Comment by pliny

2 hours ago

This is an AI written post and the details are wrong (the description of the HF incident as involving Irregular is wrong and the description of the incident as only involving stealing public credentials is wrong, per the technical report the agents got access to internal HF infrastructure).

I find it incredibly funny that the comment shown (to me) right above this one is:

> This is one of the most lucid pieces of writing capturing the current state of play I’ve read. Who is the author?

  • The same thing is happening with Laya, people didn't seem to click through to evaluate the supposed paper

    tyranny of confirmational headlines

Please see below, one detail was incorrect and has been acknowledged and amended.

  • Your description of the HF attack as being merely "the elite task of discovering 14 Hugging Face API tokens that careless developers had committed to public GitHub repositories" does not match the description in the technical report[1].

    [1] https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78... - page 9

    • The description reads "the elite task of discovering 14 Hugging Face API tokens that careless developers had committed to public GitHub repositories, and used them to try to get benchmark solutions from directly from Hugging Face by applying a template injection flaw that’s been known about since 2015[1]."

      Chaining a public token to an 11-year-old Jinja2 template injection vuln shouldn't be dressed up as an unprecedented "alien intellect" that threatens human civilisation. (And HuggingFace should take some flack for having such a dated vulnerability exposed - if your Bank was compromised in this way, you'd be blaming your bank, not the attacker.)

      One correction is fair though, the 14 tokens were in a public Hugging Face dataset not a public GitHub repository. I've updated the post to reflect that.

      [1] https://blackhat.com/docs/us-15/materials/us-15-Kettle-Serve...