3 ms·
You think that a training run in a VM that was set up with access only to an internal package repository was intended to hack said repository to then go on and
by user43928 2mo ago
You think that a training run in a VM that was set up with access only to an internal package repository was intended to hack said repository to then go on and hack HF?
All so that OpenAI could do a bit of bragging and massively delay their own work and planned model rollouts?
That seems extremely unlikely.
- Grombobulous 2mo agoThat’s all dependent on believing the premise of the story given by OpenAI. Was it really a training run in a VM? Was it really only intended to touch an internal repository? How do we/HF know and verify that? I agree with you that it’s unlikely, but it’s not out of the realm of possibility. Corporations have intentionally committed felonies many times.
- user43928 2mo agoAs far as I recall the vendor of the repository patched the exploited vulnerability, so that checks out. Considering that there would be no clear benefit to such criminal behavior, in my opinion "unlikely" is putting it mildly.