• General_Effort@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    7 hours ago

    That never made any sense. Commit a felony to present your company as a dumpster fire?

    The hack doesn’t worry me. It was a shock to see SciFi turn real, but not a cause for concern. The message board as a factor in model training is a little concerning.

  • Da Oeuf@slrpnk.net
    link
    fedilink
    arrow-up
    8
    ·
    13 hours ago

    Yeah I think it was.

    An interesting one too. It acts as a message to investors about AI’s power, but also a message to users about it being a really messy and shite tool.

    If I ask a piece of software to accomplish a task I don’t want it to cause a buggerload of new problems in the process.

    This is probably part of the reason why AI is getting so much investment but is not turning a profit.

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    7
    ·
    14 hours ago

    Agents had the ability to install packages via the package repository Artifactory. Artifactory doesn’t isolate the activity of different users, so since these agents shared the same instance, agents could also notice the package-installation activity of other agents running in parallel, even before those agents started intentionally communicating.

    As we discuss later, agents sent messages on this primary message board by creating directories in a cache of Artifactory. They could do this with the minimal permissions needed to install packages; our understanding is that Artifactory isn’t explicitly designed to keep the activity of different users isolated and to prevent different users from being able to communicate through Artifactory.

    It does seem like a big oversight at least, but I think it’s plausible that the reason it happened is just that the people working there know the company can spin this kind of thing positively, and so they aren’t getting fired if they are reckless about their sandboxing actually being good, so why bother?

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    1
    ·
    23 hours ago

    It really tells you a lot about the current state of the US where an org can admit to a federal crime, both companies go “its all good”, and the federal police are not looking into it.

    • ViatorOmnium@piefed.social
      link
      fedilink
      English
      arrow-up
      6
      ·
      17 hours ago

      If companies say “it’s all good”, why would the police look into it? If the police started prosecuting cyber crimes without a report from the victims all bug bounty programmes would become illegal.

  • 1Malayali@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    17 hours ago

    Could be also on poor security on Hugging face + OpenAI exaggerating things for publicity.