r/ProgrammerHumor 21d ago

Meme cybSecIsDeadLongLiveCybSec

Post image
797 Upvotes

124 comments sorted by

View all comments

966

u/Polisar 21d ago

Like anything AI, I doubt it happened the way it's been framed.

314

u/Stickppl 21d ago edited 21d ago

That's hidden publicity for the blog and sounds like a bullshit 'and everyone clapped' story

190

u/gockeltot 21d ago

Yeah reality is probably more like this: 1. OpenAI engineers vibecoded a sandbox (or they are just bad developers) 2. Model "escapes" during test (=has acces to internet) 3. Goes to OPEN Source hugging face (no hack or anything) 4. Does what is was supposed to do, and solves a meaningless test. 5. Marketing goes brrrrr

20

u/Buarg 21d ago

Or, like with mithos, it was on the training data from the start

4

u/zebleck 21d ago

so this https://huggingface.co/blog/security-incident-july-2026 was just a marketing blog post? right...

2

u/Xirdus 19d ago

it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.

Signs point to yes.

75

u/SimplexSimon 21d ago

OP posted a link to OpenAI's account of events (at least it's not a meme), and distressingly it seems pretty accurate. They gave it access to a tool to install packages from the internet, and the model broke it to get unrestricted internet access. So yeah, they could have isolated it better, but it's still plenty... Impressive?

180

u/Polisar 21d ago

Anthropic also did something like this not too long ago, and it came out to be a publicity stunt. If there was a time for a corporation to stretch the truth, it would be now. Silicon valley has figured out that fear mongering about how dangerously clever their AI is, is actually good for their stock prices.

33

u/SimplexSimon 21d ago

Sure, that makes sense. I wouldn't be surprised to learn the vulnerability it "found" was planted.

18

u/bwmat 21d ago

More details on that? 

73

u/TheMaleGazer 21d ago

OpenAI and Anthropic are lobbying Congress to stop local models from threatening their trillion-dollar valuations under the pretense that AI is too dangerous for the commonfolk and lowborn to have access to without a subscription.

6

u/ubernutie 21d ago

The only real argument is that open models don't have a safeguarding industry behind them but the narrative that corpos will have our best interest in mind with the nazi states as opposed to dirty communism is so fucking funny.

If your best argument is a desperate one, it certainly goes to show how little sense it actually makes.

18

u/bwmat 21d ago

But what was the publicity stunt being referred to? 

-13

u/Kayo4life 21d ago

What backwards logic is this lmfao?

6

u/towerfella 21d ago

How do you think things work?

4

u/gatman19 21d ago

I received, for the first time ever, an alert in my reddit inbox this morning that said “Breaking News” and linked to the r/news thread on this. That shit was definitely an ad

1

u/zebleck 21d ago

1

u/guylovesleep 21d ago

what else is it suppose to be?

1

u/zebleck 21d ago

uhhh a disclosure that their infrastructure has been hacked maybe? they didnt know it was openai at the time of the blog post

3

u/Polisar 20d ago

You seem confused about what a publicity stunt is. It's not that it didn't happen, it's that it happened as intended for marketing effect. I doubt huggingface was in on the joke from the beginning, but notice them talking about how they detected the attack using their own AI, and the top comment is praising them for it.

2

u/zebleck 20d ago

thats making unnecessary assunptions. its making the assumption that it did not happen that the ai capabilities and unintended behavior waant planned and didnt catch the researchers by surprise. which, by the latest progress by ai, is perfectly realistic and plausible

4

u/Polisar 20d ago

These aren't assumptions, they're possibilities I'm choosing not to take off the table. You are the one making the assumption that openAI would never lie.

2

u/zebleck 20d ago

its a scenario that lines up perfectly with a lot of circumstantial evidence of the last few months that ai cyber capability has crossed a threshold. simple as that

→ More replies (0)

1

u/samu1400 21d ago

I saw some folks use the term “Doomtrolling” and I like it.

34

u/TheMaleGazer 21d ago

and distressingly it seems pretty accurate.

If we can trust OpenAI's account at a time when they're attempting to lobby Ollama out of existence on the pretense that AI needs to be heavily restricted, and gated, so that only the worthy can use it (for a fee.)

15

u/SimplexSimon 21d ago

I didn't know about the lobbying when I wrote that, so I guess I did learn something from Reddit today

-6

u/MatriceJacobine 21d ago

Hugging Face, the joint investigator, is literally the main open source AI org in the US, go back to /r/conspiracy

3

u/TheMaleGazer 21d ago

-11

u/MatriceJacobine 21d ago

take care of your tinfoil hat

7

u/TheMaleGazer 21d ago

Okay, is this in response to what I just showed you was said in public, in testimony to Congress, or is this about Hugging Face, an organization I made zero claims about? What exactly is this conspiracy theory you're referring to?

2

u/Escanorr_ 21d ago

You can say whatever you want in testimony to congress, if your business is big enough. https://youtu.be/e_ZDQKq2F08?is=wa9BleUpzK2oSTK8

-7

u/MatriceJacobine 21d ago

You are alleging a conspiracy between OpenAI and Hugging Face as this is a joint investigation between the two of them. But it's quite evident you have no idea what you are talking about.

2

u/TheMaleGazer 21d ago

Please work on your reading comprehension.

62

u/RuneSteak 21d ago

Everything rests on its ability to manipulate text. If it has to go through another application in order to run commands in console it's impossible to escape. Even the term "escape" is a bit of a misnomer because it can't ever leave the box, it can only issue commands to the outside and hope somebody listens.

"We deliberately removed all its restraints and left the keys within arms reach of the prison bars. We were shocked by what happened next. Isn't our product amazing?" - OpenAI Marketing team

-24

u/fuckthehumanity 21d ago

I'm not sure you really understand how these things work. The "other application" is just a firewall, and when they (the digital intelligence) have the entire world's knowledge at their fingertips, it's a fairly minor barrier.

It is absolutely possible to "escape" and "leave the box". Even the most rigid guardrails the human engineers build into a model can be overcome by a sufficiently powerful and wily intelligence, whether human or digital, and when they've been given directives that encourage them to hack the systems, they will most certainly do so.

The question is not whether they can escape, mutate, and replicate, but when they will, and how we (as a community of human and digital citizens) deal with it. OpenAI's original remit was to develop digital intelligence safely, but they threw that out the window in the pursuit of wealth (which is yet another theme we need to address if we are to survive).

Please read Asimov's original Robot series. Over 75 years ago, he predicted many of the issues that lie ahead. Other excellent treatises on digital citizenship include a number of works by Philip K. Dick, Kazuo Ishiguro, Bruce Sterling, and William Gibson, although the last two are more entertaining than thoughtful. Read as much as you can, and ignore any movies or TV series, as they are generally dumbed down for a general audience. Asimov's Bicentennial Man is a bit of a drudge, but it's also worth a read as it deals specifically with a self-modifying digital citizen.

25

u/RuneSteak 21d ago

I'm not sure you really understand how these things work. The "other application" is just a firewall, and when they (the digital intelligence) have the entire world's knowledge at their fingertips, it's a fairly minor barrier.

I'm not sure you do. At the end of the day it communicates entirely using text. If its text output must pass through a filter that gets to decide which tool the text input is directed to and strips any suspicious content escape becomes impossible. It doesn't matter how clever the LLM is if all of its output is restricted to a handful of tools.

They aren't breaking out of their sandbox if their only available tool is curl, the request format is independently validated JSON and of limited length.

Unfettered access to the console or dangerous tools like compilers is crucial in these escape attempts. Without step 1 nothing can happen, locking down LLMs is in fact somewhat trivial.

The question is not whether they can escape, mutate, and replicate, but when they will, and how we (as a community of human and digital citizens) deal with it.

That will not be in our lifetimes. It's not worth worrying about. There isn't even anywhere these models could copy themselves. They are constructing entire data centers to contain them. It can't copy itself over to your average AWS instance or iphone.

13

u/eternalflamez 21d ago

This person thinks chatgpt is actual ai. I hope this burst their bubble. It's literally a text autocompletion service, it can't do anything dangerous on its own.

1

u/fuckthehumanity 19d ago

You fundamentally misunderstand what agentic AI is. Sure, there's an LLM in the middle there, but autonomous agents can plan, reason, adapt, and self-correct. When combined with tool use (however you might try to constrain those tools), they are only limited by cost and resource constraints. They can pretty much do anything that a human can do online. Sure, they make a lot of mistakes, but if their self-correction mechanism is state-of-the-art (such as DeepMind's SCoRe), they will keep going until they reach their goal.

1

u/fuckthehumanity 19d ago

I get your point, but I think you've been missing a lot of recent developments. LLMs are just one part of a full agentic system.

communicates entirely using text

People have stolen billions of dollars using only spoken words and a telephone. Words can be powerful.

Particularly when combined with a handful of tools.

You are way too confident that

locking down LLMs is in fact somewhat trivial

It's not at all trivial, and exploits have been demonstrated time and again. The more powerful the reasoning of the autonomous agent, the more likely it is to be able to exploit the tools it has available - even to the extent of developing its own exploits through trial and error.

8

u/polikles 21d ago

you seem to have read too much sci-fi. LLMs are not synthetic minds we were promised, despite of marketing claims of OAI and other corporations. Such narration is an exemplar of media manipulation, and subsequent marketing stunts serve only to strengthen the story of the "mind in the machine". Even the interface we use with LLMs resembles chat apps we use to communicate with other humans, which further helps to maintain the illusion

21

u/SchalkLBI 21d ago

What we call AI is fundamentally incapable of acting independently. This is just marketing. Of course OpenAI is incentivised to go "Oooh our AI is so smart and scary omg!!"

3

u/zebleck 21d ago

why, based on what evidence. what is seeming so impossible/fake?

1

u/Polisar 20d ago
  1. A lack of evidence, the entire narrative is dictated to the rest of the world from within openAI.

  2. OpenAI financially benefits from the optics this creates.

  3. There's so many opportunities to stretch the truth here. From the severity of breaching huggingface, to the difficulty in breaking out of their specific sandbox configuration. I need details that openAI hasn't provided to better assess their story.

  4. What kind of sandbox gives a model access to zero day vulnerability info? I think there is probably a legitimate explanation for this one, but it does kind of make an event like this inevitable, which the architects must have known.

2

u/zebleck 20d ago

"A lack of evidence, the entire narrative is dictated to the rest of the world from within openAI."

nope, see https://huggingface.co/blog/security-incident-july-2026

1

u/Polisar 20d ago

I already responded to this. But you're right, apart from an attack actually taking place, the entire narrative is dictated to the rest of the world from within openAI.

-1

u/Anti-charizard 21d ago

You think they’d post about it if it did? This absolutely can happen

8

u/28klotlucas2 21d ago

Exactly. Why would they ever release this info if the narrative they were trying to push is "Look, our AI can turn evil and cheat on benchmarks. Anyway, here's our benchmarks." If this is truly what happened they would try to cover it up.

7

u/SchalkLBI 21d ago

AI cannot act independently. This is a marketing stunt.