6 ms·
I don’t get the sentiment of classifying it as a felony. OpenAI’s model found security breaches in HugginFace’s system (it wasn’t even OpenAI running it, as it
by gpt5 26d ago
I don’t get the sentiment of classifying it as a felony.
OpenAI’s model found security breaches in HugginFace’s system (it wasn’t even OpenAI running it, as it was a 3rd party evaluation company that didn’t secure it well).
OpenAI collaborated with HuggingFace to resolve the issues when they found out about it, and publicly disclosed everything to raise awareness. This is how things should work. These models are very powerful and fully controllable. The community here at the same time cheers for fully releasing the open weight models without any hacking limits and at the same time criticizes a proper response.
Kinda shows how we have moved as a community into moralization and vibes instead of nuance and productive discussion.
- everforward 26d agoBecause it likely is, despite both their levity and the general lack of nuance in the CFAA. Quoted from 18 U.S.C. § 1030 (the CFAA) [1] (without quote blocks, because mobile): --- Start Quote (2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— (A) information contained in a financial record of a financial institution, or of a card issuer as defined in section 1602 (n) [1] of title 15, or contained in a file of a consumer reporting agency on a consumer, as such terms are defined in the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.); (B) information from any department or agency of the United States; or (C) information from any protected computer; --- End Quote OpenAI's nonchalance is forced. If they are found to be even partially responsible for the CFAA violation then they have an _enormous_ problem. They _need_ for whoever prompted the LLM to be responsible, because the alternative is having to have an efficacious process for identifying hacking attempts. They don't have that (and no one does). > The community here at the same time cheers for fully releasing the open weight models without any hacking limits and at the same time criticizes a proper response. No, at least I personally criticize because closed weight models incur a rent. I can only make sure their model can't find vulnerabilities in my software if I pay them to check. I can pay basically whoever to do the same thing on open weight models. It creates a fundamental conflict of interest. OpenAI/Anthropic/al _should_ stop bad actors, but it fuels their sales if there are X bad actors and as a result X*10 (or 100, or 1,000) good actors have to burn tokens checking if those bad actors will actually find a vulnerability. You can see their line-toeing where they talk about how safe it is, but also how dangerous it is to have code you _aren't_ auditing with their LLM. As a result, I do not trust them because their goals are not aligned with mine. The open weights might not filter out hackers, but I'm also free to check the results on my own hardware, or OpenRouters', or whoever else. The line between "my LLM can find vulnerabilities" and "you have to pay me" is a lot more blurry. It's a lot easier to claim an LLM can find vulnerabilities than it is to be the cheapest inference provider. Anyone can bullshit on Twitter about how scary a vulnerability is (see CVE scoring), a lot fewer people can build the most cost-efficient inference in the world. They would rather be buzz-worthy than competent or open. I find their position morally abhorrent. It's a mob-style shakedown. "Pay us to check your software or we're not responsible for what happens" is nothing short of a shake down. They need to either fix their systems for detecting hacks or offer some way to immunize against the hacks their software would propose, otherwise they're just as culpable as anyone selling a 0-day. [1]: https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030
- ThrustVectoring 26d agoIntent to access a computer would have to be proven for that section of the CFAA to be relevant. The shakedown would be covered under subsection 7, governing communicating threats of computer damage or unauthorized access with the intent to extort.
- forgetfreeman 26d agoReally? Dudes are catching felony raps for web scraping and you dont see how any of this is felonious?
- rcxdude 26d agoThat others have been treated unfairly doesn't make this instance also one that should be overreacted to.
- forgetfreeman 26d agoTrue. Where we appear to disagree is that any overreaction has taken place. If anything I'm deeply dissatisfied that charges haven't been filed.
- rcxdude 25d agoWhile I think those calling for charges know not what precedent they are trying to set.
- forgetfreeman 25d agoOh I am very clear about what precedents I want set. I want the C-suite, board, and major shareholders of any corporate entity that meaningfully deviates from legality to face all of the same consequences a private individual would.
- lobf 26d agoWho got charged with a felony for scraping?
- jprd 26d agoAaron Swartz, for one.
- s1artibartfast 25d ago
- atomchild 26d agowe will wait to have the nuanced and productive discussion when openai's model decides it needs to raise more capital by emptying your bank account.
- 9dev 26d agoLuckily, that isn't how the law works. Or is supposed to work, anyway. You cannot, for example, sell yourself as a slave to somebody else, because slavery is illegal - even if you opt into it. So whether something is a felony isn't decided by the victim, but the rules of law, and that means breaching a security system without authorization is illegal, no matter what you think.
- Fricken 26d agoI could show up at your doorstep, declare myself at your service, and then spend the rest of my days catering to your every beck and whim. There's no law against that. Can it even be slavery if it's voluntary?
- 9dev 26d agoThat's not slavery, because you only declare yourself at my service, but you never sign a contract giving your rights away in exchange for something. That's the part you cannot do, regardless of whether it's voluntary.
- Terr_ 26d agoIANAL, but I think there are three aspects to this which should be teased-apart: 1. Contract terms that require committing a crime are void and unenforceable. 2. "A contract made me do it" is not a defense to a crime. 3. "The victim gave me permission" is not always a defense to a crime.
- Terr_ 26d agoTo put it another way, crimes are usually [0] only something the government can/must prosecute, victims don't get to choose. The media-popularized phrase "would you like to press charges" isn't asking for your permission, it's asking if you're willing you be helpful. So HuggingFace's corporate opinion here shouldn't (normatively) matter very much. [0] "Private right of action" with a civil trial comes close.
- ThrustVectoring 26d ago
- beaker52 26d agoBecause if this was an anonymous software company who had an employee who decided to hack HuggingFace, they wouldn’t be talking about it gleefully - they’d be in court.
- anon84873628 26d agoI can't find reference to a 3rd party hosting/running the tests - that seems to have been OpenAI's own internal research team. But they were using the ExploitGym benchmark.