10 ms·
OpenAI was hacked year-old breach wasn't reported to the public
- tux3 2y agoAs someome who hoped that OpenAI would be consistently candid, this certainly comes as a disappointment. If the internal culture is to keep problems under wraps to maintain appearances, this seems like it might backfire at some point.
- TaylorAlexander 2y agoDo not waste your energy thinking that companies like this will be “consistently candid”. That’s not what they’re here for, and it’s clear from other events in their history that they have no interest in this.
- ilrwbwrkhv 2y agoYa I hope people are not putting any sensitive information when using Chat GPT. Anything that can get stolen will get stolen. Just a matter of when not if. On device LLMs with no network transmissions are the only way to keep things safe if you really care.
- righthand 2y ago> Ya I hope people are not putting any sensitive information when using Chat GPT. The ship has sailed, OpenAI wants you to put everything in their system. It makes them more valuable. They know there is no repercussions because their base will blindly advocate for them regardless under the guise of “the best llm”.
- cqqxo4zV46cp 2y agoPost headline has been editorialised yet still terrible clickbait. > OpenAI’s internal messaging systems early last year, stealing details of how OpenAI's technologies work from employees. Although the hacker did not access the systems housing key AI technologies, […] Enough said. It’s completely normal to not disclose a breach if there’s no proof or great likelihood that customers were implicated. A poorly written article regurgitating the NYT story with uninformed alarmist shitty podcast tier ‘analysis’. Jog on.
- skywhopper 2y agoSounds like they got access to email and Slack; that’s the gateway to a lot of other things. Fact is, OpenAI was booming at the time of this hack and they had every incentive to play down the severity internally. The hackers may not have gotten access to the “systems housing key technologies”, ie no SSH access to the production VMs (although I’m not sure I would trust that OpenAI’s auditing of such access was foolproof) but that doesn’t mean they couldn’t have done a lot of other damage, gathered all sorts of source code and secrets, or put a backdoor in somewhere. All in all, given the claims they are making and the level of trust they demand from their customers, they ought to have been far more open at the time.
- doe_eyes 2y ago> It’s completely normal to not disclose a breach if there’s no proof or great likelihood that customers were implicated. A bit more complicated than that for public companies. But OpenAI is private, so yeah, they most likely don't have to. It's still an interesting scoop for a journalist, though.
- CamperBob2 2y agoIt's hard enough to report issues to OpenAI. Not surprising that information coming out of the company is equally constrained. Right now my ChatGPT4 history is full of chats I didn't create, on subjects ranging from corporate governance to Roblox scripting to somebody's math homework. It will be only a matter of time before this bug causes them to leak sensitive personal data. I spent 10 minutes looking for a way to report it, but they have successfully insulated themselves from any contact with their (paying) customers. Pretty annoying, and not something you expect from a supposedly security-savvy company... although that expectation is certainly changing.
- righthand 2y agoSerious question: What gave you the impression the company is security savvy?
- moralestapia 2y agoNot OP but probably all their marketing bs about AI safety and how they're saving the world by not destroying it (th-thanks ...). They can't even do basic auth properly so ...
- righthand 2y agoI guessed that but also AI safety doesn’t seem like a security promise to me so I thought I’d clarify.
- gunapologist99 2y agoIt's good to see that we are safely protected from the other side of the political aisle.
- talldayo 2y agoWith business partners like these, who needs competitors?
- 2y ago
- uyzstvqs 2y ago> OpenAI's systems, where the company keeps its training data, algorithms, results, and customer data, were not compromised Article just rambles about some unnamed uninformed AI-phobes being concerned about US national security in relation to China because of some unknown OpenAI internal information that might have leaked.
- deleted 2y ago[deleted]
- ChrisArchitect 2y ago[dupe] Actual article: https://www.nytimes.com/2024/07/04/technology/openai-hack.html?unlocked_article_code=1.400.VSwD.N-Tzx1ND4rRB&smid=url-share https://www.nytimes.com/2024/07/04/technology/openai-hack.ht... More discussion: https://news.ycombinator.com/item?id=40887619 https://news.ycombinator.com/item?id=40887619
- bastard_op 2y agoI've worked with/for a lot of org over the past few decades, and personal experience proves there are a _lot_ of incidents that go unreported. The usual is that if there's no logs saying something bad actually happened, there's certainly nothing to say that it did, even though some terribly guessable credentials were used for ages on something publicly exposed. I know, they know, but told in no uncertain terms to drop it. Nothing to see here, move along. Work to be done, money to be made.
- deleted 2y ago[deleted]