logoalt Hacker News

davrosthedalekyesterday at 12:21 PM2 repliesview on HN

Well, I think it's fair to assume that a) They didn't upload everything before they realized it would work. b) They want to mention this as an advantage for future analyses c) Even if you assume that the attack exfiltrated everything until proved otherwise, you shouldn't just disseminate all the private information, because maybe the attack didn't.


Replies

horsawlarwayyesterday at 1:18 PM

They specifically call out credentials used during the attack.

But they should be rotating those regardless. You don't get to say "Maybe the attacker didn't get this credential". You just rotate.

The most generous interpretation is that they have not yet have completed that rotation, and they didn't want to risk putting those credentials into the wild during that process.

---

But all of that aside, I feel like the undercurrent of this comment is that the "safety" rules that providers are pushing are genuinely harmful.

Another point where "if you don't own the model, you can't properly operate the tool" becomes true. Open isn't about profits, it's about capabilities.

atconyesterday at 4:02 PM

Against an "agentic attack" and compromised credentials, one should be paranoid about latent vulnerabilities [1]

[1] eg "Robin Hood and Friar Tuck", poisoned compiler, etc. https://news.ycombinator.com/item?id=26553390