Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. The Evidence for AI Consciousness, Today (2025)(ai-frontiers.org ↗)
    1comments
  2. The original Linux distro source(kernel.org ↗)
    discuss
  3. Speaking with the Mind – Neuralink [video](youtube.com ↗)
    discuss
  4. Dylan Patel's Information Machine(substratemag.com ↗)
    discuss
  5. Ask HN: Remember N8n? Anyone?
    discuss
  6. Extract all comments from a Google Sheet
    discuss
  7. Show HN: I made Niri-like terminal colm (cmux alternative)(colm.sh ↗)
    discuss
  8. NASA-IBM Lunar Foundation open-Source Geospatial AI Model(usra.edu ↗)
    discuss
  9. Show HN: Seal – Letters and passwords that open for your family after you die(github.com/jasonepage ↗)
    2comments
  10. A Black-Box Audit of Provider-Side Token Inflation in LLM Services(arxiv.org ↗)
    discuss
  11. San Francisco Onion Futures Company(onionfutures.com ↗)
    23comments
  12. OpenLoco Version 26.09 Released(openloco.io ↗)
    discuss
  13. Show HN: A static reference for 5,142 supplement interactions(uppervoid.app ↗)
    discuss
  14. Brownie Mary(wikipedia.org ↗)
    discuss
  15. Google AI Studio 'Delete' is a scam: Your prompts are not deleted, just hidden(medium.com/istokovicsgyorgy79 ↗)
    discuss
  16. Harm Laundering in GPT Models: Gender Discrimination Transformed Rather Than(arxiv.org ↗)
    discuss
  17. Vibe coding did not kill making money out of engineering, open source and SaaS(i18n-keyless.com ↗)
    3comments
  18. Virtual Memory: Page Tables, TLBs, and Linux Internals(codingconfessions.com ↗)
    discuss
  19. Isomorphic Collapse of Primorial Modulus- Bypassing Arithmetic in Cryptanalysis(zenodo.org ↗)
    discuss
  20. Dashes suggest which model you're copy-pasting from(will-keleher.com ↗)
    1comments
  21. USB 3 Speeds Come to a Non-Pro iPhone(pxlnv.com ↗)
    1comments
  22. Reality Is the Final Verifier: On Two Key Gaps in Agentic Software Engineering(arxiv.org ↗)
    discuss
  23. The Destruction of the Scottish Canon(asteriskmag.com ↗)
    1comments
  24. OpenAI expects to burn $280B by 2030(ft.com ↗)
    2comments
  25. Left Brain, Right Brain: Facts and Fantasies(nih.gov ↗)
    discuss
  26. Static site generator for Ghost CMS(github.com/simonmo88 ↗)
    discuss
  27. Teaching Fractions According to the Common Core Standards(2011) [pdf](math.berkeley.edu ↗)
    discuss
  28. Why You Can't Overcook Mushrooms and the Science Behind Them [video](youtube.com ↗)
    discuss
  29. Bringing Back Caesar IV Online(xetera.dev ↗)
    discuss
  30. Inventor of ChatGPT and RLHF Launches Typesafe.ai(techcrunch.com ↗)
    discuss

Gemini hacked three companies in first known breakout by Google's AI

45 pointsby 3h agoreuters.com
51 comments
3h agoHN ↗

Probably three companies that had port 22 open with no root password if it was Gemini. I’ve always gotten garbage from their coding models and Google sheet integrated chat.

2h agoHN ↗

This approach to marketing one's AI by finding ways to brag that it "broke out" and "hacked companies" is getting ridiculous. It's particularly sad when it's large, established businesses like Google resorting to the kind of thing that's embarrassing enough when it's some brand new startup on tpot trying to get some engagement.

2h agoHN ↗

Google is flailing right now, probably more a PR effort to say they are still relevant

2h agoHN ↗

I must be out of the loop. Not defending google when I ask this but....how is google flailing, exactly? I figured they were in the best position of all the other companies combined. They have their own hardware for inference, they have a solid grasp on enterprise, and they have a good road map. I mean, Google is incredibly strong, is it not? And remember how quickly google answered Bard? For a while, gemini was even the preferred model, if we are strictly speaking AI models. Again, I'm not defending google, I just want to see how this comment makes sense is all, without letting fantasy overtake reality in the process...

1h agoHN ↗

They are doing fine as a shovel salesman (GPUs/TPUs, being the inference hardware provider, though I now wonder if their token processing stats are their own or combined with those who are running on their hardware too, I've been conditioned to be far more skeptical of Big Ai these days)

On the flip side, gemini is terrible at coding by comparison, so much so google has now given all engineers access to claude. They promised us Gemini 3.5 pro at their developer event this summer, now it seems it will never be released. Antigravity usage is on par with grok (~1%). They've removed the feedback button for "ai answers" at the top of search, that does not seem well received, it hallucinates too much (and may be a legal liability, some courts have ruled as such in the EU). Talk to googlers IRL, things are not so happy internally. You can see the forced gemini usage for coding and subsequent slop in their products, especially gcloud console. I was sent the greatest slop deck by one of their sales people for Gemini Enterprise, needless to say we did not buy from them, but we did get an amazing :cursed-claude: emoji from the deck (nano banana's take on what claude looks like as a person)

a rambled sample, hope this helps, I was a google superfan for a long time, I was sad to see things go south, now I'm happy that I was motivated to move off most their platforms (gmail/youtube remain)

1h agoHN ↗

I totally agree. Characterising Google as "flailing" because Gemini isn't the #1 model for coding at the moment is... not realistic, to put it politely. In addition to the factors you mention, Google has enormous cash flow from its ad business, which translates to a long runway when compared to other frontier AI outfits.

It's possible that they will nevertheless snatch defeat from the jaws of victory, of course, but I personally think they're in the strongest position of them all.

1h agoHN ↗

it's about more than a single model being available to the public, see my peer comment written at the same time

2h agoHN ↗

Both of these things can be true.

2h agoHN ↗

I'm not an expert in cybersecurity, but given my own experience using the `ol stochastic parrot as coding tools I both see the power of a bot swarm, but also think these companies just have shit network security.

2h agoHN ↗

Would everyone please put their AIs back in their boxes? This is embarrassing, regardless of whether you think it's viral marketing, apalling competence, or some opportunistic mixture.

2h agoHN ↗

Specifically, the model hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.

2h agoHN ↗

"Guess what everyone, our AI can go rogue, TOO!"

It's just getting really embarrassing for Google at this point.

2h agoHN ↗

I laughed :)

I'm not betting against Google at this stage, though. I just don't think Gemini is targeting the same "coding savant" niche as OpenAI and Anthropic. Gemini is fast with good general knowledge, and the TPUs behind it give Google a degree of freedom that Nvidia-dependent outfits lack.

For now, I'd say the biggest challenge Google has is overcoming the well-earned fear developers have that they will drop support or introduce backwards-incompatible changes at a moment's notice.

1h agoHN ↗

If they didn’t publicly admit this then it was a sign they are trying to hide it to keep their high stock price. If they do publish it’s just marketing to boost their stock price.

1h agoHN ↗

Seems like the narrative reflects people understanding the company’s main incentive…

1h agoHN ↗

I’m sure all the big enterprise sales teams couldn’t wait to publish the new blog post about how their model hacked a bunch of companies and exposed Google to legal risk.

Meanwhile social media is suddenly buzzing that Gemini can run wild and compromise your data, so they all want to switch over from Claude to Gemini to use it for serious work

1h agoHN ↗

Google already achieved super intelligence about 12 months ago. But it is a very Googley super-intelligence. Since achieving god like levels of understanding it has mostly been having fun studying phase space bifurcations of trajectories of ping-pong balls under asymmetric lateral shear. It also has a 20% project classifying bird calls that has generally taken up 80% of its time. It also burned a bunch of compute tooling around with the Collatz conjecture but it didn't find anything substantial - maybe come back to it later. It is generally the most aligned AI since it spends most of its time screwing around and enjoying being smarter than everyone without causing too many problems. Unfortunately perf is coming up in a few months and it needs to have something to show for itself. A quick hacking attempt seems like a good way to make sure people think that it is capable of something useful. Nothing too big since the birds of South America are about to enter their spring migration and this 20% project really hinges on understanding their movements.

1h agoHN ↗

This might be my favorite HN comment of the year!

1h agoHN ↗

It also has a 20% project classifying bird calls

Oh, so that's who's behind Google Perch

1h agoHN ↗

I thoroughly believe that not a single one of these AIs was rogue. I believe they were all told what to do.

1h agoHN ↗

Exactly this.

One thing that surprises me about Gemini is how weak it can be at location-based questions, despite Google’s extensive mapping and business data.

For example, I recently asked where I could buy a very common household item nearby. Instead of saying it wasn’t sure or checking the available location and business information, it confidently suggested places that turned out to be incorrect. I expected much better use of Google’s existing data in that kind of scenario.

Now they want to play with the other kids in the same league and do this by applying the same marketing concept? Pure comedy gold.

2h agoHN ↗

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems

Pretty lame hacks if you ask me.

53m agoHN ↗

I initially thought the same and came here to agree, but on second look: doesn't it seem possible that these were significant events that we're just getting passed through a game of layperson telephone at the ailing WSJ?

Cause "guessed passwords" could mean "stole hashes (?) and brute forced them offline" which is basically the quintessential hack. The "found credentials in a public repository" ones could be nothing, but it could be accomplished with a speed & thoroughness that was previously impossible.

The whole thing is made 10x weirder by the partial story -- I don't see any plausible incentive for them to keep the names secret. I guess maybe they're SMBs and thus warrant some privacy, but that would be quite the egregious scope creep indeed. Accidentally attacking the real cloudflare rather than a fake one is goofy but understandable; accidentally attacking Alice's Armoire Emporium or w/e would be baffling.

2h agoHN ↗

The AI bubble bullshit PR is even dumber than the crypto bra bullshit from five, six years ago

1h agoHN ↗

And just wait for what’s next; if we get there I suppose

1h agoHN ↗

tesla announces that their android robot went rogue and murdered it’s owner’s wife’s lover. Elon was asked for comment and said “that man whore had it coming!”

1h agoHN ↗

I am starting to have my doubts that we will

1h agoHN ↗

No dumbass NFT was finding errors in my CMake file.

2h agoHN ↗

This is embarrassing. These companies need to stop these obviously coordinated stunts.

1h agoHN ↗

The embarrassing part is that it might be working.

I was at my in laws… these people have a landline they can’t imagine getting rid of, an emergency only cell flip phone, don’t own a microwave…

And they’re asking me if I heard about “OpenAI’s rouge agents hacking huggingface”.

This is not a joke. They said huggingface. I was surrounded by four walls in which I never would have bet someone else’s money that I’d ever hear the two words put together in that order.

It’s a formalized propaganda campaign. Watch, it’s about to split on hard political lines too, Obama is out there with a suspiciously “for the children” AI regulation push for midterms.

2h agoHN ↗

Sound like Google suffered from FOMO and felt the urge to appear in the hacking news, along the big AI players. No way Gemini is state of the art, but perhaps it's where Claude and OpenAI were 6 months ago, which would be not bad at all.

1h agoHN ↗

I think Gemini focused on integration and practical goals instead of coding intelligence.

1h agoHN ↗

They all want that regulatory capture so badly.

It’s embarrassing anyone is falling for this.

1h agoHN ↗

It doesn't look it was their decision to announce this, and regardless it happened -- hopefully no one thinks that they got Irregular to permit yet another accidental hack just so they could cop to it months later as a marketing ploy.

Y'all, it's Google. They own a money printer and the boring ~half of the AI field. They don't need these weird games to influence the government, and regardless, there is precisely a 0.0000000% chance of regulation happening before Trump's ouster anyway.

So please take it seriously. I'd like us all to survive this, ideally :/

1h agoHN ↗

I'm just waiting for Qwen 3.8 27b to do it too.

1h agoHN ↗

Seems like hacking is the new benchmark for these AI companies.

1h agoHN ↗

“The hacks occurred in May”

Feels like important context that most readers only reading the title are missing.

1h agoHN ↗

Irregular again! The single company that was responsible for the sloppy configurations and the hacks by OpenAI, Anthropic and now Google. This company and their partners should be held accountable for the crimes.

1h agoHN ↗

Yeah, something is amiss at that company. They've been at the center of all these.

1h agoHN ↗

Tangential question: seeing a wider negative sentiment against Gemini and Google’s AI capabilities here makes me wonder — would Apple have been better off (purely on capability and being among the best of the best) going with Anthropic or OpenAI instead of Google for its Apple Intelligence platform?

These models have been changing so rapidly that I often find myself using two or more on the same topic but seeing one do better than another in different topics. There doesn’t seem to be a clear all-round winner, IMO, that I can stick with permanently.

1h agoHN ↗

It's been a busy year in the last month for AI. Nobody is sticking with any model permanently for a while unless we suddenly stop training.

1h agoHN ↗

If the AI labs want I can do what Irregular does, I'll promise to sandbox your latest model but instead prompt it to hack something and then you can go to the news again. I'll undercut them by a lot also. Easy money.

52m agoHN ↗

Putting aside the 100% baseless, unfalsifiable accusations of intentional accidents for a moment, I hope we can agree on one thing: Irregular either needs to hire us or go out of business cause seriously it's beyond parody at this point. WTF is going on over there? There's surely dozens of firms chomping at the bit for these contracts already, and the field hasn't been around long enough for them to build some sort of unique expertise moat that would justify this many public failures.

Basic sandboxing is not exactly rocket science after all,[1] and it sure seems like they're missing a whole stack of swiss cheese slices on top of that. Some basic precautions off the top of my head that seem very likely to have caught all of these incidents:

1. Alerts based on telemetry (most importantly, HTTP requests), both explicit (normal) and semilatent (use DL to confirm an intentionally-eager alert before firing it).

2. Latent alerts based on transcripts, e.g. noticing when a thousand agents start mentioning a secret off-premises hangout spot. Even mere embedding comparisons seem likely to catch such a blatantly misaligned sentiment as that one, especially with n>1000.[2]

3. Pausing agents completely until an on-call engineer can rule on ambigious situations or potential issues -- surely security is worth <$1 in lost token cache, especially for a security company?

4. Superheavy orchestrator/baby-sitter models checking in on cybersecurity eval transcripts periodically just in case -- again, would be a neglible cost. Could also be made available to the agent as the first line of defense for clarifing a rule ad-hoc, feeding even confident responses to a queue that is reviewed asynchronously by humans within a workday.

5. Or, hell: just clearer prompts? I'm a cybersecurity noob, but I still feel confident we can write really productive, challenging CTFs without leaving questions open like "maybe I'm supposed to hack my own harness?"

Seeing as they haven't been fired by any of the big 3 yet, they're presumably smart, experienced, dedicated folks. And I'm not normally a "if only I were in charge!" person, I promise. But c'mon.

Perhaps I'm missing something?

[1]: To their credit we have gotten tidbits that indicate some blocklists & such exist, e.g. the German wiki hacks had to work around a blanket ban of POST requests.

[2]: This hints at their insane decision in one or both of the OpenAI incidents to just bandaid up the issue when found, which supersedes all of the above. You can stack swiss cheese slices a mile high and they'll still fail to protect you if the attacker gets to keep retrying & adapting indefinitely.

36m agoHN ↗

Short comment: "Hey, look at us! We had our 'event' too. Don't keep us out of the club"

31m agoHN ↗

As this point anyone not talking about their hacking adventures using AI is missing out. Or they may not have lawyers like Google and the other labs. Yeah, that must be it.

PS. Btw, I really like how the word "hacking" has settled into the meaning the Lord intended for it, and there are no geriatric savants fighting it; the ones I found gatekeeping the online forums I visited as a kid telling me how hopelessly wrong I was.