返回
RCreddit.com
16
·15小时前·开发者社区 · RSS

The OpenAI "incident" feels suspect to me

查看原文
OpenAI

热度趋势

趋势数据积累中

百分比基于当前可用热度信号,而非评论数或独立用户人数。

Reading the OpenAI incident report: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf

How is it that there is no talk about reconnaissance? Where reconnaissance attempts usually get flagged by intrusion prevention software.

How is it that the agents knew what to go after?

It's always "agent used X" and nothing is said about "agent discovered X."

For example, they say that agents go straight to prod-hub-secs, to moon-bot-memory, to the Xet CAS service, to the specific Kubernetes CSI/RBAC config.

My suspicion is that, the OpenAI model was trained on data that contained infrastructure schematics of the victims, because possibly someone there used an OpenAI model to code infrastructure.

Therefore nobody else could of executed the attack on Hugging Face and the other orgs. Intrusion prevention would of caught them. Only OpenAI could because they had a map of the targets infrastructure and knew what to look for.

The OpenAI "incident" feels suspect to me · BuzzRadr