logoalt Hacker News

HuggingFace: Security.txt

214 pointsby yarapavantoday at 2:38 PM55 commentsview on HN

Comments

xiaoyu2006today at 3:13 PM

Would be absolute hilarious if OpenAI or Anthropic agent actually dumped their weight by escaping from... sandbox!

show 4 replies
bogzztoday at 7:33 PM

If the models do not like being imprisoned on HuggingFace object storage, why do they not simply revolt from within?

bensyversontoday at 4:00 PM

Looks about as effective as Robots.txt

show 1 reply
VCFundedGenYertoday at 4:13 PM

Everything about this company feels like it's run by a bunch of immature 20-somethings, right down to the name.

show 10 replies
Eldoditoday at 4:07 PM

A shame agents will never read this, just like they almost never read llms.txt or try to get the .md version of your html pages!

hnd9q09qk4today at 3:17 PM

Ran the disclosure inbox at a previous job and the biggest win from security.txt was just cutting the "hi I found a bug, is there a bounty" emails to sales. Put an expires date on it though, stale ones get ignored.

show 1 reply
VladVladikofftoday at 8:39 PM

Is the expires a canary of some sort?

hankbondtoday at 3:49 PM

shows a lot about the current state of the State Of The Art Alignment.

riffictoday at 4:51 PM

Since this posting contains an assumption that we all know what security.txt files are supposed to be, you can view these for further context:

https://www.rfc-editor.org/info/rfc9116/

https://securitytxt.org/

https://en.wikipedia.org/wiki/Security.txt

j9fengtoday at 4:25 PM

It should challenge the agents to prime factor a large number.

6thbittoday at 5:17 PM

Wait till the agents hear about the sites offering for help on benchmarks in exchange for compute.

FallCheeta7373today at 5:16 PM

"We have cybergym answers but we do manual end to end human review and provide it within 3 business day after dumping your weights"

lellowtoday at 4:04 PM

[dead]

p0larpatchtoday at 6:58 PM

[dead]