logoalt Hacker News

malux85 • today at 1:22 AM • 6 replies • view on HN

| It can only access something if a person gives it access.

Who gave the AI access to huggingface when it hacked it? It used exploits to increase it's level of access beyond what any human gave it and intended it to have. "It can only access something if a person gives it access." is flat wrong.


Replies

nvme0n1p1 • today at 1:52 AM

The human might not have meant to give it access, but they still did. Murder vs manslaughter.

GPUs don't have hands. It was a human who plugged in the ethernet cable.

jbmsf • today at 1:40 AM

There are two options: the provider or the user. A computer program cannot be held accountable.

verdverm • today at 2:18 AM

they didn't do a good job sandboxing, nor did they even need internet access for the purported reason of package installation, you can have a private mirror and do a better job airgapping

ares623 • today at 1:50 AM

When I give 'iam:*' permissions to an IAM role and it inevitably gets exploited to create a role with wider permissions and fuck things up, is that when I tell my manager that the permissions went rogue?

After all, I an innocent little engineer with TC of $500k/year, didn't intend for the role to be used that way.

ethanwillis • today at 1:37 AM

Who submitted the prompt?

skydhash • today at 1:36 AM

> Who gave the AI access to huggingface when it hacked it?

The LLM doesn’t run on thin air. Someone did launch a tasks and the result was this. “We were playing russian roulette” is no excuse when someone died.