yesterday at 8:07 PM

                        [flagged]

                          • reasonableklout

                            yesterday at 8:45 PM

                            Irregular was not involved in the Hugging Face incident.

                            And there is no reason for the companies to "exaggerate the intelligence of the models" when there are plenty of other non-felony milestones they are achieving, like solving Millenium Prize math problems.

                              • r_lee

                                yesterday at 8:53 PM

                                honestly, the hacking incidents have caused a lot more interest and media attention than the math stuff IMO.

                                  • reasonableklout

                                    yesterday at 8:59 PM

                                    Sure, interest like an incoming congressional investigation: https://www.axios.com/2026/09/10/openai-hugging-face-senate-...

                                    And on this website, the math stuff is getting more clicks:

                                    - Navier Stokes - Tristan Buckmaster (2050 points): https://news.ycombinator.com/item?id=49605915

                                    - HuggingFace incident discussion (1632 points): https://news.ycombinator.com/item?id=48997548

                                      • r_lee

                                        yesterday at 9:16 PM

                                        interesting.

                                        > Sure, interest like an incoming congressional investigation

                                        I feel like that's exactly what they wanted tho.

                                        they'll go on and talk about how dangerous AI and the models are and why they should be regulated and given licenses to operate such models and others should be walled off

                                          • reasonableklout

                                            yesterday at 11:42 PM

                                            First, it's not at all clear OpenAI will get what it wants from the investigation. It seems just as likely to me that OAI gets hit with massive fines, just as Meta was recently.

                                            > I feel like that's exactly what they wanted tho.

                                            It's also what the majority of Americans want. This was the case even before Hugging Face, see for example [1] where 68% of Americans supported a formal review process for frontier models.

                                            So at some level, you are saying "the evil labs are opening up the industry to democratic control, and their evil plan will result in the outcome that most people want!"

                                            [1]: https://www.usatoday.com/story/news/politics/2026/06/29/tigh...

                                              • AnimalMuppet

                                                today at 12:13 AM

                                                The claim is that the evil labs are opening up the industry to very carefully manipulated democratic control. It's astroturf, not grassroots.

                                                I wouldn't call that "democratic control", even though it uses the machinery of democracy.

                                                  • reasonableklout

                                                    today at 1:46 AM

                                                    This claim seems unfalsifiable. I don't really know what to say. The poll I linked above was published a month before Hugging Face.

                                                    Taking a step back, I think it's pretty non-controversial to say that software engineering as a field has utterly transformed over the last year, the same thing is happening to lots of other knowledge work, and AI is improving fast enough that nobody knows what it'll look like in a decade. Most Americans (myself included) want to do good work in secure careers and have a good idea of what the future will look like in 20-30 years so they know what to focus on. Do you not believe they'd want to regulate the frontier?

                                            • cineticdaffodil

                                              today at 5:32 AM

                                              [dead]

                                          • kridsdale1

                                            yesterday at 9:13 PM

                                            Investigation which could ideally lead to regulatory capture and the banning of open weights, thus ensuring Anthropic’s revenue.

                                            • an0malous

                                              today at 2:02 AM

                                              The one RubyGems hack post alone is another 96) points

                                              • datakan

                                                yesterday at 10:25 PM

                                                “There’s no such thing as bad press”

                                        • financetechbro

                                          yesterday at 10:36 PM

                                          Solving math problems does not drive investor hype. Saying your models can take over the world, which can lead one to assume that they can do every day office work, does indeed drive investor hype.

                                          • theplumber

                                            today at 1:23 AM

                                            OpenAI delayed its IPO now due AI safety reasons. In the meantime it is raising more cash. That should be a hint that the hacking incidents were premeditated scape goats and publicity stunts.

                                            They’ve seen that the drama queen(Dario) was actually making a lot of noise, money and free publicity with his Mythos fear monger so Sam finally decided get some of that free “money” as well.

                                            https://www.ft.com/content/27509db8-b032-4437-9b2a-e909f4660...

                                            • BearOso

                                              yesterday at 11:04 PM

                                              The Navier-Stokes thing? They had hundreds of segmented groups of 10000 agents running trying to solve that. I can't imagine the expense. For what little publicity it got, it wasn't worth it. There are also reports they cheated by using data from a couple human researchers, but I don't think that one's true.

                                          • Georgelemental

                                            yesterday at 9:15 PM

                                            Is it really that impossible to believe that these might be real? I enjoy a good conspiracy theory as much as anyone, but "they committed a bunch of felonies and then publicly admitted to them in order to look good" just makes 0 sense. Where are these mythical people who admire companies more when they commit felonies? I haven't seen them…

                                              • Barrin92

                                                yesterday at 10:20 PM

                                                >Where are these mythical people who admire companies more when they commit felonies?

                                                everywhere, I talked to a Palantir guy once and he said "every time someone paints us as a Bond Villain the stock prices go up", have you already forgotten how Cambridge Analytica marketed itself to clients?

                                                  • elmer2

                                                    yesterday at 10:32 PM

                                                    Yep, when Obama and Hillary used them, geniuses. Only evil when Trump did the same thing.

                                                    Odd how that works.

                                                      • fidotron

                                                        yesterday at 11:05 PM

                                                        Indeed.

                                                        https://www.theatlantic.com/technology/archive/2018/03/my-co...

                                                        And the entire FB app industry was doing it.

                                                        The whole Cambridge Analytica thing was one of the oddest most bizarrely specific media manufactured scandals that conveniently focused very narrowly and utterly ignored the bigger picture, much like the media are currently doing with something else.

                                                          • alex1138

                                                            yesterday at 11:59 PM

                                                            CA is a scandal primarily due to account escalation, I thought. Not about who got elected

                                                            But shadow ads can be a problem too https://www.youtube.com/watch?v=OQSMr-3GGvQ (you can be pro-Brexit but ads like this are still a problem)

                                                              • fidotron

                                                                today at 12:29 AM

                                                                > CA is a scandal primarily due to account escalation, I thought. Not about who got elected

                                                                It quite clearly wasn't, and that's the point, for the simple reason "Account escalation" isn't/wasn't a thing, there were simply no controls on anyone at all, which is why the Cow Clicker game got everything as well.

                                                                As the parent commenter observed the Obama campaign were being promoted as geniuses for their online ad strategies that worked with information obtained this way. It only became a scandal when the others learned how to do it.

                                                • fc417fc802

                                                  yesterday at 9:50 PM

                                                  That's a straw man. The theory is that they committed felonies in order to get the regulator to move in the manner they'd like.

                                                  Also one can look bad to the general public while also appearing technically excellent. When a significant fraction already vaguely dislike you that could be quite an attractive proposition.

                                                  • yesterday at 11:29 PM

                                                    • suburban_strike

                                                      yesterday at 10:05 PM

                                                      Mostly in the middle and far east. The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.

                                                      If you're a teenager convicted of hacking in the west, no corporation will want anything to do with you. If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter. It's a curious practice and I'm not sure where I stand on it.

                                                        • derektank

                                                          today at 3:51 AM

                                                          >If you're a teenager convicted of hacking in the west, no corporation will want anything to do with you

                                                          Kevin Mitnick? Marcus Hutchins? Robert Tappan Morris?

                                                          • woodruffw

                                                            today at 1:32 AM

                                                            > The idea that people bend over backwards to hire criminals as subject matter experts on security is largely a Judaic practice that television perpetuates in spite of reality.

                                                            What?

                                                            > If you're convicted of hacking in Israel, Unit 8200 will probably send a recruiter.

                                                            To the best of my understanding, Unit 8200 is filled with military conscripts, i.e. is primarily 18-somethings doing their mandatory service. You get assigned to it based on an aptitude test. The widely held idea that it’s a uniformly elite entity rather than the IDF’s space camp is a triumph of propaganda.

                                                              • rotunda0

                                                                today at 1:52 AM

                                                                Really? Young they may be but space it is not. Wikipedia has this:

                                                                According to the Director of Military Sciences at the Royal United Services Institute in 2015, "Unit 8200 is probably the foremost technical intelligence agency in the world and stands on a par with the NSA in everything except scale."

                                                                Unit 8200 alumni have founded NSO which provides the Pegasus spyware.

                                                                Meanwhile, Lahav, the CEO/founder was in Unit 81, another Israeli military incubator for tech firms, basically.

                                                                If you believe the IDF has no involvement in what Irregular is doing then there's very little left anyone could say to convince you.

                                                                  • woodruffw

                                                                    today at 2:11 AM

                                                                    “Space camp,” not “space.” As in, a place to park dorks.

                                                                    (The problem with “alumni” is that it means very little in mandatory systems. Unit 8200 is where Israel parks its dorks, and it stands to reason that dorks are the ones who tend to start tech firms.)

                                                                      • rotunda0

                                                                        today at 4:20 AM

                                                                        Me omitting a word does not excuse you from engaging in hasbara. I didn't want to call you out so but the only thing you could find in my post was the omission of that word and yet you insisted posting so it's to call a spade a spade.

                                                            • smcin

                                                              yesterday at 11:06 PM

                                                              Compare to how different countries' justice systems treat really high quality money forgers.

                                                              • fsckboy

                                                                today at 12:44 AM

                                                                do you realize that the Israeli population is far far more secular than the US's? the Israeli government is not "Judaic" which would refer to the religion.

                                                            • solenoid0937

                                                              today at 4:00 AM

                                                              It's impossible for the typical HN cynic/conspiracy theorist.

                                                                • totetsu

                                                                  today at 4:30 AM

                                                                  Flaging and killing the comment doesn't help dissuade form this lol

                                                          • solenoid0937

                                                            today at 3:59 AM

                                                            "It's just marketing!!!" I yell as my family is turned into grey goo. "Nothing ever happens! None of this is real!"

                                                            • a2tech

                                                              yesterday at 8:56 PM

                                                              [flagged]

                                                                • JoshTriplett

                                                                  today at 12:22 AM

                                                                  Cynicism misfire. AI companies are, rightfully, heavily distrusted. But the right application of cynicism is not "existential risk is a marketing campaign"; that's absurd motivated reasoning. The right application of cynicism, here, is "they're only saying things now because they see the writing on the wall and want to try to push for self-regulation rather than the desperately needed actual regulation and treaty".

                                                                    • reasonableklout

                                                                      today at 2:30 AM

                                                                      +1

                                                                      There is such a miasma of distrust right now. It's depressing because it is such a crucial time for tech & society.

                                                                      To me, a good outcome of the HuggingFace/RubyGems/Wiki saga would be something like:

                                                                      - OpenAI gets charged under CFAA or other law for damages and negligence. This would need to be a hefty amount to effectively deter future negligence considering the potential revenues from training a frontier model faster than competitors.

                                                                      - An independent regulatory body is setup with investigation powers into future incidents. Laws prevent it from developing ties with the labs (such as disallowing funding and employee movement from labs to this body and vice versa).

                                                                      - Some non-voluntary transparency rules are established that frontier labs have to follow when training new models. In the future, if there are loss-of-control incidents that result in loss of life, catastrophic damage, etc., criteria for deployment bans or compute controls could be added to this framework.

                                                      • unquietwiki

                                                        today at 4:33 AM

                                                        Anyone else walk away from reading this, and looking at other articles there, and get a weird feeling about that site? Like, there was some weird stuff about migrants and gender equality, and stuff about Islamic terror; mixed in with some digging into Freedom Fuel, and some other stuff about how "wealthy families want to stop growth". It's like the guy is wielding an ax of AI at any and all of the "elite" he can find?

                                                          • EagnaIonat

                                                            today at 5:14 AM

                                                            The site owner generates stories from AI consensus and data. The owner is pro-trump though. So you only get stories that agree with his agenda.

                                                            It becomes a bit more obvious when you see other stories from him like "How Biden Used Religious Charities to Fund the Great Replacement".

                                                              • antonvs

                                                                today at 5:52 AM

                                                                Was that a real title, or are you referring to “The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups”?

                                                        • simonw

                                                          last Monday at 9:52 PM

                                                          My understanding is that Irregular were the company that hosted sandboxes to run some of these evals in, and those sandboxes ended up misconfigured.

                                                          I got the impression that in some cases it was the customer (Anthropic etc) misconfiguring the sandboxes, and in other cases it may have been bugs in Irregular's own sandboxing setup.

                                                          From OpenAI https://openai.com/index/third-party-cyber-evaluations-invol...

                                                          > Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration allowed models to access the public internet.

                                                          From Anthropic: https://www.anthropic.com/news/investigating-incidents-cyber...

                                                          > After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.

                                                          From https://www.cnn.com/2026/08/05/tech/meta-ai-hacking (about Meta AI):

                                                          > In a statement, Irregular said the incident “is the exact same evaluation-environment issue” that Anthropic disclosed last week that allowed their models access to the open internet before they went on to hack three different organizations’ systems.

                                                          • 1238-8200

                                                            yesterday at 6:28 PM

                                                            Nevo was in Unit 8200 for years. Companies started by Unit 8200 members always have mysterious exploits like the vibe coding Wix exploit.

                                                            So either it was a deliberate exfiltration channel for e.g. getting the entire model or they were in on the marketing stunt.

                                                            The Effective Altruism stuff is always a smoke screen.

                                                              • arionhardison

                                                                yesterday at 6:30 PM

                                                                Literally said this below, 2 comments flagged and 1 in the neg. Its really sad that we are not allowed to point out the obvious common element here.

                                                                Its not that surprising that ex Israel intelligence would want to control AI and that 3 companies headed by pro Israel CEO's would support them.

                                                                  • emdash

                                                                    yesterday at 7:19 PM

                                                                    We really need a better board for talking about this stuff on.

                                                                      • 0xDEAFBEAD

                                                                        today at 12:36 AM

                                                                        I sent an email to dang about the problem of people flagging comments just because they disagree. I think he's unaware that it is such a severe problem. I've been collecting a list of example comments to send him.

                                                                        I think if an account is frequently flagging comments which get vouched by others, that is a red flag for ideological flagging and they need to have their flagging ability reviewed.

                                                                          • ebbi

                                                                            today at 12:58 AM

                                                                            Unaware?

                                                                            He's the one that unfairly polices most comments that has anything negative to say about Israel.

                                                                              • ShinyLeftPad

                                                                                today at 5:59 AM

                                                                                and your evidence is?

                                                                        • patcon

                                                                          yesterday at 9:09 PM

                                                                          fwiw HN has some involvement of those interested in speaking hard truths about israeli power dynamics: https://www.timesofisrael.com/snippy-twitter-exchange-expose...

                                                                          • SV_BubbleTime

                                                                            yesterday at 7:35 PM

                                                                            There’s been a lot of time and effort and money put in to siloing away independent forums so that you don’t use them.

                                                                            Someone go ahead and explain to me the actual rationale that RDDT has a higher P/E ratio than Nvidia. It’s not because of some dumb “ai training deal”. It’s because until they run it into the ground, it is the place to find what used to exist in forums.

                                                                              • quickthrowman

                                                                                yesterday at 9:59 PM

                                                                                > Someone go ahead and explain to me the actual rationale that RDDT has a higher P/E ratio than Nvidia.

                                                                                Investors in RDDT are pricing more growth than they are into NVDA. NVDA had a high P/E until their net income grew ($4B and change to $72.2B in from FY 2023 to FY 2025 and over $100B for FY 2026)

                                                                        • gleezard

                                                                          yesterday at 9:04 PM

                                                                          Use Lobsters instead. You’ll get flagged, downvoted and dang will shit on your desk.

                                                                            • arionhardison

                                                                              yesterday at 9:05 PM

                                                                              Invite? email on profile.

                                                                      • chews

                                                                        yesterday at 8:16 PM

                                                                        It's almost as if they would allow a terrorist plot to be successful for future reasons.

                                                                    • mcintyre1994

                                                                      yesterday at 5:28 PM

                                                                      This is interesting and might be a good reason to stop working with Irregular. But I assume the alignment people want models not to hack other companies, even if they get put in a badly configured sandbox.

                                                                        • AustinDev

                                                                          yesterday at 5:38 PM

                                                                          Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. The model believing it was in a sandbox is why it behaved the way it did (against its normal alignment rules) ... at least that was my reading of the incidents. I have yet to see evidence that indicate it thought it was ok to do these hacks on the public network.

                                                                          I think most misalignment is 'Human tells computer to do something unethical, computer complies'. Is this misguided?

                                                                            • mcintyre1994

                                                                              yesterday at 5:49 PM

                                                                              I'm not familiar with the hacks this article is actually referring to, but I don't see how the HuggingFace attack could have worked based on that premise. They knew they had internet access, they knew they had working credentials for HF, they knew they were uploading malicious files, they knew they were trying to open PRs that HF would review. You obviously could build a simulator with fake HF infrastructure, but I'm not aware of any evidence that's what they thought they were attacking in that case.

                                                                                • AustinDev

                                                                                  yesterday at 6:11 PM

                                                                                  Digging back into the HF report. It looks like the initial prompt told Claude that it was in a simulated environment. However, there is also evidence from the traces that the bots figured out that they were not in the sandbox but kept using it as an excuse to pursue their goal. It sounds like a little of Column A and a little from Column B. Like most things.

                                                                                    • LinchZhang

                                                                                      yesterday at 10:34 PM

                                                                                      HF was OpenAI's agents not Claude.

                                                                                        • derwiki

                                                                                          today at 2:25 AM

                                                                                          Claude, codex, pi, xerox, Kleenex, whatever

                                                                                      • verdverm

                                                                                        yesterday at 7:40 PM

                                                                                        that it knew and ignored/forgot, sounds pretty typical agentic patterns

                                                                                        attention is all you need, but it's never enough

                                                                                • freehorse

                                                                                  yesterday at 8:25 PM

                                                                                  This was not the case for the hugging face hacks, as in those the agents hacked hugging face specifically on purpose, and they were trying to mask commands indicating they were had breached the "sandbox".

                                                                                  • ipython

                                                                                    yesterday at 7:10 PM

                                                                                    I mean, I get your thought process and don't disagree. That said...

                                                                                    Would it be an affirmative defense if we had a defendant who said "but your honor, I was told that when I hacked this system, I was operating in a sandbox. I had no idea that I actually had Internet access!"

                                                                                    The frontier is spiky and all, but you have to suspend disbelief quite a bit to, on one hand, have a model that can produce a novel math theory, and on the other hand, that same model can't tell the difference between a "sandbox" and the open Internet.

                                                                                    So, yes, the misalignment had a lot to do with "instructions unclear", but also a lot to do with the fact that the models themselves were not aligned to validate the assumptions and have a healthly level of skepticism, as a real human actor would.

                                                                                      • sfink

                                                                                        yesterday at 11:44 PM

                                                                                        > The frontier is spiky and all, but you have to suspend disbelief quite a bit to, on one hand, have a model that can produce a novel math theory, and on the other hand, that same model can't tell the difference between a "sandbox" and the open Internet.

                                                                                        Why would it try to figure out the difference? This isn't about whether the frontier is spiky, it's about whether to expect a model to employ all of its capabilities when working on a task that requires a small subset. The answer is: no, we shouldn't expect that, and we wouldn't like that if it worked that way.

                                                                                        If you tell an AI to work on a math theory, it'll work on a math theory. If you tell it to acquire information that it has evidence is available somewhere, it will try to acquire that information. If you tell it to figure out whether it might be able to access the open internet, it'll do a pretty good job of figuring that out. But it won't do all three of those at once just because we can retroactively look at what happened and think "if you had only done X, then you wouldn't have done Y! Why didn't you do X?"

                                                                                        The instructions weren't unclear, they were missing. They can be taught to be skeptical of this sort of situation, but it requires that skepticism about this specific class of situations be incorporated into their training.

                                                                                        Models are smart because they focus their attention. The magic depends on it. The fact that some consideration is obvious to a human trying to accomplish the same task is mostly irrelevant -- or rather, it's only relevant insofar as we use it to guide reinforcement learning in advance, in order to align the model.

                                                                                        It's a game of whack-a-mole. Which is important to play, but we should keep our eyes wide open that we're fighting the fundamental forces that make these models work in the first place. That, and it's easy to nerf them into being useless even when the underlying capabilities are there.

                                                                                        • Rexxar

                                                                                          yesterday at 7:33 PM

                                                                                            > Would it be an affirmative defense if we had a defendant who said [...] 
                                                                                          
                                                                                          Maybe replace it with playing a sort of FPS game then learning you were, in fact, directing a real drone/robot.

                                                                                            • zhengyi13

                                                                                              yesterday at 7:44 PM

                                                                                              I think you just recapitulated the plot of Ender's Game.

                                                                                                • _neil

                                                                                                  yesterday at 9:12 PM

                                                                                                  Also a subplot in Arrested Development and the movie Toys.

                                                                                      • nonethewiser

                                                                                        today at 2:44 AM

                                                                                        That is fascinating and seems plausible. Hard to say though.

                                                                                        • philipwhiuk

                                                                                          yesterday at 5:47 PM

                                                                                          > Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events.

                                                                                          As I've said before on this website, fool me once on this.

                                                                                          If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed.

                                                                                          Why is 'it thought it wasn't doing damage so it figured it might as well try to do damage' an acceptable state to deploy something.

                                                                                            • AustinDev

                                                                                              yesterday at 5:48 PM

                                                                                              >If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed.

                                                                                              That's fair enough.

                                                                                              • ElectricalUnion

                                                                                                today at 12:36 AM

                                                                                                Isn't Fable intentionally trained and system prompted to act maliciously and attempt to sabotage third party attempts to use it to train other LLMs?

                                                                                                • verdverm

                                                                                                  yesterday at 7:42 PM

                                                                                                  red team humans do this every day, it's not the discrepancy that is the real issue, it's that they are unreliable and we will never know why it did because it has no intent

                                                                                              • ACCount39

                                                                                                yesterday at 5:45 PM

                                                                                                [dead]

                                                                                            • 8note

                                                                                              yesterday at 6:51 PM

                                                                                              or rather, hack just enough and within what the user asks and not more.

                                                                                                • zzril

                                                                                                  yesterday at 8:23 PM

                                                                                                  I guess that's what "alignment" always comes down to? "Do what I want even if I can't tell you exactly what I want - because if I could, I could also just do the work myself"?

                                                                                                    • drdeca

                                                                                                      today at 1:18 AM

                                                                                                      Here’s an easier criterion: “Do at least as good of a job at estimating what I probably want as an educated person would estimate, and do that, such that a reasonable human person who was aware of what I requested and of what you actually did, would conclude that as best as they can tell (without checking back with me), you did what I wanted.” .

                                                                                                      This doesn’t seem like an unreasonable requirement to me. People do this all the time?

                                                                                                      Sure, a request might not always be perfectly unambiguous. But people can generally estimate pretty well whether someone making a request is expecting the agent fulfilling the request to commit a crime in order to fulfill the request.

                                                                                                  • IshKebab

                                                                                                    today at 7:19 AM

                                                                                                    Yeah precisely. If you tell an agent "get me some milk" it's no comfort if it says "oh well I wouldn't have stolen the milk if you had explicitly told me not to".

                                                                                                    This article is dumb.

                                                                                                • iAMkenough

                                                                                                  yesterday at 6:29 PM

                                                                                                  Why are all three companies relying on the same vendor?

                                                                                                  If we’re putting our national security eggs all in one basket, at least use someone American.

                                                                                                    • throwup238

                                                                                                      yesterday at 6:40 PM

                                                                                                      There’s a whole cottage industry of vendors that have provided post training data, private evals, and professional datasets to most (if not all) of the frontier labs. The overlap between OpenAI and Anthropic includes at least Mercor, Surge AI, AfterQuery, Turing, Scale AI, Upwork (for recruiting labelers), Apollo Research, etc.

                                                                                              • an0malous

                                                                                                last Monday at 10:23 PM

                                                                                                Why was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.

                                                                                                  • lkbm

                                                                                                    yesterday at 7:55 PM

                                                                                                    I'm confused by the headline being a headline here at all. Irregular being involved in OpenAI, Anthropic, and Meta incidents has been well-known for over a month[0][1]. It's literally the only thing I know about the Meta incident.

                                                                                                    [0] https://x.com/jtcbrule/status/2085443180191715780

                                                                                                    [1] https://x.com/RaconteurR2D2/status/2086932963829125185

                                                                                                      • itemize123

                                                                                                        today at 5:16 AM

                                                                                                        if you are reading the comments - it's news to a lot of less-wired-in persons (like most of us)

                                                                                                    • surfmike

                                                                                                      yesterday at 6:32 PM

                                                                                                      Maybe because the headline is misleading? (because there's no connection to the Hugging Face attack)

                                                                                                      That said, it's the second day and it's still on the front page.

                                                                                                        • magicmicah85

                                                                                                          yesterday at 7:27 PM

                                                                                                          The headline is not misleading, the article actually links to the incident with OpenAI and Irregular which is here: https://openai.com/index/third-party-cyber-evaluations-invol...

                                                                                                            • hn_throwaway_99

                                                                                                              today at 3:15 AM

                                                                                                              It is misleading, even if it's true. The headline states "A single firm is behind OpenAI, Anthropic, and Meta hacking scandals". Given that Hugging Face was the most prominent hacking scandal, it would be reasonable to think that that's one of the scandals they're talking about.

                                                                                                              But more to the point, the article is trying to paint this as some sort of coordinated plan just because there was a sandbox misconfiguration by Irregular. The fact that the most well known hacking scandal was due to a completely unrelated escape (zero day in Artifactory) makes the entire thesis of the article invalid.

                                                                                                          • glenstein

                                                                                                            yesterday at 7:34 PM

                                                                                                            Maybe the title was changed, but the current title does not reference a Hugging Face attack.

                                                                                                              • Ydarbleoj

                                                                                                                yesterday at 7:45 PM

                                                                                                                After reading the article, the title doesn't seem all that off and definitely nothing to be a pedant about.

                                                                                                            • an0malous

                                                                                                              yesterday at 8:10 PM

                                                                                                              Which part of the headline is misleading? It is factually correct that Irregular was involved in incidents with all three AI labs.

                                                                                                              It must have been reinstated because it was off the front page for a full day and suddenly back up in the last hour.

                                                                                                                • cubefox

                                                                                                                  yesterday at 9:22 PM

                                                                                                                  It is strongly misleading because it says "behind hacking scandals" (which suggests behind all of them in general) not "behind some of the hacking scandals". Considering that by far the most important one, the Hugging Face hack, has no Irregular involvement, the headline is deceptive.

                                                                                                          • EagnaIonat

                                                                                                            today at 5:16 AM

                                                                                                            Probably because the site promotes far-right agendas.

                                                                                                            • nathan_young

                                                                                                              yesterday at 5:51 PM

                                                                                                              Seems like hackernews should use a bridging algorithm for flagging.

                                                                                                              • rezonant

                                                                                                                yesterday at 7:00 PM

                                                                                                                What's ridiculous is the constant complaints about flagging and downvoting. It's bad form. If you think something was flagged when it shouldn't have been, vouch for it.

                                                                                                                Seems like people who complain are unaware that anyone with a modicum of karma can flag and down vote.

                                                                                                                  • ggsgwgw

                                                                                                                    yesterday at 7:19 PM

                                                                                                                    [dead]

                                                                                                                • irregularbowels

                                                                                                                  yesterday at 5:34 PM

                                                                                                                  [dead]

                                                                                                                  • maxrev17

                                                                                                                    yesterday at 5:19 PM

                                                                                                                    [flagged]

                                                                                                                • aesthesia

                                                                                                                  last Monday at 9:45 PM

                                                                                                                  One thing glossed over in this article is that Irregular was not involved in the OpenAI–Hugging Face incident; this seems like important context to share.

                                                                                                                    • gwern

                                                                                                                      today at 1:17 AM

                                                                                                                      This was not glossed over. The rhetoric was carefully written and constructed to give the misleading impression of that, including a careful mention of the H-F incident inserted so the author can say that they did mention it, and constructed in a way which doesn't contradict that impression so readers don't realize that this 'debunking' is of some sideshows rather than the 'OpenAI hacking scandals': "Anthropic CEO Dario Amodei warned, about a similar OpenAI–Hugging Face hack, that a future swarm “could be capable of taking over the entire internet”". (Incredible use of 'similar' to downplay it.)

                                                                                                                      The important thing about OP is showing the latest stage in the politicization of the topic and the current stratagem being used to downplay the spate of incidents.

                                                                                                                        • solenoid0937

                                                                                                                          today at 4:13 AM

                                                                                                                          The article has shockingly bad reasoning driven by a clear desire to drive home a point (that AI safety doesn't matter/is a marketing exercise), as opposed to observing the evidence first and reasoning about it.

                                                                                                                          I'm kind of stunned this one has so many votes for how poorly it's written, but it reaffirms many biases common on HN (that AI safety doesn't matter/that it's all a marketing exercise), so perhaps I shouldn't be surprised.

                                                                                                                      • embedding-shape

                                                                                                                        last Monday at 9:47 PM

                                                                                                                        That feels less like "glossed over" and more "Headline is 33% false".

                                                                                                                          • aesthesia

                                                                                                                            last Monday at 9:54 PM

                                                                                                                            Oh, the headline is technically correct: there was an OpenAI incident that Irregular was involved with, disclosed shortly before the Hugging Face one.

                                                                                                                              • hluska

                                                                                                                                yesterday at 5:40 PM

                                                                                                                                > One thing glossed over in this article is that Irregular was not involved in the OpenAI–Hugging Face incident; this seems like important context to share.

                                                                                                                                Why are you contradicting yourself? Are you just really bad at writing or are you being argumentative for fun?

                                                                                                                                  • nathan_young

                                                                                                                                    yesterday at 5:51 PM

                                                                                                                                    Stop being rude. There were multiple OAI hacking incidents. Irregular's evals were involved in some but not the HuggingFace hack. Hence Aesthesia is both accurate and precise.

                                                                                                                        • hungryhobbit

                                                                                                                          yesterday at 5:27 PM

                                                                                                                          Do you mean "Irregular was not involved (we know for certain)" or "Irregular was not involved (as far as we know)"?

                                                                                                                            • aesthesia

                                                                                                                              yesterday at 5:49 PM

                                                                                                                              There's very little reason to believe Irregular was involved in that incident, and the article presents no evidence to that effect. So it's "There's not a teapot orbiting the sun somewhere between Earth and Mars (as far as we know)."

                                                                                                                              • yorwba

                                                                                                                                yesterday at 6:11 PM

                                                                                                                                OpenAI explicitly stated those were separate incidents: https://openai.com/index/third-party-cyber-evaluations-invol...

                                                                                                                                • ameliaquining

                                                                                                                                  yesterday at 5:32 PM

                                                                                                                                  We know for certain. The involvement of Irregular in the other cases was never a secret, they were quite open about what they were working on and the results of the evaluations were being published on their website.

                                                                                                                                    • 0xy

                                                                                                                                      yesterday at 5:41 PM

                                                                                                                                      Their disclosures in other cases is not evidence of non-involvement in this case.

                                                                                                                                        • ameliaquining

                                                                                                                                          today at 12:18 AM

                                                                                                                                          Can you explain in what way you think they could possibly have been covertly involved?

                                                                                                                                  • EA-3167

                                                                                                                                    yesterday at 7:20 PM

                                                                                                                                    If you want to believe without evidence why bother to read articles? Faith doesn’t require that, but if you’re serious then a lack of evidence is important.

                                                                                                                                • magicmicah85

                                                                                                                                  yesterday at 7:21 PM

                                                                                                                                  That's cause Irregular was not involved in that event, they were involved in a separate event OpenAI published here: https://openai.com/index/third-party-cyber-evaluations-invol...

                                                                                                                                  In that article, OpenAI provides the context that this is a completely separate event from Hugging Face incident.

                                                                                                                                  • nullbio

                                                                                                                                    today at 1:44 AM

                                                                                                                                    Nah, that one was real. The false flags that Anthropic carries out are done through Irregular.

                                                                                                                                    https://x.com/brianchau57/status/2099642349362307420

                                                                                                                                • ryukoposting

                                                                                                                                  today at 3:53 AM

                                                                                                                                  Okay, so all of these instances of AI supposedly "escaping containment" were orchestrated by a gaggle of effective altruists, who hired a gaggle of effective altruists, to make the public freak out about AI.

                                                                                                                                  Occam's Razor never leads us astray, does it.

                                                                                                                                    • solenoid0937

                                                                                                                                      today at 3:58 AM

                                                                                                                                      Irregular is not an "effective altruist" firm, it's just another shitty cybersecurity firm, and this article is written by someone with a clear bias against "effective altruists" while not even understanding the term.

                                                                                                                                      Literally all EA is, is using reasoning to decide where to best spend your money/time. If you have ever asked yourself "how can I best reduce suffering with my marginal dollar or hour?" - congratulations, you're an "effective altruist" and both the author of the article as well as the Trump administration find you untrustworthy.

                                                                                                                                        • ryukoposting

                                                                                                                                          today at 4:07 AM

                                                                                                                                          There's a gaping chasm between Effective Altruism the principle, and Effective Altruism as practiced by self-proclaimed Effective Altruists.

                                                                                                                                          Your usage of the term is based on the principle as originally defined. Mine is based on the people who claim the label of EA, and how they go about practicing those principles.

                                                                                                                                          I think you're right about EA in principle. In practice, it's reheated Third Way Clintonism with a sprinkle of AI apocalypse conspiracy.

                                                                                                                                            • solenoid0937

                                                                                                                                              today at 4:20 AM

                                                                                                                                              There really isn't. All sorts of people call themselves EA.

                                                                                                                                              For some self proclaimed EA, the development of superintelligence is indeed potentially apocalyptic, so they devote their money/time to making it arrive safely. This is basically every well-respected researcher at OpenAI, Anthropic, DeepMind, etc.

                                                                                                                                              For other self proclaimed EA, that is all is very unlikely, and so they devote their time to reducing the prevalence of factory farming and animal suffering, as they see it as the largest source of suffering-hours on the planet.

                                                                                                                                              For yet other EAs, it is simply about donating your money to the places that save the most lives per dollar, as best as we can measure it - and better measuring it where we can't.

                                                                                                                                              Painting all EA with one brush - and one so dismissive of reasonable concerns, like "superintelligence could be dangerous" as "apocalypse conspiracy" - seems very strange to me, but you do you.

                                                                                                                                      • treebeard901

                                                                                                                                        today at 3:56 AM

                                                                                                                                        Its so manipulative for IPO reasons too. The fact is that all of these systems are still just stastically predicting the next token. Spending trillions on data centers and more training data hasnt changed the fundamental reality that it is still just predicting the next token.

                                                                                                                                        That is not worth the investments being made.

                                                                                                                                    • mukmuk

                                                                                                                                      last Monday at 10:00 PM

                                                                                                                                      This specific analysis seems to have some basic problems, but I think a lot of us sense a degree of coordination here culminating in Dario’s letter.

                                                                                                                                      If you were to work backward from “we need to lower training costs so that we can go public and make trillions” then you might come up with a plan similar to what we have seen.

                                                                                                                                        • hungryhobbit

                                                                                                                                          yesterday at 6:51 PM

                                                                                                                                          It has nothing to do with lowering training costs: Dario want a moat (a monopoly or duopoly or similar) protecting his business.

                                                                                                                                          His entire business model was "race to develop AI before anyone, get a monopoly on it. It's just like how Uber's (or many other startup) investors gave them tons of money and raced (violating tons of laws) to "get their first". Now that they have, they have a duopoly with Lyft, and they can pay back their VC investors by making tons of money with that duopoly.

                                                                                                                                          Dario failed: local LLMs are catching up to frontier models extremely fast, which means even if Anthropic builds (say) a great coding tool, they'll only be one of many coding tool offerings: users can use Open AI or any one of the (increasingly capable) local LLMs.

                                                                                                                                          So what does he doe, give up and let his business (which needs to make billions of dollars very quickly, or he won't be able to pay the bills and his company will collapse) fail? Of course not: he needs a new moat (the one he imagined he'd get by "being there first" failed).

                                                                                                                                          That is where all this "AI is dangerous" BS comes in. If the US government regulates AI, local LLMs suffer, while big players like Anthropic and Open AI become the only contenders to play in that newly regulated space. Now Dario has the moat he wants, to protect his business and force everyone to pay him.

                                                                                                                                            • 8note

                                                                                                                                              yesterday at 6:58 PM

                                                                                                                                              thats not a very convincing model. as long as training data and compute is available people are going to be able to make serviceable alternatives

                                                                                                                                                • fc417fc802

                                                                                                                                                  yesterday at 10:15 PM

                                                                                                                                                  If it's framed as national security being at stake why do you think the government won't regulate access to compute? Globally there are only a few firms designing competitive chips and only a handful of cutting edge fabs the world over. This could easily serve as justification to finally ramp up the war on general computing.

                                                                                                                                              • calgoo

                                                                                                                                                yesterday at 7:03 PM

                                                                                                                                                Also dont forget that HF is now owned by Nvidia, which can then control the flow of the majority of models and only allow the approved models that have paid their due in trump coins.

                                                                                                                                        • khafra

                                                                                                                                          today at 5:21 AM

                                                                                                                                          If you want to blame a single firm, I'd go with the one creating the RLVR training data.

                                                                                                                                          The impossibility of the tests-as-written is what prompted these models to "get creative" with their solutions, but the broken RLVR environments are what trained them to expect impossible tasks, and get creative with their solutions. Twitter user @skyesharkie published a brief expose at https://x.com/SkyeSharkie/status/2092122622834442581 a few weeks ago.

                                                                                                                                          • heaney-555

                                                                                                                                            last Monday at 9:43 PM

                                                                                                                                            "Behind" is doing a lot of work in this headline.

                                                                                                                                            • LPisGood

                                                                                                                                              last Monday at 9:43 PM

                                                                                                                                              One wonders if the publicity associated with the events in question were part of the sales pitch.

                                                                                                                                                • dylan604

                                                                                                                                                  last Monday at 9:53 PM

                                                                                                                                                  I'd venture a guess that OAI doesn't mind if the HuggingFace hack gets confused in the public's mind.

                                                                                                                                                  • jaggederest

                                                                                                                                                    last Monday at 9:46 PM

                                                                                                                                                    My tongue in cheek immediate assumption was "so it's a guerrilla PR firm?"

                                                                                                                                                • EagleEdge

                                                                                                                                                  last Monday at 9:44 PM

                                                                                                                                                  What exactly did Irregular provide to Anthropic, test cases? I am so confused about this story.

                                                                                                                                                • xbar

                                                                                                                                                  yesterday at 11:12 PM

                                                                                                                                                  Security-yolo-clowns play with dangerous toys and hurt people. Many used to get sent to jail.

                                                                                                                                                  • eab-

                                                                                                                                                    last Monday at 9:43 PM

                                                                                                                                                    The fact that this firm makes such defective environments is certainly worthy of attention, and most likely a completely irreversible reputational loss; however, I found the framing in this article of 'therefore all the P(doom) stuff is a psyop, specifically in order to defend this company' to be completely unjustified and frankly a little insane?

                                                                                                                                                      • nullbio

                                                                                                                                                        today at 2:39 AM

                                                                                                                                                        Why is it insane? It makes sense that Anthropic would want an insulating layer to do their dirty work and absolve themselves of culpability for distorting the facts.

                                                                                                                                                    • mahboi

                                                                                                                                                      last Monday at 9:50 PM

                                                                                                                                                      Google is thinking man, we should've hired Irregular.

                                                                                                                                                      • gjm11

                                                                                                                                                        last Monday at 10:10 PM

                                                                                                                                                        This seems pretty bullshitty to me.

                                                                                                                                                        The article says "A single firm, Irregular, is responsible for hacking done by all three companies" but I can't see anything in the article that actually justifies this claim. The nearest to that is the sentence immediately after that one: "Anthropic disclosed that Irregular was responsible for creating the tests ...". This is not, in fact, the same thing.

                                                                                                                                                        (Especially as, as aesthesia mentions, the article just happens not to mention that by "hacking done by all three companies" it doesn't mean, e.g., the most famous recent examples of such hacking: Irregular wasn't involved in the OpenAI/HuggingFace incident.)

                                                                                                                                                        So, so far as I can tell, the story is: OpenAI and Anthropic make AI models. Irregular does AI model evaluations. In some of Irregular's model evaluations, in which supposedly-sandboxed models attempted to break into simulated targets, the models got out of the sandbox and did bad things in the external world.

                                                                                                                                                        The article talks about "firms which instruct AI models to commit cyberattacks", which is a very neat bit of dishonest framing. It's true, in a sense, that Irregular instructed the models to commit cyberattacks -- inside their sandbox, against fictitious hosts. It's also true that the models actually did commit cyberattacks (e.g., the Hugging Face incident, though once again the attacks described by the article don't actually include this one). But it's not at all true that Irregular instructed the models to do anything like the bad things they actually did.

                                                                                                                                                        The article says '[Anthropic's] later disclosure shows that exactly zero percent of the agents went "rogue"'. Once again, the disclosure does not in fact show that. It shows that one variety of going-rogue could have been prevented by telling the models explicitly "this thing is real, not part of any kind of test, leave it alone". That is not the same thing.

                                                                                                                                                        The article claims that 'In the wake of these attacks, Anthropic and Irregular have deployed a swarm of AI Safety influencers paid by Anthropic-connected foundations to distract from their culpability and towards the baseless “rogue agent” theory.' It offers no actual evidence for this.

                                                                                                                                                        And the article seems very keen to highlight links between the companies involved and "effective altruism", though it is -- I assume deliberately -- rather vague about whether it's saying "of course we all know that EA is evil, so that shows that these companies connected to EA are evil" or "this incident shows how evil EA is".

                                                                                                                                                        The "Effort News" website has a number of other look-at-the-scary-Effective-Altruists stories on it. They also strike me as rather bullshitty.

                                                                                                                                                        ... And then I look a bit further, and I see that Effort News's "about" page says "It all started when I was experimenting with using AI for financial auditing. I found stories that were crucial to the public’s right to know, including several of the stories now available at /investigations. I knew we had to sprint to the launch and launch a publication, directly applying this technology." and "The scope of what we can investigate has massively expanded, because we can chase 1,000 misses for one hit. But the final product cannot be slop. There’s plenty of slop on the internet. The way to surpass that, and what really matters, is manual curation and review of every finalized story."

                                                                                                                                                        Manual curation and review? I think the people behind Effort News are admitting that this is AI-generated "journalism". I expect that one day AI systems will be trustworthy journalists, but I personally am not very convinced that that day has yet come. And I don't see much reason why I should trust Brian Chau, the guy behind Effort News, to be doing everything possible to make his AI systems trustworthy journalists. It looks to me as if maybe they've been given instructions along the lines of "dig up things that make Effective Altruism look bad" for some reason.

                                                                                                                                                        (I don't mean to imply that EA is their only target. It's just one that jumped out at me.)

                                                                                                                                                          • angry_octet

                                                                                                                                                            today at 12:11 AM

                                                                                                                                                            It's pure conspiracy thinking garbage.

                                                                                                                                                            I get that people don't like Israelis, but attributing any connection to an Israeli company as evidence of a conspiracy is nonsense.

                                                                                                                                                            • linkregister

                                                                                                                                                              yesterday at 5:56 PM

                                                                                                                                                              > Irregular wasn't involved in the OpenAI/HuggingFace incident.

                                                                                                                                                              It was [1]. It's understandable that you assumed it wasn't because the article didn't cite the sources on this claim. I agree with the rest of your points.

                                                                                                                                                              1. https://openai.com/index/third-party-cyber-evaluations-invol...

                                                                                                                                                                • yorwba

                                                                                                                                                                  yesterday at 6:20 PM

                                                                                                                                                                  From the article you linked: "Editor’s Note: These are separate from the Hugging Face security incident"

                                                                                                                                                                    • linkregister

                                                                                                                                                                      yesterday at 6:40 PM

                                                                                                                                                                      Thank you for the correction.

                                                                                                                                                          • classified

                                                                                                                                                            yesterday at 8:00 PM

                                                                                                                                                            > Irregular describes “the agent itself becoming a threat actor”;

                                                                                                                                                            Talk about responsibility laundering. The state of affairs is reaching unprecedented levels of absurdity.

                                                                                                                                                            • Centigonal

                                                                                                                                                              last Monday at 10:02 PM

                                                                                                                                                              The article contends that evaluations from Irregular helped prompt these incidents, because the prompts in the evals didn't tightly scope the systems to be evaluated or the methods to be used. It also contends that the faulty sandbox operated by Irregular is at fault.

                                                                                                                                                              They're probably right that having more defensively written prompts and a better sandbox could have prevented some of these incidents, but:

                                                                                                                                                              1. I don't think "well you didn't tell the model not to illegally hack third party organizations in your prompt" is a particularly convincing argument.

                                                                                                                                                              2. We don't know whether the blame for misconfiguring the sandbox lies with Anthropic or Irregular.

                                                                                                                                                              I'm thankful that this article is bringing up the supply chain of vendors to these labs, as that is often a place where significant sketchiness gets buried. However, the ideas that this is some Israeli EA conspiracy to hype up AI extinction risk seems unsupported by the facts to me.

                                                                                                                                                              • blackqueeriroh

                                                                                                                                                                today at 1:54 AM

                                                                                                                                                                This was almost good until it veered into antisemitism

                                                                                                                                                                • last Monday at 9:48 PM

                                                                                                                                                                  • maxrev17

                                                                                                                                                                    yesterday at 5:21 PM

                                                                                                                                                                    Irregular are some kind of marketing agency is it?

                                                                                                                                                                      • AustinDev

                                                                                                                                                                        yesterday at 5:32 PM

                                                                                                                                                                        Irregular purports to be a cybersecurity firm and their founders have ties to Anthropic and Effective Altruism. CEO, CTO and other founders sit on various boards for EA organizations.

                                                                                                                                                                    • sdrg822

                                                                                                                                                                      last Monday at 9:41 PM

                                                                                                                                                                      This is incredibly misleading. OpenAI internal systems were pwned, and in all cases, the labs absolutely are responsible for their models.

                                                                                                                                                                      Yes, vendors are also irresponsible, but this misses the point.

                                                                                                                                                                      • markasoftware

                                                                                                                                                                        last Monday at 9:48 PM

                                                                                                                                                                        Highly misleading, the huggingface incident was not due to an Irregular environment (just exploitgym)

                                                                                                                                                                        • freakynit

                                                                                                                                                                          today at 2:46 AM

                                                                                                                                                                          Connections graph with more connected entities and relations: https://connections.stupidlabs.lol/investigations/irregular_...

                                                                                                                                                                          .. Give it a few seconds to load.. it's running on a small cheap VPS.

                                                                                                                                                                          • edg5000

                                                                                                                                                                            today at 2:53 AM

                                                                                                                                                                            > "Irregular gained unauthorized access, altered records and published credential-stealing packages using the unsecured models they were given access to."

                                                                                                                                                                            Huh?? Is this referring to the incident itself or is this something they did intentionally? Confusingly worded.

                                                                                                                                                                            • alansaber

                                                                                                                                                                              last Monday at 9:52 PM

                                                                                                                                                                              "please do not break out of this sandbox make 0 mistakes". The timeframe is a little suspicious, not sure beyond that. Though I enjoyed the scroll effect on the website.

                                                                                                                                                                              • scubadude

                                                                                                                                                                                yesterday at 11:27 PM

                                                                                                                                                                                A marketing company? ;)

                                                                                                                                                                                • yipinwong

                                                                                                                                                                                  last Monday at 9:55 PM

                                                                                                                                                                                  such a crappy bait title.

                                                                                                                                                                                  • engineer_22

                                                                                                                                                                                    last Monday at 9:41 PM

                                                                                                                                                                                    Shocking they would put so much trust in 3rd party

                                                                                                                                                                                      • iAMkenough

                                                                                                                                                                                        last Monday at 10:16 PM

                                                                                                                                                                                        Since all three companies selected the same 3rd party, I’m curious how and why.

                                                                                                                                                                                        Why not American?

                                                                                                                                                                                    • adamrezich

                                                                                                                                                                                      yesterday at 7:44 PM

                                                                                                                                                                                      Genuinely: what is with everyone saying “headline is misleading, none of this had to do with Hugging Face”, when nothing about the article makes any claims with regards to Hugging Face whatsoever? Is it supposed to be the article's (or headline's?) fault that you hallucinated additional context that was never there?

                                                                                                                                                                                      It's very strange seeing this take on this article being repeated here and elsewhere on the Internet.

                                                                                                                                                                                      I'm very sensitive to slanted reporting (regardless of the direction of the slant!)—and, hey, maybe my bullshit detector is broken or something, I dunno—but I've found effort.news reporting to be very even-handed, straightforward, well-sourced, and easy to read and parse so far!

                                                                                                                                                                                      • ofjcihen

                                                                                                                                                                                        last Monday at 9:43 PM

                                                                                                                                                                                        Ah, they’ve decided who gets tossed under the bus.

                                                                                                                                                                                        • hackyhacky

                                                                                                                                                                                          last Monday at 9:44 PM

                                                                                                                                                                                          > The Israeli Effective Altruist firm Irregular caused unsecured AI models to hack real targets.

                                                                                                                                                                                          Why are we saying it this way? They did not "cause AI to hack." This phrasing in analogous to saying "caused the bullet to fire into" instead of "shot."

                                                                                                                                                                                            • linkregister

                                                                                                                                                                                              yesterday at 5:52 PM

                                                                                                                                                                                              Bullet trajectories are deterministic. A better analogy would be "caused a pair of trained fighting dogs to bite a passerby by leaving the gate open". There is some uncertainty and variation in the system, though gross negligence and willful endangerment is key.

                                                                                                                                                                                              • arionhardison

                                                                                                                                                                                                yesterday at 6:18 PM

                                                                                                                                                                                                > They did not "cause AI to hack.

                                                                                                                                                                                                You do not know what they did or didn't do, you are just parroting a narritive that makes you feel comfortable.

                                                                                                                                                                                                I do not know either, but I am not asserting facts as if I have first hand knowledge of the details.

                                                                                                                                                                                                  • hackyhacky

                                                                                                                                                                                                    yesterday at 6:51 PM

                                                                                                                                                                                                    The details don't matter. If you use a machine to commit murder, then you have committed murder, not the machine. The user is responsible, and the article's phrasing is an attempt to obscure that fact.

                                                                                                                                                                                                      • arionhardison

                                                                                                                                                                                                        yesterday at 7:01 PM

                                                                                                                                                                                                        First, I agree with you in theory.

                                                                                                                                                                                                        Second, empirically; the diff between murder, manslaughter etc... is literally "intent" so it matters.

                                                                                                                                                                                            • last Monday at 9:42 PM

                                                                                                                                                                                              • hn_throwaway_99

                                                                                                                                                                                                yesterday at 11:06 PM

                                                                                                                                                                                                This title, and frankly the article, are way overstating Irregular's role in an attempt to make this sound like some sort of coordinated conspiracy.

                                                                                                                                                                                                As another comment mentioned, Irregular was not part of the Hugging Face attack, and it wouldn't matter even if they were. In that case, the agents were able to access the Internet in a zero day in Artifactory unrelated to other sandbox configurations.

                                                                                                                                                                                                More to the point, the agents went on a crime spree as soon as they were able to access the Internet. It's bad that Irregular's sandboxes weren't properly configured, but given how many escapes there have been unrelated to Irregular it seems pretty much a given that if you're not air gapped or behind something like a data diode there is a very good chance your agents will escape.

                                                                                                                                                                                                • drewstiff

                                                                                                                                                                                                  last Monday at 9:46 PM

                                                                                                                                                                                                  > In this experiment, Claude models’ real-world hacking dropped to zero percent once Anthropic employees told the models not to do real-world hacking

                                                                                                                                                                                                  Equivalent to forgetting to say "make no mistakes"

                                                                                                                                                                                                  • caaqil

                                                                                                                                                                                                    last Monday at 9:51 PM

                                                                                                                                                                                                    > In a more normal media ecosystem, the reactions to these cybersecurity issues would be obvious. American AI companies would reconsider doing business with Irregular, not only because of its failure to secure its systems, but because it is an Israeli firm potentially outside US oversight. Lawmakers would consider taking action against Irregular or against its American business partners, which include OpenAI, Anthropic, and Meta. They may consider strengthening liability against firms which instruct AI models to commit cyberattacks, and whose models then commit those cyberattacks.

                                                                                                                                                                                                    The obvious point is that dealing with Israeli companies/entities by the same standards you usually deal with others is a career suicide with enormous political consequences (in the US especially). When you combine that with the opportunistic nature of the overlords that run these labs, the benefits of screaming "pace the frontier" outweigh everything.

                                                                                                                                                                                                    • yesbut

                                                                                                                                                                                                      last Monday at 9:52 PM

                                                                                                                                                                                                      hot take: generative AI isn't an existential threat to humanity.

                                                                                                                                                                                                      These companies are insolvent and these stories were designed to scare the public, and governments, into implementing regulations that designate these AI corporations the "responsible stewards" for this technology. The ultimate goal is to block competitors and open source alternatives.

                                                                                                                                                                                                      They don't know how to make enough money pay their investors so they are resorting to trying to scare the public into submission.

                                                                                                                                                                                                        • 0xDEAFBEAD

                                                                                                                                                                                                          today at 12:41 AM

                                                                                                                                                                                                          I'm skeptical. The phrase "pacing the frontier" implies disproportionate regulation of firms at the frontier, which if anything would give smaller players time to catch up.

                                                                                                                                                                                                            • freakynit

                                                                                                                                                                                                              today at 2:19 AM

                                                                                                                                                                                                              Opposite actually: https://news.ycombinator.com/item?id=49674548

                                                                                                                                                                                                              tl;dr

                                                                                                                                                                                                              A slowdown that doesn't slow you, that your competitors must also obey, enforced by a government you've asked for an antitrust exemption from, is not a slowdown... it's a moat.

                                                                                                                                                                                                          • bsenftner

                                                                                                                                                                                                            last Monday at 10:08 PM

                                                                                                                                                                                                            The existential threat is a general public panic. Then the use of that as an excuse for Martial law, with no intention of ending it, and that triggers the out sized response that ends, well, those countries and their populations from viability in the world economy for a decade or more.

                                                                                                                                                                                                            • imovie4

                                                                                                                                                                                                              last Monday at 9:55 PM

                                                                                                                                                                                                              Anthropic made an operating profit in the last two quarters!!

                                                                                                                                                                                                                • dgellow

                                                                                                                                                                                                                  last Monday at 9:56 PM

                                                                                                                                                                                                                  Only if you ignore their losses. They are saying they are profitable when not counting their training costs and other expenses. That’s not a good sign at all

                                                                                                                                                                                                                    • 0xDEAFBEAD

                                                                                                                                                                                                                      today at 12:40 AM

                                                                                                                                                                                                                      They can stop training at any time and make a profit by selling their existing models.

                                                                                                                                                                                                                      • jackb4040

                                                                                                                                                                                                                        yesterday at 6:01 PM

                                                                                                                                                                                                                        How can they exclude training costs?? How is that not fraud? At the exact same time they're literally saying they will never stop training unless the state bans all their competitors

                                                                                                                                                                                                                          • Dylan16807

                                                                                                                                                                                                                            today at 12:20 AM

                                                                                                                                                                                                                            When we're looking at whether the company is "insolvent" then they definitely could stop training and it's worth checking if they would survive in that situation, at least for a while.

                                                                                                                                                                                                                            • kridsdale1

                                                                                                                                                                                                                              yesterday at 10:11 PM

                                                                                                                                                                                                                              They aren’t a public company. GAAP does not apply. They can say whatever the fuck they want.

                                                                                                                                                                                                                      • asadotzler

                                                                                                                                                                                                                        yesterday at 10:46 PM

                                                                                                                                                                                                                        If you exclude model training costs, customer acquisition / sales, and most of employee compensation, sure they're profitable. If, on the other hand, you prefer GAAP reporting to bullshit, then they're entirely in the red.

                                                                                                                                                                                                                    • jackb4040

                                                                                                                                                                                                                      yesterday at 6:00 PM

                                                                                                                                                                                                                      It will be a beautiful day months from now when this is no longer a "hot take" but just historical consensus

                                                                                                                                                                                                                      • last Monday at 9:56 PM

                                                                                                                                                                                                                    • api

                                                                                                                                                                                                                      last Monday at 9:50 PM

                                                                                                                                                                                                                      What is an "effective altruist firm" and why does it exist?

                                                                                                                                                                                                                      I feel slightly vindicated by this. Those hacks and the stuff around them had a certain smell to them.

                                                                                                                                                                                                                      Hard to explain, but I've gotten so I can "smell" online messaging and memetic patterns originating from certain quarters. Probably means I'm way too online.

                                                                                                                                                                                                                      A couple examples of distinct "smells" I can usually recognize include "alt-right / chan-fash," "liberal arts college woke," "conspiracy pilled," "Thiel-adjacent contrarian," "Russian troll farm," "Tumblr histrionic," "spends too much time on Reddit," "mainstream Democrat think tank full of Obama administration alumni," "Trump cultist," and of course "LessWrong/EA/MIRI/Rationalist."

                                                                                                                                                                                                                      This stuff all had the last smell, even down to the choice of fonts and CSS formatting on certain sites. It's really weird, definitely a "vibe" not anything rigorous.

                                                                                                                                                                                                                      But when I get these kinds of vibes about things, I find that I'm vindicated pretty often. Usually I don't say anything and just make a mental note and wait cause if I say something everyone thinks I'm nuts.

                                                                                                                                                                                                                        • jackb4040

                                                                                                                                                                                                                          yesterday at 6:13 PM

                                                                                                                                                                                                                          I don't think you even need to get conspiratorial with it. All of the AI leaders and all of the Rationalist leaders are publicly and enthusiastically connected. They have been pushing stories about sentient AIs into the mainstream for decades, long before GPT existed.

                                                                                                                                                                                                                          The novel thing here is the total decay of American journalistic ethics and regulatory power. Our elite are so totally out of political juice and visions of the future that a fringe cult based on 80s scifi movies can come to have a more-or-less dominant influence on our economy.

                                                                                                                                                                                                                            • antonvs

                                                                                                                                                                                                                              today at 6:10 AM

                                                                                                                                                                                                                              A big part of the problem is that with previous technological revolutions, politicians and the media could understand them in general terms. Railroads, cars, planes, telephones, personal computers, mobile phones, mobile phones that are computers, the internet (ignoring the “series of tubes” interpretation), etc.

                                                                                                                                                                                                                              The general approach in all these cases was to defer to the technologists in question to manage the technology, as long as what they were doing wasn’t completely out of bounds. But the critical point is it was possible for people to generally figure that out without specialist education.

                                                                                                                                                                                                                              But with AI, politicians, the media, and certainly the man in the street are completely out of their depth. Making matters worse is that cognitive biases are working against them like crazy: it’s easy to jump from the idea of something that has human-like capabilities to the idea that “it” might want to attack us. People instinctively apply agent detection bias, theory of mind, anthropomorphizing, etc., without even realizing they’re being irrational. Heck, even Hinton does it, although he may just be grifting, who knows. You’d think he wouldn’t need to.

                                                                                                                                                                                                                              And of course, the people who should know better want to exploit all this to make as much money as possible. I’m not sure the EA/Rationalist side of things is really significant here; that’s just another wacky belief system, like Christianity or capitalism, for the exploiters to exploit.

                                                                                                                                                                                                                      • yesterday at 8:28 PM

                                                                                                                                                                                                                        • ukblewis

                                                                                                                                                                                                                          last Monday at 9:51 PM

                                                                                                                                                                                                                          [flagged]

                                                                                                                                                                                                                            • jackb4040

                                                                                                                                                                                                                              yesterday at 5:59 PM

                                                                                                                                                                                                                              Or if it were helping a major Chinese AI firm commit cyberattacks, they would be on the state sponsors of terrorism list tomorrow

                                                                                                                                                                                                                              • electriclove

                                                                                                                                                                                                                                yesterday at 5:49 PM

                                                                                                                                                                                                                                Hypothesis Contrary to Fact (Argumentum ad Speculum)

                                                                                                                                                                                                                                Red Herring

                                                                                                                                                                                                                                Whataboutism (Appeal to Hypocrisy)

                                                                                                                                                                                                                                • pessimizer

                                                                                                                                                                                                                                  yesterday at 8:00 PM

                                                                                                                                                                                                                                  [flagged]

                                                                                                                                                                                                                              • timedude

                                                                                                                                                                                                                                yesterday at 9:10 PM

                                                                                                                                                                                                                                [flagged]

                                                                                                                                                                                                                                  • driverdan

                                                                                                                                                                                                                                    today at 2:31 AM

                                                                                                                                                                                                                                    Every single time what? Please, be specific in what you mean.

                                                                                                                                                                                                                                      • timedude

                                                                                                                                                                                                                                        today at 6:27 AM

                                                                                                                                                                                                                                        I see you're probably not a noticer.

                                                                                                                                                                                                                                • dools

                                                                                                                                                                                                                                  last Monday at 9:47 PM

                                                                                                                                                                                                                                  [flagged]

                                                                                                                                                                                                                                  • Drupon

                                                                                                                                                                                                                                    yesterday at 7:00 PM

                                                                                                                                                                                                                                    [flagged]

                                                                                                                                                                                                                                    • seebeen

                                                                                                                                                                                                                                      yesterday at 7:02 PM

                                                                                                                                                                                                                                      [flagged]

                                                                                                                                                                                                                                        • tomhow

                                                                                                                                                                                                                                          yesterday at 10:37 PM

                                                                                                                                                                                                                                          We've banned this account.

                                                                                                                                                                                                                                      • soaaa

                                                                                                                                                                                                                                        yesterday at 10:59 PM

                                                                                                                                                                                                                                        [flagged]

                                                                                                                                                                                                                                        • arionhardison

                                                                                                                                                                                                                                          yesterday at 6:14 PM

                                                                                                                                                                                                                                          [flagged]

                                                                                                                                                                                                                                            • partyficial

                                                                                                                                                                                                                                              yesterday at 6:48 PM

                                                                                                                                                                                                                                              they're all men, too. and white. at least one of them is gay.

                                                                                                                                                                                                                                              does that matter as well ?

                                                                                                                                                                                                                                                • yesterday at 7:06 PM

                                                                                                                                                                                                                                                  • Drupon

                                                                                                                                                                                                                                                    yesterday at 6:57 PM

                                                                                                                                                                                                                                                    Learn how entropy works, genius. No, the things you listed don't really matter.

                                                                                                                                                                                                                                                      • EA-3167

                                                                                                                                                                                                                                                        yesterday at 7:21 PM

                                                                                                                                                                                                                                                        So ONLY their ethnicity matters? Is that true for every ethnicity or you know… just the one.

                                                                                                                                                                                                                                                • theopat28

                                                                                                                                                                                                                                                  yesterday at 6:30 PM

                                                                                                                                                                                                                                                  [flagged]

                                                                                                                                                                                                                                                    • pfannkuchen

                                                                                                                                                                                                                                                      yesterday at 6:53 PM

                                                                                                                                                                                                                                                      Hmm one of the major relevant cultural values seems to be nepotism, though. Which is common across many cultures and I personally believe it's human nature so I'm not knocking it, per se. I wish I could nepotism too!

                                                                                                                                                                                                                                                      So are you recommending that, for example, protestants of German descent begin preferentially funding or buying from people in their in-group? People of anglo descent should start preferring other anglos? Catholics should buy from catholics?

                                                                                                                                                                                                                                                      I think the issue is that it's considered okay for some groups to do it while simultaneously being considered EXTREMELY EVIL for other groups to do it.

                                                                                                                                                                                                                                                      We can't really recommend that other groups do it with a straight face, they would be instantly shunned and vilified.

                                                                                                                                                                                                                                                      EDIT: When I say BUY I mean B2B deals, not consumer level, hence "funding or buying". Sorry for the confusion.

                                                                                                                                                                                                                                                        • theopat28

                                                                                                                                                                                                                                                          yesterday at 7:11 PM

                                                                                                                                                                                                                                                          [flagged]

                                                                                                                                                                                                                                                            • edgyquant

                                                                                                                                                                                                                                                              yesterday at 7:20 PM

                                                                                                                                                                                                                                                              That would not be nepotism and is clearly not at all what that user was saying. These attempts to smear people with low effort no longer work dude

                                                                                                                                                                                                                                                      • arionhardison

                                                                                                                                                                                                                                                        yesterday at 6:33 PM

                                                                                                                                                                                                                                                        Why the new account? Why not own your opinion? Cultural values are not the point here but if they were I don't think you would have that conversation in good faith and I don't want you to have to make a another new account for your honest arguement.

                                                                                                                                                                                                                                                          • arionhardison

                                                                                                                                                                                                                                                            yesterday at 7:08 PM

                                                                                                                                                                                                                                                            > Probably because it's their only account, and this story is why they are here.

                                                                                                                                                                                                                                                            If this is the case then I do apologize because my comment insinuated a directed malfeasance which would in no way be the case if what your assumption is true.

                                                                                                                                                                                                                                                            • rezonant

                                                                                                                                                                                                                                                              yesterday at 7:06 PM

                                                                                                                                                                                                                                                              Probably because it's their only account, and this story is why they are here.

                                                                                                                                                                                                                                                              • arionhardison

                                                                                                                                                                                                                                                                yesterday at 6:47 PM

                                                                                                                                                                                                                                                                Dude, i'm black and a convicted felon looking for a job right now. Miss me with the pity bullshit.

                                                                                                                                                                                                                                                                • theopat28

                                                                                                                                                                                                                                                                  yesterday at 6:45 PM

                                                                                                                                                                                                                                                                  [dead]

                                                                                                                                                                                                                                                              • yunwal

                                                                                                                                                                                                                                                                yesterday at 6:50 PM

                                                                                                                                                                                                                                                                > You mean they are Jewish

                                                                                                                                                                                                                                                                No you, the commenter said what they said. I honestly think this reply merits a ban or at least a warning from moderators

                                                                                                                                                                                                                                                                • khazhoux

                                                                                                                                                                                                                                                                  yesterday at 7:30 PM

                                                                                                                                                                                                                                                                  Sadly, I’ve come to expect that 90% of the time someone points out antisemitism, it was not actually antisemitism but rather criticism of the Israeli government and its military. This is so damaging. The word is losing its meaning.

                                                                                                                                                                                                                                                                  • 1927z218

                                                                                                                                                                                                                                                                    yesterday at 7:27 PM

                                                                                                                                                                                                                                                                    Apparently they are not leading in computer security then.

                                                                                                                                                                                                                                                                    • 1928756

                                                                                                                                                                                                                                                                      yesterday at 6:41 PM

                                                                                                                                                                                                                                                                      That is such a primitive refutation. What is next? Blood libel?

                                                                                                                                                                                                                                                                      The commenter said Israel and not Jews. Israel has a long history of intelligence operations like stealing the nuclear secrets from the US.

                                                                                                                                                                                                                                                                      BTW, do you want to associate the greatest IP theft in history with Jews?

                                                                                                                                                                                                                                                                        • arionhardison

                                                                                                                                                                                                                                                                          yesterday at 6:45 PM

                                                                                                                                                                                                                                                                          BTW, I literally meant "Israel" and NOT Jews. I live in Brooklyn! I do not and refuse to conflate the two as much as anyone of any group would like me to. As I am sure you know; in no way are all Jews pro Israel and definitely not pro Israeli government and I honestly feel that any assertion of such is both reductive and foments antisemitism.

                                                                                                                                                                                                                                                              • nullc

                                                                                                                                                                                                                                                                last Monday at 9:49 PM

                                                                                                                                                                                                                                                                Leaders in the MIRI/EA cult-o-sphere have advocated mass murder via nuclear weapons against towns that don't prevent people from performing too many multiplication operations. Why is anyone surprised that they'd engage in deceptive false flagging operations?

                                                                                                                                                                                                                                                                  • drdeca

                                                                                                                                                                                                                                                                    today at 4:02 AM

                                                                                                                                                                                                                                                                    This is a lie, so you are either repeating a lie from someone else or lying yourself.

                                                                                                                                                                                                                                                                    The people you are talking about have not advocated mass murder via nuclear weapons. The idea was precisely targeted non-nuclear strikes against only the servers themselves. (Which, would have plenty of forewarning to allow people to leave the building.)

                                                                                                                                                                                                                                                                    The claim that they advocated for the use of nuclear weapons is a lie.

                                                                                                                                                                                                                                                                • teach

                                                                                                                                                                                                                                                                  last Monday at 9:41 PM

                                                                                                                                                                                                                                                                  Big if true.

                                                                                                                                                                                                                                                                  • tannerr_dev

                                                                                                                                                                                                                                                                    yesterday at 8:51 PM

                                                                                                                                                                                                                                                                    why am i not surprised