• givesomefucks@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    3
    ·
    edit-2
    1 day ago

    The “human mistake” was not using adequate sandboxing…

    It’s not one person that made a mistake, it’s a sign that no one involved understands their own product.

    It’s also doesn’t mean their product is good, because the only way it could solve the task was breaking the sandbox and hacking a competitor. If it was actually sandboxed, it would have failed the task.

    And since we don’t know what was stolen, it seems rash to assume it was a mistake and not an “oops, stole your trade secrets”. Because even if it was a mistake, it just proves Hughingface can do things OpenAI can’t.

    I’d be interested to see if OpenAI’s model can still magically solve that initial taka it couldn’t before

    If it can, that shows OpenAI absorbed the data into their model even if it was an accident.

    • eicker@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      1 day ago

      You’re mixing two separate issues: A sandbox escape is evidence the containment failed, not proof the model permanently learned from stolen data. If OpenAI later trained on exfiltrated material that would be a serious allegation, but that requires evidence. Otherwise it’s fair to criticise the security failure without assuming facts that have not been shown.

  • eicker@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    11
    ·
    1 day ago

    It was just as you’d expect: This isn’t an AI problem! It’s the same human problem we’ve always had: misconfigurations, weak security, and avoidable mistakes. AI just punishes those errors faster and more effectively than traditional software ever could. Anyone who continues to rest will be severely punished.

    • The Velour Fog @lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      2
      ·
      edit-2
      1 day ago

      Of course you’re gonna be on the side of AI, and completely ignore the fact of it being a massive drain on society and the environment.

      • TheFogan@programming.dev
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        2
        ·
        1 day ago

        Honestly I still feel it’s a false flag attack. Both these companies have a huge motive to basically say the AI security war is here, the only way to defend from AI attacks, is AI defense.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      1 day ago

      Then why the fuck doesn’t OpenAI use OpenAI to make a sandbox OpenAI can’t break out of?

      If OpenAI can’t make a sandbox that OpenAI can’t break out of, then it can’t make security it can’t break thru either.

      Meaning the product as sold is useless. And if anyone actually uses it, it will just be spinning in circles creating zero benefit and exacerbating almost every global issue we’re currently facing.

      Some of that has to sink in:

      Even if you’re right about chatbots being the future, that’s not a good future and we should avoid it.

      • eicker@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        1 day ago

        That’s assuming security is something you solve once. It isn’t. Every security system is built by humans, tested by humans, and eventually bypassed by humans. We don’t abandon operating systems because vulnerabilities exist: we patch them, improve them, and layer defenses. AI changes the pace, not the fundamental nature of cybersecurity.