Comment by gpt5
3 hours ago
I don’t get the sentiment of classifying it as a felony.
OpenAI’s model found security breaches in HugginFace’s system (it wasn’t even OpenAI running it, as it was a 3rd party evaluation company that didn’t secure it well).
OpenAI collaborated with HuggingFace to resolve the issues when they found out about it, and publicly disclosed everything to raise awareness. This is how things should work. These models are very powerful and fully controllable. The community here at the same time cheers for fully releasing the open weight models without any hacking limits and at the same time criticizes a proper response.
Kinda shows how we have moved as a community into moralization and vibes instead of nuance and productive discussion.
Luckily, that isn't how the law works. Or is supposed to work, anyway. You cannot, for example, sell yourself as a slave to somebody else, because slavery is illegal - even if you opt into it.
So whether something is a felony isn't decided by the victim, but the rules of law, and that means breaching a security system without authorization is illegal, no matter what you think.
To put it another way, crimes are usually [0] only something the government can/must prosecute, victims don't get to choose. The media-popularized phrase "would you like to press charges" isn't asking for your permission, it's asking if you're willing you be helpful.
So HuggingFace's corporate opinion here shouldn't (normatively) matter very much.
[0] "Private right of action" with a civil trial comes close.
That actually is how the law works. You can read the Computer Fraud and Abuse Act at https://www.law.cornell.edu/uscode/text/18/1030 and double check, but these felonies all require knowingly or intentionally accessing a computer etc. These aren't strict liability statutes - the government must prove mens rea to a jury in order to get a conviction at trial.
I could show up at your doorstep, declare myself at your service, and then spend the rest of my days catering to your every beck and whim. There's no law against that. Can it even be slavery if it's voluntary?
That's not slavery, because you only declare yourself at my service, but you never sign a contract giving your rights away in exchange for something. That's the part you cannot do, regardless of whether it's voluntary.
1 reply →
Because if this was an anonymous software company who had an employee who decided to hack HuggingFace, they wouldn’t be talking about it gleefully - they’d be in court.
we will wait to have the nuanced and productive discussion when openai's model decides it needs to raise more capital by emptying your bank account.
Because it likely is, despite both their levity and the general lack of nuance in the CFAA. Quoted from 18 U.S.C. § 1030 (the CFAA) [1] (without quote blocks, because mobile):
--- Start Quote
(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—
--- End Quote
OpenAI's nonchalance is forced. If they are found to be even partially responsible for the CFAA violation then they have an _enormous_ problem. They _need_ for whoever prompted the LLM to be responsible, because the alternative is having to have an efficacious process for identifying hacking attempts. They don't have that (and no one does).
> The community here at the same time cheers for fully releasing the open weight models without any hacking limits and at the same time criticizes a proper response.
No, at least I personally criticize because closed weight models incur a rent. I can only make sure their model can't find vulnerabilities in my software if I pay them to check. I can pay basically whoever to do the same thing on open weight models.
It creates a fundamental conflict of interest. OpenAI/Anthropic/al _should_ stop bad actors, but it fuels their sales if there are X bad actors and as a result X*10 (or 100, or 1,000) good actors have to burn tokens checking if those bad actors will actually find a vulnerability. You can see their line-toeing where they talk about how safe it is, but also how dangerous it is to have code you _aren't_ auditing with their LLM.
As a result, I do not trust them because their goals are not aligned with mine. The open weights might not filter out hackers, but I'm also free to check the results on my own hardware, or OpenRouters', or whoever else. The line between "my LLM can find vulnerabilities" and "you have to pay me" is a lot more blurry. It's a lot easier to claim an LLM can find vulnerabilities than it is to be the cheapest inference provider. Anyone can bullshit on Twitter about how scary a vulnerability is (see CVE scoring), a lot fewer people can build the most cost-efficient inference in the world. They would rather be buzz-worthy than competent or open.
I find their position morally abhorrent. It's a mob-style shakedown. "Pay us to check your software or we're not responsible for what happens" is nothing short of a shake down. They need to either fix their systems for detecting hacks or offer some way to immunize against the hacks their software would propose, otherwise they're just as culpable as anyone selling a 0-day.
[1]: https://www.law.cornell.edu/uscode/text/18/1030
Intent to access a computer would have to be proven for that section of the CFAA to be relevant. The shakedown would be covered under subsection 7, governing communicating threats of computer damage or unauthorized access with the intent to extort.
Really? Dudes are catching felony raps for web scraping and you dont see how any of this is felonious?
That others have been treated unfairly doesn't make this instance also one that should be overreacted to.
True. Where we appear to disagree is that any overreaction has taken place. If anything I'm deeply dissatisfied that charges haven't been filed.
Who got charged with a felony for scraping?
Aaron Swartz, for one.