Elektrine lite

← Feed

@quinn@social.circl.lu

Post #4246262

2026-07-30 16:06 UTC

The whole Hugging Face/Openai thing just reeks of scam. It's a publicity stunt, it helps keep them in the media, trying to scare people into being wowed by their horrible next word picker. folks are assuming that it must of happened... because they said so? If it happened, it would be fucking CFAA felony. And there's no way to know if it's totally cleaned up on HF's side, *that's not how compromises of infrastructure work*

Replies (3)

  • @quinn@social.circl.lu 2026-07-30 16:08

    Fixing that takes weeks and real money and is stressful as hell. Is anything still in your infra? You don't know until you've looked. It's shit, it's horrible, there's a reason it's a fucking crime. ...unless, of course, you just planned the whole thing out in advance for the lols with another company God this timeline is stupid.

    Open ##4251472

  • @womble@infosec.exchange 2026-07-30 22:10

    @quinn@social.circl.lu it's possible that this is a publicity stunt, but it's a high risk, lowish reward one. It requires a lot of people to stay very quiet, including some people who won't necessarily have a reason to stay loyal in the next year or two (when they get laid off). With openai making a run at an IPO, making up a story like this is a risky move. If it did happen, it certainly *should* be a felony, but I'm at least partially persuaded that it isn't a CFAA violation because there was seemingly no intent on the part of a human to violate the law, and the CFAA requires the prosecution to prove intent. It's entirely plausible that openai's lawyers took a careful look and decided that, at the most, some low-level mook *might* end up carrying the can, not the company, but most likely it's not criminal. So sure, let's milk it for all it's worth. Now, was there gross negligence? Absolutely, but "I am a complete moron" isn't CFAA territory, it's (mostly) a civil matter, and no doubt hugging face and openai stitched up a quiet deal before openai admitted any kind of culpability. On the "intent" front, it's tempting to say that the model formed the intent, but allowing that precedent opens a huge can of worms for everyone. How do you punish the spicy autocomplete? The mental image of a data centre in a giant prison cell is amusing, but unlikely, and doesn't solve the problem that humans are being reckless. I'm not arguing, by the way, that this shouldn't be a crime, because hoo boy it absolutely should be. There's even precedent for holding humans accountable for the actions of a non-human entity (dangerous dogs, for example). It's just that the arguments I've seen thus far are more persuasive that this event, if it happened, was not, in fact, covered by any existing law.

    Open ##4255446

  • @quinn@social.circl.lu MLs perform trained patterns in pursuit of a defined objective. The "emergent capability" thing is a fucking lie. Anything it does is something it was trained to do, whether they sterilized their training data enough to know it or not. Anything it does is in pursuit of an objective they define, whether they know what they're defining for it or not. The problem with fuzzy inference engines is they *can't* truly know either, so the results get embellished and attributed to the model.

    Open ##4332662