Massive over-exaggeration. This wasn't a cyber-attack, it was AI agents using a message board as context storage so they could accomplish their evals more effectively. I'm not saying there's no problem with this, but let's keep a level head.
Massive over-exaggeration. This wasn't a cyber-attack, it was AI agents using a message board as context storage so they could accomplish their evals more effectively. I'm not saying there's no problem with this, but let's keep a level head.
https://openai.com/index/hugging-face-incident-and-the-road-... that was the attack, the one against HuggingFace. OpenAI themselves in the post even call it an attack, and so do the agents orchestrating it, in one of the "Agent chain-of-thought reasoning" excerpts.
He didn't say it was a cyber-attack, but it was a cyber-attack risk. Being able to bypass instructions (morality) and security restrictions (capability) is bread and butter for hacking.
"cyberattack" is indeed exaggerated. AI breakout risk most definitely isn't, specially given how their swarm did in fact hack HuggingFace not long ago.
Did you read the report? They were attempting XSS exploitation, admin impersonation, session-hijacking, all kinds of things. This went beyond just "using a message board".
According to whom? This isn't a report from the owner of the site who can validate what requests were made to the servers, it's someone who allegedly stumbled on to it and is piecing together a sensationalized narrative with limited information. This someone also happens to be an AI doomer that is trying to make a name for himself and is peddling his "AI 2027" and "AI 2040" material.
The people who actually do know what happened, with the server logs: "OpenAI disputed that characterization based on its analysis of the material Thursday."