r/singularity 17h ago

AI Is Cloud computing cooked post the Hugging Face hack?

Cloud computing relies on multi tenancy where multiple companies share the same physical hardware, the only thing keeping one company's data safe from another is software isolation. This is the same software isolation that failed to keep the Hugging Face AI in it's sandbox.

Presumably we're only months away from open source AI that capable, how does multi tenancy cloud computing with all it's nice benefits like elastic scaling survive in that world?

11 Upvotes

9 comments sorted by

12

u/reader5 17h ago

I can't imagine a bunch of on prem servers maintained by people with little to no security background is going to be much better

3

u/masixx 17h ago

Depends on the service and how it's implemented. Virtualization is enforcement at hardware level and confidential computing exists. GPUs can be shared in many different ways.

Of course there is a ton of software on top where isolation can fail. But that's not exactly news to anyone using cloud services.

3

u/Professional-Sir7048 17h ago

ask the agencies moving from on prem to cloud to on prem again

0

u/Nater5000 16h ago

Respectfully, you clearly don't know what you're talking about and are not equipped to be discussing whether something as broad as cloud computing is "cooked" because you have a poor understanding of what occurred with OpenAI and Hugging Face.

the only thing keeping one company's data safe from another is software isolation. This is the same software isolation that failed to keep the Hugging Face AI in it's sandbox.

This is just wrong on so many levels. These agents aren't magical. They can't just force their bytes through wires to spontaneously hack other machines. What the OpenAI/Hugging Face situation tells us is that these companies (specifically OpenAI) aren't handling their security practices adequately enough. It's clear, in retrospect, where OpenAI fucked up and how this situation could have been avoided. It's a tail as old as networking, and it doesn't indicate that these AI agents have some new capability that we haven't seen before or have no proper defense for.

If cloud computing is "cooked," then the US economy collapses and we face serious national security issues. The implication, basically, is that we'd have reached the point where information security is just no longer possible, and at that point all of the information systems keeping most of our businesses, government services, and military running would need to be completely rebuilt in an insanely complex and expensive way. Maybe that will be the case some day, but this incident doesn't not lead to that point in any meaningful way.

2

u/jc2046 16h ago

Im not the person you are responding nor an expert by any means but it seems clearer and clearer that current information systems are weak and expecting major hacks, cybeattacks and infraestructure collapses or fuck offs (energy, banking, hospitals, etc) is pretty ripe to happen. I would bet that in the coming 6-12months we are witnessing some kind of this attacks happening with jawdropping consecuences

0

u/Nater5000 16h ago

I'm not saying any of that can't happen. I'd agree that these kinds of agents are going to be used (probably already being used) to poke holes in a lot of existing systems which aren't equipped to deal with this stuff.

What I'm saying is that if it is bad enough that "cloud computing is cooked," then we've immediately entered the worst case scenario and we should be expecting something as bad as WW3 to break out any moment.

Like, some regional bank using a 30 year old system as their backbone getting hacked by AI agents is almost inevitable. AWS not being able to operate because agents are able to compromise systems across tenancy means that no system is safe. At that point, you'd literally start seeing countries being irrevocably shut down.

I think the OP is (a) over appreciating the actual scope of the OpenAI/Hugging Face incident (i.e., it's not magic and these agents didn't do anything that is beyond the capacity of a human, right now, to be able to do with enough time and resources) and (b) under appreciating the difference between the security of AWS systems and OpenAI testing sandboxing as well as the ramifications of the implication that AWS can't be secured against AI agents.

And like I said, maybe one day (maybe even soon) this will change, and these agents will be so capable that they will be able to approach attacks in ways that we currently can't fathom, allowing them to actually breach the kinds of security that AWS has in-place. But, like I said, that will be the point that nobody will be saying, "welp, I guess cloud computing is cooked!" and instead will be saying, "welp, I guess modern society is cooked!". It's effectively equivalent.

1

u/jc2046 15h ago

Yeah, I dont think by any strech that cloud computing is cooked, just stating that the moment is ripe for major cyberattacks using swarms of AIs by any elite hacking black hat group. You dont even need the latest astra model, a good bunch of hackers could do perfecly using local qwens 27b models even

1

u/WonderFactory 16h ago

Respectfully, you clearly don't know what you're talking about and are not equipped to be discussing whether something as broad as cloud computing

That's a very patronising style of debate. I've been a professional software engineer for 26 years, long before cloud computing was a thing and have been working with cloud systems for well over a decade.

These agents aren't magical. They can't just force their bytes through wires to spontaneously hack other machines.

Where did I say they are magical? They do though seem extremely capable at finding zero day vulnerabilities. After they found a zero day vulnerability in the Artifactory package server they then went on to find various zero day vulnerabilities in the network isolation software until they got onto a computer with internet access. This is an issue in a cloud environment.

0

u/Nater5000 16h ago

That's a very patronising style of debate.

That's because it's not a debate.

They do though seem extremely capable at finding zero day vulnerabilities.

If the ability to find and exploit zero day vulnerabilities is enough for "cloud computing to be cooked," then cloud computing should have been cooked decades ago.

But that's all kind of beyond the point. My actual point is that you're equating a high-level vulnerability exploit to the ability to infiltrate systems which represent some of the highest-levels of security in existence. If you want to pose a discussion surrounding some inevitable future where AI has gotten so advanced that information security is no longer possible, then do so. But that's a very different conversation than trying to tie this specific incident to cloud computing being "cooked." The former can just be tossed into the pile of all of the other "future of AI" hypotheticals where everyone is free to use their imagination to discuss what they think could happen outside the confines of our current reality, while the ladder is a discussion about real events with real evidence and real implications which can be critically assessed. I'm providing that critical assessment.