Hacker Newsnew | past | comments | ask | show | jobs | submit | rubyfan's commentslogin

I love the concept, it would be great to see broader uptake of an open standard for this sort of space.

Thx. The spec matters more than the site here, its SPEC.md in the repo. Still v1.1 and cheap to change, so any/all notes welcome.

Didn’t they just raise $85B “for AI”?

It's not like they can sell the SPCX stock. It's still locked up.

Being a poorly equipped victim still isn’t a crime thankfully.

It may or may not be a crime and typically the damaged party is pressing the charges. One would argue there is no actual damage here.


Despite the common misconceptions from TV, the victim "pressing charges" isn't actually a thing in criminal cases: prosecutors can choose to put someone on trial even if the victim doesn't want that. In practice this is somewhat rare, but it certainly can happen. In my reply to tokioyoyo below I laid out why this is one instance where the government should prosecute even if HuggingFace doesn't want it to.

Criminal Cases of 'hacking' require specific intent. What you're asking is that the prosecution attempt to prove Open AI intended to infiltrate Huggingface maliciously, all while the victim is saying 'no harm no foul'.

No offense but prosecutors have better things to do with their time.


Gross negligence can stand in for intent. I believe a rather compelling case could be developed on the basis that a system believed to be capable of this was developed and improperly secured.

But what’s the crime? The thing got out of its poorly secured cage and caused what damage? Imagine instead of an agent it was a dog or a chimpanzee that got into the neighbor’s yard and the particular neighbor isn’t even pissed about it.

Aaron Schwartz was being prosecuted and threatened with 35 years in jail for the crime of saving research papers to a thumb drive. What damage did he cause?

If intent matters when LLMs get involved, then we can't do anything even if they kill millions of people. Anything LLM-related should involve strict liability.

Get back to me when they kill millions of people then. Like I said, prosecutors have better things to do.

I don't care about intent. That it happened is unacceptable. Ignorance is not an excuse

Intent often matters in the law (aside from certain laws with strict liability). You intentionally drive your car into someone you hate and kill them => murder, go straight to jail. You're driving along normally and someone who's chasing their pet cat suddenly runs into traffic and you hit them => no charges. Sometimes you can be charged with negligence for not taking enough care to prevent something, but then you have to deal with the tricky question of how much care is enough.

If you're driving along normally and then tie a blindfold around your face and hit someone you've taken actions that still expose you to liability. And, in the case that you hit someone who is chasing their pet cat into traffic then you'd better hope you were following every facet of safe driving - being distracted, drunk or on your phone could easily result in you being charged.

I mean, in theory the FBI could press charges on this as it was an attack involving interstate commerce.

The chances of this are nearly zero if HF doesn't want it, and even if they did OAI has their bread buttered with the administration.


But what do you honestly expect would happen? It’s “an accident” with no actual damages.

My hunch is they are all seeing the problems at OpenAI and some other collateral damage on the horizon. They don’t want the US government intervening to try to save OpenAI. A little controlled burn is probably good for the industry long term.

The VAST thing speaks to me. I am capable of deep focus work but often am subject to constant interruption and multiple concurrent urgent demands. During a work week I get a lot done but often feel pulled in a lot of directions like I imagine ADHD might feel like.

During the weekends when I am not occupied with a task I often fall asleep. This happens on the first day or two of vacation also. After a few days my brain acclimates to the pace.


> like I imagine ADHD might feel like.

Definitely feels like that, with the exception of task initiation. I am capable of deep focus work, but I can't control when (or where). I can block out time on my calendar all I want, if my brain says "Nope, we're not doing work today" then I'm not doing work, interruptions or not.

It becomes a real disability in the workplace when everything is defined by more or less rigid schedules and your mode of operating is not a schedule but "whenever my brain says so." Some days that might be 7am, other days its 1am, and sometimes it's an entire week or two of not being able to get jack done and then staying up all night and getting 15 business hours worth of work done at once because you physically can't pull yourself away.

I always tell people, its not a deficit of attention, I have plenty of that. Its an inability to direct where and what that attention is on.


Yes, I've found it to be completely incompatible with managers and the corporate world.

I had some success in small startups where I was left to my own devices and built cool stuff whenever I felt the urge to do so.

In corporate jobs I just have to lie and describe smooth and steady daily progress while actually working in sudden fits and starts, but it's hard to maintain the lie.


> I always tell people, its not a deficit of attention, I have plenty of that. Its an inability to direct where and what that attention is on

Yeah, ADHD is very poorly named unfortunately. It really is not an attention disorder, it's an executive function disorder


I always joke that what I am interested in doing and when it is accomplished (if ever) comes down to when the Holy Spirit deigns to work through me lol

I’ve got a few dozen quarter finished projects still waiting in line…


> The VAST thing speaks to me. I am capable of deep focus work but often am subject to constant interruption and multiple concurrent urgent demands

This is actually something that is pretty misunderstood about ADHD.

People with ADHD don't actually struggle with attention. They struggle with executive function, because their brains don't produce/consume/manage dopamine correctly

Somewhat ironically, Hyperfocus is also a symptom of ADHD. When ADHD people are doing something that is rewarding (producing dopamine) to their brains they might be really hard to pull away from it. It's really common for ADHD people to be able to sit and play videogames for hours on end, because it is giving them dopamine. Ask them to sit and do spreadsheets and they can't sit still and they look "attention deficit". But attention isn't a problem when they're engaged with the work!

I have ADHD, and I really enjoy coding and building stuff. I can't sit still for more than two seconds when I try to use LLMs to build software though. I need to be more hands on than that. Same goal, same process, different execution, completely different experience for me. I don't feel accomplished or rewarded when the LLM writes a function for me compared to writing it myself.


As a fellow ADHD.. increase your threads... while the agent is working on one thing, prompt another thread to work on another project. Keep a bunch of them in the air at one time. But make sure you are still interested in what you are building. If you don't think what you are building is important coding agent or not it's going to be very hard to do that thing.

I dunno. Sounds like trying to keep many plates spinning with breaking any, to me.

I'll give it a try though. Thanks


My vicious cycle is that the optimal time to work is overnight, when the world is asleep and the notifications and the chatter finally cease. Then, of course if I'm able to keep myself awake through the early evening I'm up hard-focused all night. Then you wake up exhausted and the focal deficiency during the day is even more pronounced per the above discussion re: lack of sleep, etc. Rinse and repeat.

> During a work week I get a lot done but often feel pulled in a lot of directions

This is normal for any "knowledge" employee or professional, or basically any job that is not strictly defined as doing one or a small number of fixed tasks such as on an assembly line.


It’s theft because a lot of rich people have money on the line.

I can’t help but feel all warm and fuzzy with my head in the sand and getting a shout out in TFA for calling it marketing.

We don’t currently and probably won’t ever fully understand the conditions that precipitated these events. That and the timing of this event is going to make it look suspicious to a lot of people.

The truth of how it happened doesn’t matter. The attention around this will be used to create the kind of fear marketing that generates enterprise sales. Maybe more importantly it will also be used to aggrandize the national security and financial system threats to effect US government action in a way that benefits domestic closed frontier labs. This is an area already starting to get politically polarized, expect further developments here.


The CEO of a cyber security company was already making comments about how this is a watershed moment for AI security. The hype machine continues (and my stocks go up)

/ot Hamburger menu at the bottom right is pretty nice too. Haven’t seen it there before but seems like a very user friendly choice for its placement.

I would attribute it to profit motive instead of either stupidity or malice.

Yeah, I think this needs to be update for the modern age. "Never attribute to malice that which can be explained by greed." Seems to fit vastly more situations.

This is marketing+. They will look for policy action here to try to capture tax payer dollars.

Are you saying it is marketing and their AI broke into hugging face, or are you saying it is marketing and their AI didn't brake into hugging face?

Those are two very different things


What incentive does HF have here?

HF need not be party to it at all, beyond being the victim. I suspect the hack is real; I have observed GLM 5.2 being able to discover similar vulnerabilities in web applications I'm hosting (which I've then fixed!). At the same time, it seems very neatly timed at an inflection point in the conversation around open models, and there's questions around the incompetent isolation under which the hacking benchmark appears to have been run.

Remember that there is generational wealth on the line for most OpenAI employees, and consider what people might do to obtain it.


Yeah. They and Altman in particular did a ton of shady stuff during the last peak of hype around open models: accusations that turned out to be outright made up (there's zero chance R1 ever distilled their model), obvious coordinated media distractions, alignment scaremongering, even possible DDoS and hacking attempts against DS (see the Xlab report everyone ignored), all of which magically disappeared once the hype died a bit later as OAI hastily released their next model.

Their alignment is under suspicion a lot more than their model's.


I don’t know if the initial “incident” was purposeful but I can tell that if I were in this position that would be my pivot.

The timing after the release of GLM 5.2 and Kimi K3 is quite convenient, too, as an angle for regulatory quashing of open-weights models just as they're entering the mainstream conversation around usurping the American frontier labs. I accept my thinking here is conspiratorial, but there's also a hell of a lot of money on the line to encourage the unscrupulous.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: