logoalt Hacker News

foo12bartoday at 5:04 AM5 repliesview on HN

From https://huggingface.co/blog/security-incident-july-2026 , this is frickin' hilarious:

> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.


Replies

gertrundetoday at 9:46 AM

> This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

Well, that may be correct for the second, local, analysis attempt... but seems funny to tout this as an advantage after already having tried the opposite...

show 2 replies
diabllicseagulltoday at 2:08 PM

so an on-premise and open-weight model was more useful than a commercial frontier model?

show 1 reply
chinathrowtoday at 7:59 AM

Turtles all the way down.

iugtmkbdfil834today at 5:28 AM

It is pretty funny, because there is something here for everyone. People who don't believe in guardrails have a clear indicator as to why operators should have access to models that don't try to question their Daves. On the other, people, who think that if only we could align the models just a tiny lil bit better, none of this would have happened to begin with. Pure madness.

show 8 replies
runtime_lenstoday at 8:57 AM

[dead]