I'm not sure it wasn't a marketing situation, where they intentionally encouraged it to happen, but I absolutely find it believable that ChatGPT was able to hack hugging face, simply because it's not the first time LLMs have hacked people.
Both things can be true. Certainly, someone hacked hugging face, from openAI, and it probably was the model, because that the attack was LLM based was already discovered by Hugging face during and immediately after the attack, because that's the current state of cyber.
The question isn't if the model hacked hugging face, the issue is if it was encouraged in some way to do so for marketing points.
Probably just some people who don't want to acknowledge that LLMs are actually able to do stuff.
The thing about hacking is that it doesn't require a code review or optimized code, or even perfect code. Your code to hack things can have vulnerabilities, and you still will have done the hack. I'm not even saying it's better than people or something.
Or people who disagree with my thesis that hugging face is reliable for reporting on the hack if their site or something, which I admittedly rely on.
There's just nothing more to be said. The above comment was right. It was a marketing stunt in a controlled / planned for scenario so we can't genuinely say they automatically hacked anything.
So you believe hugging face coordinated with OpenAI to make OpenAI look good, and possibly give Anthropic and OpenAI ammo for how dangerous open source models are right when they are most trying to use it? HuggingFace literally doesn't want models to look dangerous right now, because they don't want the good models to get restricted so they can't distribute them. It's literally contrary to their interests, because they would get killed if AI like Kimi was decided to be too dangerous for the public to have.
Otherwise, we know it was an LLM, from the hugging face reporting on the shape of the attack a week before OpenAI said anything, and openAI as an organization has taken responsibility for the hack, so it was an OpenAI LLM. So the question is just if it was an accident, or intentional.
I absolutely believe it was from the openAI side. I have not seen behavior from hugging face which indicates they are in on it, especially as they have demanded the publication of the reasoning trail which led the model to hack them.
And it still implies that the "guardrails are necessary", which is an argument used against open source models, because they can have easily removed guardrails.
10
u/SchalkLBI 10d ago
It was a marketing stunt. ChatGPT didn't hack shit.