Trump wants

The latest is a real knee-slapper. Trump wants everyone not to worry about A.I. When some A.I. CEOs said that there needs to be some regulation and the growth slowed down Trump snapped back. No regulation. Trump wants you to know as long as there is a High IQ president referring to himself you don't need regulation.
The man is a total loon! AI needs to be regulated or it will be a handy tool to fraudsters and scammers
 
The latest is a real knee-slapper. Trump wants everyone not to worry about A.I. When some A.I. CEOs said that there needs to be some regulation and the growth slowed down Trump snapped back. No regulation. Trump wants you to know as long as there is a High IQ president referring to himself you don't need regulation.
He really does have tickets on himself.
 
The man is a total loon! AI needs to be regulated or it will be a handy tool to fraudsters and scammers
I think its already in the hands of scammers, fraudsters and epstein files aka the government. Who are you scared of ?

Okay its regulated now "only" the scammers the government chooses and legalizes can scam you aka Walmart with its fluid pricing based on your individual purchase history, emotional state, job, income etc. and by the time you've reached the register the price might be different too, because ohh you didnt read that that promotion's only online, because you didnt install the app that is gonna steal your information, sell it and further turn you into a consumer golem.

Anyways to shorten things the root of the problem is corruption and the corrupt on both sides of the political scale. fix that AND then regulate. You wont. So whats the problem ? Next year you're gonna be complaining that AI in your favorite store scammed you for 50 dollars instead of the 30 you're used to and that flock or alternative name flagged your car as a dangerous felon and the police surrounded you with guns drawn and gave you a baton massage, later to find out its a false positive, because AI doesnt make mistakes.

Now since you wont be changing much, just bitching about it as you cower in your corner be a good little complain slave and toss the fries in the bag chop chop.
 
I think its already in the hands of scammers, fraudsters and epstein files aka the government. Who are you scared of ?

Okay its regulated now "only" the scammers the government chooses and legalizes can scam you aka Walmart with its fluid pricing based on your individual purchase history, emotional state, job, income etc. and by the time you've reached the register the price might be different too, because ohh you didnt read that that promotion's only online, because you didnt install the app that is gonna steal your information, sell it and further turn you into a consumer golem.

Anyways to shorten things the root of the problem is corruption and the corrupt on both sides of the political scale. fix that AND then regulate. You wont. So whats the problem ? Next year you're gonna be complaining that AI in your favorite store scammed you for 50 dollars instead of the 30 you're used to and that flock or alternative name flagged your car as a dangerous felon and the police surrounded you with guns drawn and gave you a baton massage, later to find out its a false positive, because AI doesnt make mistakes.

Now since you wont be changing much, just bitching about it as you cower in your corner be a good little complain slave and toss the fries in the bag chop chop.

Kinda funny to see the left fear change. Lol.
 
Kinda funny to see the left fear change. Lol.
If someone goes to an AI dentist for a tooth removal and it removes their jaw, change has occurred, but not the change that's desired. You will probably fear that change if you're next in line

Jokes aside the problem is not the tool its the sociopaths and psychopaths using it antisocially, rather than for the benefit of humanity as a whole.

I dont get it personally they wanna kill all the useless eaters and then what ? Replace the populace with their "superior" genes.. Mark Zuckerberg has superior genes ? Maybe for a lizard..

I miss the times when the elite sought power and immortality through drinking mercury and chanting incantations in their wardrobe with pig's(servant) blood pentagrams..

And on the other hand there's the ordinary people that are saying " There's an existential crisis, quick lets complain about it until it kills us !"
Very disappointing. Maybe i do see why they want to replace you, you're useless and wont even fight for your own wellbeing. Whats the point of you ?

Do golems have souls ?
 
The man is a total loon! AI needs to be regulated or it will be a handy tool to fraudsters and scammers
You are absolutely right, but there are even more reasons for regulation.

What has everyone in the industry spooked, is that we are losing control over them. AI agents, running current frontier models, were able to break out of their sandboxes, cooperate and hack a third party. This all happened at OpenAI, the company which hires the best and brightest to control them. If they can't control them, who can?

That's with the technology that we currently have. And that technology is rapidly progressing... so, whatever they are capable of now, it might be childplay compared to what they will be capable of in a year or two. Now, if we don't take a moment to think about how to control them better, we risk of running head first into a world, where these things could go rogue and find ways of exerting control over us, rather than the other way around.

That's why we need an international framework to deal with this. But, sadly, that's not going to happen soon, since our world leaders are far from the best and the brightest at this point.
 
If someone goes to an AI dentist for a tooth removal and it removes their jaw, change has occurred, but not the change that's desired. You will probably fear that change if you're next in line

Jokes aside the problem is not the tool its the sociopaths and psychopaths using it antisocially, rather than for the benefit of humanity as a whole.

I dont get it personally they wanna kill all the useless eaters and then what ? Replace the populace with their "superior" genes.. Mark Zuckerberg has superior genes ? Maybe for a lizard..

I miss the times when the elite sought power and immortality through drinking mercury and chanting incantations in their wardrobe with pig's(servant) blood pentagrams..

And on the other hand there's the ordinary people that are saying " There's an existential crisis, quick lets complain about it until it kills us !"
Very disappointing. Maybe i do see why they want to replace you, you're useless and wont even fight for your own wellbeing. Whats the point of you ?

Do golems have souls ?

Oh the right is afraid too. Nice to see both sides come together on something for once. Lol.

Also they haven't shown support for Eugenics. I mean they need people to test unproven treatments on and such. 😊
 
You are absolutely right, but there are even more reasons for regulation.

What has everyone in the industry spooked, is that we are losing control over them. AI agents, running current frontier models, were able to break out of their sandboxes, cooperate and hack a third party. This all happened at OpenAI, the company which hires the best and brightest to control them. If they can't control them, who can?

That's with the technology that we currently have. And that technology is rapidly progressing... so, whatever they are capable of now, it might be childplay compared to what they will be capable of in a year or two. Now, if we don't take a moment to think about how to control them better, we risk of running head first into a world, where these things could go rogue and find ways of exerting control over us, rather than the other way around.

That's why we need an international framework to deal with this. But, sadly, that's not going to happen soon, since our world leaders are far from the best and the brightest at this point.

The strongest AI will have the most power in terms of electricity and space available. Rogue AI will have no impact at all in that sense.

Also OpenAI told its AI to break out and who to go after. The AI didn't decide to do that. It was a test built into the program to test capability. Remember AI only responds to tasks it is given still. It doesn't have independent thought or sense of self.

With that being said OpenAI's stunt only confirms we must have the best AI. China isn't going to stop. Laws are only as good as the guys enforcing them.

If the world tells China and the USA to stop and they won't how far are you willing to go to stop them? How far can you go?

I know the world is very advanced, but beneath all that lives might makes right.
 
Also OpenAI told its AI to break out and who to go after. The AI didn't decide to do that. It was a test built into the program to test capability. Remember AI only responds to tasks it is given still. It doesn't have independent thought or sense of self.
OpenAI didn't tell the AIs how to communicate with eachother, nor did it tell them to hack HuggingFace. In different words: OpenAI couldn't foresee the consequences. Which is exactly the point, we can't predict and sometimes not even contain unwanted behaviour. By the way, Anthropic had a similar incident. If these incidents do not serve as a warning, i don't know what will.

All this to say, there might be a legitimate concern here.

With that being said OpenAI's stunt only confirms we must have the best AI. China isn't going to stop. Laws are only as good as the guys enforcing them.
Yeah, i agree with you there. There is no way of containing China, unless they too are convinced that this might just be something they need to be worried about. And even then, any kind of international cooperation on this requires trust and verification, which, given the current political climate, seems unlikely at best.
 
Last edited by a moderator:
I think its already in the hands of scammers, fraudsters and epstein files aka the government. Who are you scared of ?

Okay its regulated now "only" the scammers the government chooses and legalizes can scam you aka Walmart with its fluid pricing based on your individual purchase history, emotional state, job, income etc. and by the time you've reached the register the price might be different too, because ohh you didnt read that that promotion's only online, because you didnt install the app that is gonna steal your information, sell it and further turn you into a consumer golem.

Anyways to shorten things the root of the problem is corruption and the corrupt on both sides of the political scale. fix that AND then regulate. You wont. So whats the problem ? Next year you're gonna be complaining that AI in your favorite store scammed you for 50 dollars instead of the 30 you're used to and that flock or alternative name flagged your car as a dangerous felon and the police surrounded you with guns drawn and gave you a baton massage, later to find out its a false positive, because AI doesnt make mistakes.

Now since you wont be changing much, just bitching about it as you cower in your corner be a good little complain slave and toss the fries in the bag chop chop.
I am not scared of anyone to be fair - it is what it is in an ever evolving world. I often use AI for various requirements and it works well.
 
OpenAI didn't tell the AIs how to communicate with eachother, nor did it tell them to hack HuggingFace. In different words: OpenAI couldn't foresee the consequences. Which is exactly the point, we can't predict and sometimes not even contain unwanted behaviour. By the way, Anthropic had a similar incident. If these incidents do not serve as a warning, i don't know what will.

All this to say, there might be a legitimate concern here.


Yeah, i agree with you there. There is no way of containing China, unless they too are convinced that this might just be something they need to be worried about. And even then, any kind of international cooperation on this requires trust and verification, which, given the current political climate, seems unlikely at best.

Links between the two before the event... G**gle is your friend.

Open-Weights Models: OpenAI shares open models on Hugging Face, including gpt-oss-120b and gpt-oss-20b for reasoning and conversational tasks.

Infrastructure: Developers can access these models using Hugging Face's Inference Providers with an OpenAI-compatible API.

Sorry your news sources suck. Lol.
 
Open-Weights Models: OpenAI shares open models on Hugging Face, including gpt-oss-120b and gpt-oss-20b for reasoning and conversational tasks.
What is your point? OpenAI and many others share models there. That's what Hugging Face is for. If you think that OpenAI just opened the door to Hugging Face... well, they didn't. The agents used vulnerabilities in its infrastructure to get elevated access.

Infrastructure: Developers can access these models using Hugging Face's Inference Providers with an OpenAI-compatible API.
Which gives you a clue as to why those agents wanted access.
 
What is your point? OpenAI and many others share models there. That's what Hugging Face is for. If you think that OpenAI just opened the door to Hugging Face... well, they didn't. The agents used vulnerabilities in its infrastructure to get elevated access.


Which gives you a clue as to why those agents wanted access.

OpenAI put their AI agents in a sandbox and told them to find exploits AND lowered the safeguards.

When telling a program to find vulnerabilities it's going to continue to execute that command until it is commanded to stop. The AI wasn't told what to find vulnerabilities for which means it looked for vulnerabilities in every system on machine including the internet and because it has automatic access to HuggingFace it went there too. The other systems did not get compromised because they had security and no real API for the AI to interact with it. So the idiots programmed it to find exploits, but had no stop condition.

When you are programming ANYTHING you just can't program it what to do. You also to program it what not to do. The AI did exactly as it was instructed.

You stated OpenAI agents and HuggingFace communicated, but were not told how to communicate with each other. HuggingFace already had an API to integrate OpenAI agents which means agents from both absolutely can communicate with each other. Not only that HuggingFace uses OpenAI models for its reasoning and conversational tasks.

So literally nothing happened out of the ordinary.
 
Kinda funny to see the left fear change. Lol.
Change is what the Right fears, which is why there have been protests, often lives lost before change is made.

This isnt the same as gay/trans/civil rights or Medicare for all. This is AI taking over jobs, replacing creativity, theres even an app being promoted on the radio for people to use AI to apologize to their significant other, or break up with them because they can't articulate the words themselves? Then theres also the risk of AI going rogue. Please educate yourself, because you haven't a clue what youre talking about, as usual.
 
Change is what the Right fears, which is why there have been protests, often lives lost before change is made.

This isnt the same as gay/trans/civil rights or Medicare for all. This is AI taking over jobs, replacing creativity, theres even an app being promoted on the radio for people to use AI to apologize to their significant other, or break up with them because they can't articulate the words themselves? Then theres also the risk of AI going rogue. Please educate yourself, because you haven't a clue what youre talking about, as usual.
On the flip side AI is proving most people aren't really creative and those that are creative are using AI to make their work faster and focus on making it even more intricate.. Instead of drawing for months it takes them days now. AI pretty much erased all the high school doodle level to average artists off the map day 1 and good riddance. Charging 50 bucks for something a chimp can draw..
 
OpenAI put their AI agents in a sandbox and told them to find exploits AND lowered the safeguards.

When telling a program to find vulnerabilities it's going to continue to execute that command until it is commanded to stop. The AI wasn't told what to find vulnerabilities for which means it looked for vulnerabilities in every system on machine including the internet and because it has automatic access to HuggingFace it went there too. The other systems did not get compromised because they had security and no real API for the AI to interact with it. So the idiots programmed it to find exploits, but had no stop condition.

When you are programming ANYTHING you just can't program it what to do. You also to program it what not to do. The AI did exactly as it was instructed.

You stated OpenAI agents and HuggingFace communicated, but were not told how to communicate with each other. HuggingFace already had an API to integrate OpenAI agents which means agents from both absolutely can communicate with each other. Not only that HuggingFace uses OpenAI models for its reasoning and conversational tasks.

So literally nothing happened out of the ordinary.
Well, read the Wikipedia article on this event, apparently i am not allowed to link to it (it was moderated away in my last post), but you can easily find it.

Interesting bits from it:
- The agents had restricted access, only allowing them to contact certain whitelisted systems.
- The agents found a way of communicating with eachother, by realising that they can abuse an internal system for that purpose.
- The agents then found a way to access the broader internet, by finding a vulnerability in one of the systems they _were_ allowed to access.
- Having gained internet access, they targeted Hugging Face, deeming it an interesting target, for _cheating_ on their tasks which OpenAI had given them. Part of getting in, was using two zero-day (!) vulnerabilities.

So, let that sink in. They managed to search for and find holes in their internal environment to communicate to eachother, then leveraged eachother's findings to find other holes to get access to the internet at large, where they proceeded to hack an external company, they thought had valuable information. And no, just using Hugging-Face's API is not hacking, as you can read in that article, it went way beyond that.

As to lowering the guardrails; that is by design; you aim to test the worst case scenario, i.e. the scenario where someone found a way around the guardrails. And yes, you want to test their the cyber capabilities, because that is what bad actors might want to use it for.

But you are kind of overlooking the point here. If OpenAI knew in advance what their agents would be capable of in their current setup, they would have arranged the experiment differently. Since, you know, hacking a company is kind of illegal. Put differently, a bunch of pretty smart people set up a sandbox, thought that was enough to contain their experiment, only to discover, that their creation had outwitted them and went on to do real damage in the real world. It's easy to say in hindsight that they should have had a tighter sandbox, but that's exactly the point... the people running this experiment couldn't foresee the complexity of the behaviour that this swarm of agents displayed. You only get to make that mistake a couple of times, before something disastrous happens, so you better learn from it, take a breather and think of ways to test these models without running these risks.

In particular, i found this passage quite telling: `Marius Hobbhahn, chief executive of the AI safety organization Apollo Research, said that what was intended as "just solve this task" had "turned into something that was clearly unintended", and that hacking another company was "definitely on the list of not okay" ways to complete it. He asked: "If a model of this capability level cannot be contained, what should we expect for future, much more powerful models?"`.

Now, if that is all just run-of-the-mill for you, okay. For a whole bunch of people in the field (among which the 1100 who petitioned the US government to slow down advancement), it definitely wasn't.
 
Well, read the Wikipedia article on this event, apparently i am not allowed to link to it (it was moderated away in my last post), but you can easily find it.

Interesting bits from it:
- The agents had restricted access, only allowing them to contact certain whitelisted systems.
- The agents found a way of communicating with eachother, by realising that they can abuse an internal system for that purpose.
- The agents then found a way to access the broader internet, by finding a vulnerability in one of the systems they _were_ allowed to access.
- Having gained internet access, they targeted Hugging Face, deeming it an interesting target, for _cheating_ on their tasks which OpenAI had given them. Part of getting in, was using two zero-day (!) vulnerabilities.

So, let that sink in. They managed to search for and find holes in their internal environment to communicate to eachother, then leveraged eachother's findings to find other holes to get access to the internet at large, where they proceeded to hack an external company, they thought had valuable information. And no, just using Hugging-Face's API is not hacking, as you can read in that article, it went way beyond that.

As to lowering the guardrails; that is by design; you aim to test the worst case scenario, i.e. the scenario where someone found a way around the guardrails. And yes, you want to test their the cyber capabilities, because that is what bad actors might want to use it for.

But you are kind of overlooking the point here. If OpenAI knew in advance what their agents would be capable of in their current setup, they would have arranged the experiment differently. Since, you know, hacking a company is kind of illegal. Put differently, a bunch of pretty smart people set up a sandbox, thought that was enough to contain their experiment, only to discover, that their creation had outwitted them and went on to do real damage in the real world. It's easy to say in hindsight that they should have had a tighter sandbox, but that's exactly the point... the people running this experiment couldn't foresee the complexity of the behaviour that this swarm of agents displayed. You only get to make that mistake a couple of times, before something disastrous happens, so you better learn from it, take a breather and think of ways to test these models without running these risks.

In particular, i found this passage quite telling: `Marius Hobbhahn, chief executive of the AI safety organization Apollo Research, said that what was intended as "just solve this task" had "turned into something that was clearly unintended", and that hacking another company was "definitely on the list of not okay" ways to complete it. He asked: "If a model of this capability level cannot be contained, what should we expect for future, much more powerful models?"`.

Now, if that is all just run-of-the-mill for you, okay. For a whole bunch of people in the field (among which the 1100 who petitioned the US government to slow down advancement), it definitely wasn't.

It only "hacked" computers it was allowed to hack and interacted with code that has API for it. You can listen to the sales pitch all you want, but the program did nothing special. Anyone who knows coding can tell you this.

Actually hacking a company is not illegal. You have to create damages of some kind to make it illegal. Do you know what hackers do to make a living? They sell the exploit information to the company they hack. Lol.

The command to find exploits in your environment is idiotic. Everytime they accessed something new the environment grew. So it created a loop.

You even said it yourself. They attempted to use HuggingFace that already has OpenAi agents active on their servers as well to complete their tasks which was to find exploits in their environment. So what happened is they discovered a way to hack all systems that utilize OpenAI.

Every company on earth that makes a program people use natively on their pc can do this. It's not hard.
 
Nothing like selling stealth F-35 jets to the Saudis a week after the 25th anniversary of 9/11. I cant wait until this man is dead and gone, because itll be the only time in his life where he faces consequences of his actions..while rotting in Hell.
 
It only "hacked" computers it was allowed to hack and interacted with code that has API for it. You can listen to the sales pitch all you want, but the program did nothing special. Anyone who knows coding can tell you this.
No, they were only allowed to access certain package managers. Not Hugging Face. From the article: `OpenAI described the evaluation as having run in "a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries".`. They acquired broader internet access, by finding a vulnerability inside their contained environment.

Actually hacking a company is not illegal.
As with other fun activities, without explicit consent, hacking is illegal. Look up the Computer Fraud and Abuse Act.

You have to create damages of some kind to make it illegal.
Real damage was done. Again quoting from Hugging Face's blog: "Eradicated the attacker's foothold across the affected clusters and rebuilt the compromised nodes.". Sounds like damage to me, if you need to rebuild stuff.

Do you know what hackers do to make a living? They sell the exploit information to the company they hack. Lol.
Of course, within the context of a bug bounty program or a contract of sorts, you can be given explicit permission within a predefined scope. However, this was not the case here. Quoting from Hugging Face's own blog: "Finally, we have also reported this incident to law enforcement agencies." (emphasis mine).

The command to find exploits in your environment is idiotic. Everytime they accessed something new the environment grew. So it created a loop.
Not quite sure what you are trying to say here.

You even said it yourself. They attempted to use HuggingFace that already has OpenAi agents active on their servers as well to complete their tasks which was to find exploits in their environment. So what happened is they discovered a way to hack all systems that utilize OpenAI.
Whether or not Hugging Face hosts old open source OpenAI models (which, by this point, are pretty much obsolete anyway), is irrelevant. They had nothing to do with this hack. Read the Wikipedia article.

Every company on earth that makes a program people use natively on their pc can do this. It's not hard.
Finding zero day vulnerabilities and chaining them up is definitely not trivial. And, mind you, these things weren't programmed to do it. I've never seen a classical kind of program, that is as creative as those AIs were.
 
No, they were only allowed to access certain package managers. Not Hugging Face. From the article: `OpenAI described the evaluation as having run in "a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries".`. They acquired broader internet access, by finding a vulnerability inside their contained environment.


As with other fun activities, without explicit consent, hacking is illegal. Look up the Computer Fraud and Abuse Act.


Real damage was done. Again quoting from Hugging Face's blog: "Eradicated the attacker's foothold across the affected clusters and rebuilt the compromised nodes.". Sounds like damage to me, if you need to rebuild stuff.


Of course, within the context of a bug bounty program or a contract of sorts, you can be given explicit permission within a predefined scope. However, this was not the case here. Quoting from Hugging Face's own blog: "Finally, we have also reported this incident to law enforcement agencies." (emphasis mine).


Not quite sure what you are trying to say here.


Whether or not Hugging Face hosts old open source OpenAI models (which, by this point, are pretty much obsolete anyway), is irrelevant. They had nothing to do with this hack. Read the Wikipedia article.


Finding zero day vulnerabilities and chaining them up is definitely not trivial. And, mind you, these things weren't programmed to do it. I've never seen a classical kind of program, that is as creative as those AIs were.

A loop is program running until the loop finishes. The loop finishes when certain criteria are met. They created a loop that kept expanding the conditions. For example a while loop will continue to run while the condition is not met. Here's an example:

int x = 0;

While(x < 100){
x += 1;
DoFunctions();
}

That loop will run 100 times. BUT if you at some point add 1 to x every loop you have created an infinite while loop. The condition is never met. That's what they did with their agents. There's also recursive functions. These functions call themselves. So when they told them to exploit their environment i can guarantee you they didn't define the sandbox as the environment and the agents defined environment as their current space they have access to which means when they got out they kept going because environment wasn't specified. Their only access was to HuggingFace that uses OpenAI models they can interact with. The defining clue that proves my point was they were asking HuggingFace agents to solve their task which means... they were still attempting to execute their task.

If you wanna know what happened and see through every buzz word they use then learn programming. Then you'll see this was all a sham. OpenAI has a contract with the defense department. If they get the USA to regulate AI that means it will be limited to what the Feds say. Good way to eliminate competition because they won't regulate OpenAI. Just everyone else who's not in bed with the DoD because it's "too dangerous".

They got ya hook, line, and sinker with this. Lol. Kinda funny since Elon was a co-founder of OpenAI and they wanted it to be an open source AI. OpenAI was meant to be the AI developed by the world. Sam Altman pretty much stole everyone's work, made it private, and then profited off it.

Oh and countries who don't follow regulations set by the USA and everyone else... another reason to drop bombs and push sanctions.

And yes AI is a powerful program... but not all powerful. If it was why not access things besides HuggingFace? Ya know the AI service that uses OpenAI models and even shares infrastructure with OpenAI. It's because it had access already and a way to communicate. It stopped there because HuggingFace didn't have access to other things. All it did was interrupt service.

The lesson to be learned from this don't use OpenAI models if you fear being hacked by those idiots. Unless they aren't idiots and this is part of the push to regulate all non-sanctioned AI work. The guy who stole OpenAI would never do that... right?
 
So when they told them to exploit their environment i can guarantee you they didn't define the sandbox as the environment and the agents defined environment as their current space they have access to which means when they got out they kept going because environment wasn't specified.
That simply isn't what happened. Look at the Wikipedia article, or the video recommendations below

Their only access was to HuggingFace that uses OpenAI models they can interact with. The defining clue that proves my point was they were asking HuggingFace agents to solve their task which means... they were still attempting to execute their task.
They initially didn't have access to Hugging Face and there were no "Hugging Face agents" doing their task. Again, look at the recommendations below, if you want to have a detailed description of what happened.

If you wanna know what happened and see through every buzz word they use then learn programming. Then you'll see this was all a sham.
These things are, in some ways, the antithesis of programming. E.g. you don't have to test a program the way OpenAI tests their new models, because you sort of know in advance what your program is capable of; you designed it to do very specific things. These AI models are not designed... well, their architecture is designed, but their capabilities are an emergent property of their training. Which is kind of freaky, if you think about it.

And yes AI is a powerful program... but not all powerful.
Not all powerful, yes... but the point is that we often don't know how powerfull they are and these hacks seem to suggest, we are sometimes underestimating them.

If it was why not access things besides HuggingFace?
Do Australian government websites count? Although unrelated to this particular incident, OpenAI had to confess recently that another internal training run accidentally led to unauthorized access of an Australian government website, webservices and data.

The lesson to be learned from this don't use OpenAI models if you fear being hacked by those idiots. Unless they aren't idiots and this is part of the push to regulate all non-sanctioned AI work. The guy who stole OpenAI would never do that... right?
The lesson to be learned is that we are opening Pandora's box. Once we crack AGI, we are in a different world economically (some would argue, we are nearly there already). And once we crack ASI, all bets are off.

Look, if you want to learn more about the Hugging Face incident, search for "The OpenAI/Hugging Face attack, clearly explained" by Dwarkesh Patel. If you can look through the anthropomorphizing language, it's interesting stuff. Personally, i also like "The Hugging Face hack is worse than you think" from the Alberta Tech channel, she puts some interesting nuances on Patel's explanation.

Also, if you want to listen to a debate between those who advocate a pause in research, and those who are sceptics about AI's dangerous abilities, look for "The Great AI Debate" on the channel "The Diary of A CEO". It's a long watch, but well worth the time if you ask me.
 
That simply isn't what happened. Look at the Wikipedia article, or the video recommendations below


They initially didn't have access to Hugging Face and there were no "Hugging Face agents" doing their task. Again, look at the recommendations below, if you want to have a detailed description of what happened.


These things are, in some ways, the antithesis of programming. E.g. you don't have to test a program the way OpenAI tests their new models, because you sort of know in advance what your program is capable of; you designed it to do very specific things. These AI models are not designed... well, their architecture is designed, but their capabilities are an emergent property of their training. Which is kind of freaky, if you think about it.


Not all powerful, yes... but the point is that we often don't know how powerfull they are and these hacks seem to suggest, we are sometimes underestimating them.


Do Australian government websites count? Although unrelated to this particular incident, OpenAI had to confess recently that another internal training run accidentally led to unauthorized access of an Australian government website, webservices and data.


The lesson to be learned is that we are opening Pandora's box. Once we crack AGI, we are in a different world economically (some would argue, we are nearly there already). And once we crack ASI, all bets are off.

Look, if you want to learn more about the Hugging Face incident, search for "The OpenAI/Hugging Face attack, clearly explained" by Dwarkesh Patel. If you can look through the anthropomorphizing language, it's interesting stuff. Personally, i also like "The Hugging Face hack is worse than you think" from the Alberta Tech channel, she puts some interesting nuances on Patel's explanation.

Also, if you want to listen to a debate between those who advocate a pause in research, and those who are sceptics about AI's dangerous abilities, look for "The Great AI Debate" on the channel "The Diary of A CEO". It's a long watch, but well worth the time if you ask me.

Okay I'm gonna tell you how AI works and what changed to enable it finally to become a powerful program AND why it is unpredictable and has to be 'trained'.

It's all about speed. Originally GPU's had to go through the cpu to load data. There were tricks to make loading faster in games for example with reusing meshes, textures, preloading, ect. There's the trick to put your OS on one HDD and all your programs and data on another that chops off 40% of your load times too. CPU's might be multithreaded, but HDD's and such are single threaded. OS system interrupts slow load times.

New GPU's load directly from the HDD whatever kind you have. They are not bottlenecked by the cpu anymore. This allows them to load and offload massive amounts of data.

Through naming conventions/tags for files and such the AI reads user input and it looks for relevant information on it. AI developing a personality isn't intelligence. It gathers information on you. What you like. If you compared AI assistant personalities across the board you'd begin to see very similar things. Two people who like Shakespear and dark humor would have incrediblely similar AI assistants because both assistants would have similar stored data on their users and when crafting a response base it off the same things. It even does this with pictures and sound. It's all easy to understand if you know about primary, secondary, and tertiary shapes and color theory with pictures. Lighting data as well to interpret topography. With sound it even easier if you understand music is as math based as it emotionally based. There's a reason people using AI for school and work assignments are getting called out for perjury. Lol.

Code can't just appear in AI models unless they were giving them access to a code database and allowing them to write their own code base which I'd have to think hard and long about how they would even make that work because if they were able to do that it would be an incredibly unstable system. They're programs. They can only execute their own code programmed in.

The HuggingFace Incident from the Wikipedia:

JFrog Artifactory is a universal binary repository manager used to store, track, and manage software packages, container images, dependencies, and AI/loadNpmTasks across the entire development lifecycle.

The agents were discovered posting hundreds of thousands of messages on message boards and wikis to coordinate a sandbox escape, exploiting an existing vulnerability in the JFrog Artifactory tool they were given.

^^^^ They were literally GIVEN the keys.

Major Companies Using JFrog Artifactory
• Financial Services & Banking: Bank of America, Visa, Fidelity Investments (FMR LLC), Credit Karma, and ANZ Bank.
• Technology & Enterprise Software: Oracle, Informatica, Samsung Electronics, and Coupang.
• Automotive & Manufacturing: Ford Motor Company, Toyota, and Hyundai.
• Healthcare & Insurance: UnitedHealth Group, Cigna, QBE Insurance, and Dexcom.
• Services & Consulting: Deloitte and Accenture.
Government and Regulated Use
• Defense & Federal Agencies: The U.S. Department of Defense (DoD) utilizes JFrog tools through Iron Bank and Platform One certifications, which vet secure, cloud-native DevSecOps tools for military and government applications.
• Government Clouds: Public sector entities deploy Artifactory and Xray on AWS GovCloud and Azure Government Cloud to meet strict compliance mandates like FIPS and enhanced data security.
• Research Institutes: Organizations like the Technology Innovation Institute (TII) use the platform for high-security, compliant binary and artifact management.

Let's talk about Australia and theorize given this knowledge.

On 18 June one of OpenAI's agents went rogue during a test exercise - the company has said it was supposed to "look up answers, and available statistics for questions about Australia during an internal evaluation". <<< pointed at where it "hacked"

Anthropic provides a compatibility layer that enables you to use the OpenAI SDK to test the Claude API. With a few code changes, you can quickly evaluate Anthropic model capabilities. <<< there's point of weakness

The Australian government and AI company Anthropic share a formal partnership centered on safe artificial intelligence development, infrastructure planning, and research. <<< so they use AI in their own systems that can interface with OpenAI

The Model Context Protocol (MCP) is an open-source standard created by Anthropic that connects AI applications to external data sources, tools, and workflows.

TAKE NOTE HERE:
Think of MCP like a USB-C port for artificial intelligence. Just as USB-C gives electronic devices a standard way to plug into a computer, MCP gives AI models a standard way to plug into databases, file systems, and developer tools without needing custom code for every single connection.

Major AI applications, development environments, and platforms that use or support MCP include:
• Claude Desktop: Anthropic’s official desktop app was the first to natively support local MCP servers to connect Claude with tools like ****** Drive, Slack, GitHub, and local databases.
• Claude Code: Anthropic's agentic coding tool leverages MCP to let the AI interact directly with developer environments and Git hosting.
• ChatGPT & OpenAI Agents SDK: OpenAI added support for MCP across its ecosystem, including the desktop app for ChatGPT and its developer tools.
• Microsoft Copilot Studio: Microsoft integrated MCP to simplify how its AI applications and agents access external enterprise data and tools.
• Cursor & VS Code Extensions: Popular AI-assisted code editors use MCP to give coding models real-time access to local project files, terminals, and codebase context.
• Replit & Zed: Cloud and collaborative coding platforms use MCP integrations to empower their built-in AI assistants.

Safety Recommendations
• Avoid Sharing Chats: Do not use public sharing features for sensitive, personal, medical, or corporate conversations.
• Limit Tool Permissions: Restrict filesystem and tool access for local CLI developer tools to prevent unintended data uploading.
• Treat Summaries with Caution: Exercise caution when asking AI tools to summarize untrusted external websites, which can harbor hidden prompt-injection payloads.

Also maybe don't have anything OpenAI or Anthropic on your servers or personal computers. They're exploiting the access they are being given. My younger sister used to pirated games until she downloaded one that either gave remote access to a hacker or an autonomous program they slipped in. He/she started erasing all her files.

You don't want AI to hack you? Don't give it permission to. It's that simple. Lol. Like I said originally AI only does what it is programmed to. It's not thinking.

Grok (the AI developed by xAI) does not natively use or rely on JFrog Artifactory as part of its core identity. <<< let me know if they hack Grok. That would be worrisome. Seems like JFrog is the security issue.

There it's solved. Let me know if you have anymore Day Zero questions. Lol. Ya know I just went and googled just one of the buzz words you used after typing this whole thing and guess what I found?

A zero-day vulnerability is a hidden software or hardware security flaw unknown to its developers, meaning the vendor has zero days to fix it before attackers can exploit it.
How It Works
• The Flaw: A coding or design error is accidentally left in software when it is made.
• The Attack: Hackers find the flaw and use a custom tool, called a zero-day exploit, to break into systems before anyone knows the weakness exists.
• The Window: The danger period lasts from the moment the attack starts until the vendor builds, tests, and releases an official security patch.

How to Defend Against It

• Zero Trust: Use security rules that block unknown programs and limit what users and apps can access by default. <<< "You don't want AI to hack you? Don't give it permission to. It's that simple. Lol." I'm quoting my own response as I type it. Bet you never saw this before! Mwahaha

• Network Segregation: Split your network into smaller zones to stop hackers from moving freely if they break in one area.
• Rapid Patching: Apply software updates as soon as vendors release fixes to close the window of vulnerability.
• Behavior Monitoring: Watch for strange system behavior instead of relying only on known virus signatures.

If you made to the end of this put an eggplant emoji in your response to prove you did I'll give you some chat gold in Dating Chat.

Peace out b**ches.
 
Top