logoalt Hacker News

Animatstoday at 3:20 AM2 repliesview on HN

Does "To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy" just mean somebody had an open redirect? Those are still common.[1]

[1] https://sitetruth.com/reports/phishes.html


Replies

kibibutoday at 11:32 AM

> the models identified and exploited a zero-day vulnerability

This use of language is very hard to reconcile with the "AI is just a tool" rhetoric that many use.

Did the models do this, or did humans at OpenAI do this using the models?

simonwtoday at 3:31 AM

I expect it must have been more than just an open redirect if it let the models then go on to execute a bunch of vulnerabilities against Hugging Face.

show 3 replies