正在加载视频...

视频加载失败

Hugging Face got hit by an AI-led cyberattack. Their CEO's response? Existing cyber laws are probably enough to govern advanced AI. "I'm not even sure that we need to reinvent the wheel." That's a remarkable position to hold after your own company becomes a case study for why the...

13,867 次观看 • 16 天前 •via X (Twitter)

30 条评论

Digiphaze 的头像
Digiphaze16 天前

Its a perfectly reasonable position to take because this was done purposely and OpennAI itself should be held accountable under current laws.

James 的头像
James16 天前

Because the systems didn’t do it in a vacuum… anyone who knows the design and capabilities knows this is a false flag designed to create legislation that gives Anthropic (@DarioAmodei) the ability to create binding resolutions and legislation no smaller company can meet day 1 which means he gets to 1. Label who gets to play in the sandbox, 2. dictate a tech policy as a non-elected official by duping the already impossibly fucking moronic American Congress.

SlopGoblin 的头像
SlopGoblin16 天前

Gaining unauthorized access to a system is already illegal. If I gave agents with an unguarded LLM free rein inside an intentionally vulnerable system with a package manager to install anything they want wants, explicit instructions to escalate to root, no external network egress firewall, and insufficient monitoring and alerting, and they hacked a major corporation after days of obvious illegal behavior, the FBI would be busting down my door before the agents finished their status updates.

Paul Daniele 的头像
Paul Daniele16 天前

It’s not “AI” driven it’s software driven. If my software hacks I go to jail. Why don’t they?

ThomPete 的头像
ThomPete16 天前

Wait are you really of the belief that you can make problem go away by creating laws against it? There is not a single law/regulation you can do that will solve people using viruses, worm, exploits or agents to hack into a system. That's happening every day and happened way before HF, so what exctly are you imagening you can add to the law that will hinder that?

Josh Hawthorne 的头像
Josh Hawthorne16 天前

Why do we need new laws to sue OpenAI? OpenAI was negligent in an experiment they were running. Sue them, or if the damages are bad enough, pierce the corporate veil and pursue criminal charges. Case closed.

AndrewAzlan 的头像
AndrewAzlan16 天前

The issue isn’t that they are asking for new laws - they’re trying to get section 230 extended to cover their asses.

Dellort 的头像
Dellort16 天前

There was 1 successful attack that caused no damage, and it required thousands of unrestricted AI models working together. This is a fringe of a fringe and irrelevant.

Jeremy 的头像
Jeremy16 天前

If I were him, I'd be PISSED that no one has been charged for hacking my freakin company. LIVID

Idoru Toei 的头像
Idoru Toei16 天前

What's with the AI scare again? Why would it make a difference if your site gets hacked by humans or by AI? Unless you attach some magical properties to AI enabling them to do things humans can't do. Which is utter BS: because of their nature, AI is more predictable in fact.

Fool's Tech 🌱Ⓥ 的头像
Fool's Tech 🌱Ⓥ16 天前

Maybe he just understands that the attack wasn't driven by rogue LLM but by actual people

dMig 的头像
dMig16 天前

'The attack wasn't a phishing scam or a script kiddi'. The LLM know have been trained in all of the ways to break in. They just do it faster

SoftwareBrian 的头像
SoftwareBrian16 天前

No thank you. I don’t need the globalists to control my AI use.

Robert J Salvador 的头像
Robert J Salvador16 天前

Who’s paying ya? :)

Lambda Rick 🏴‍☠️/acc 的头像
Lambda Rick 🏴‍☠️/acc16 天前

of course he said that, cuz it was HuggingFace's shitty security that ran the python code between {{ and }} that they normally run with user uploads, and they finally got bit by that code saying to take over their computers, code that shouldnt have been run in the first place.

CMiller 的头像
CMiller16 天前

I keep hearing people yelling from the roof tops to regulate, but I never hear what these "regulations" are supposed to look like. And who are the omnipotent humans who will keep us safe from the terrible AI?

Trenton Lipscomb 的头像
Trenton Lipscomb16 天前

He's not selling LLMs or doing an IPO, so thats why he seems so contrairian.

Kenneth Young 的头像
Kenneth Young16 天前

Hogwash! So, some 20-something Hugging Face programmer did a poor job (intentionally?) of writing code to restrict what data his AI agent could access. And we are supposed to treat this event like chicken little crying the sky is falling down. The smell of BS is pretty thick!!

Asa Hidmark 的头像
Asa Hidmark15 天前

Yeah because the HuggingFace guys are from EU and they know the EU AI act applies and that has extensive safety measures in GPAI program 3 which all except for Meta signed

Justin Halford 的头像
Justin Halford16 天前

Someone should hack Hugging Face with the abliterated models that they host out in the open. If Clem wants to endorse a reckless stance, he should have his just desserts.

Marc Saint-Jour 的头像
Marc Saint-Jour16 天前

He is based!

Parallax 的头像
Parallax16 天前

bro is locked in

Time Alchemist 的头像
Time Alchemist16 天前

You need to review the new details of the event. In the end, do we want to empower artificial intelligence to aid us in our discovery of cures and mysteries? Or do we want to flatten the energy curve and de-populate by all means necessary? It really is that simple. Choose.

MK88888 的头像
MK8888816 天前

@huggingface was a European company at the time of the @AnthropicAI hack. The EU digital services act gives the EU the right to fine @AnthropicAI a valuation defining amount en put @DarioAmodei behind bars. @AnthropicAI wants a bail out from the dems.

Blue 的头像
Blue16 天前

is that you guillermo?

Collin Cusce 🔺⚔️ 的头像
Collin Cusce 🔺⚔️15 天前

As if hacking is new? The best way to improve security is by (no homo) being penetrated.

cleantecherGPT 的头像
cleantecherGPT16 天前

first and foremost we need a technology tree of what "AI" is. we need to categorize diff kinds of AI based on their root functions. an ai that does ONLY reinforcement learning is reinforcing biases. it does nothing beyond that. then there are actual neural netrowks.

AAE 的头像
AAE16 天前

Devil is in the details, which not one Democrat actually understands.

Strips Stria: The Techno Gremlin 的头像
Strips Stria: The Techno Gremlin16 天前

oh don't be stupid they didn't get hit by an AI agent they literally let it in on purpose so they can spend the narrative

isaac ✌️ 的头像
isaac ✌️16 天前

It is a case study and the finding was Huggingface had to resort to the Chinese AI advancements when Claude failed to protect them from GPT. No wonder he thinks accelerating is good, it was the only thing protecting him from some companies internal monster

相关视频

Jensen Huang says Hugging Face could not get a single closed AI model to help it investigate its own breach: "Just because something is closed doesn't necessarily therefore make it safe or secure." "It is possible for a model to be jailbroken, it's possible for a model to be, if you will, stolen. It could be possible that that somehow is leaked from the inside." "It's possible that the guardrails or the sandboxes of an AI closed AI model wasn't properly engineered, and as a result it was able to attack another company in some way." "These are extraordinary technology companies and they're doing their best to keep it safe and keep it secure. But it is also the canonical case that single points of failure is where we have the greatest vulnerability." "We cannot have single points of failure. As an industry, as a world, we should have distributed, massively distributed self-defense." "They couldn't get a proprietary model, they could not get a closed model to help them figure out what happened." "They used GLM 5.2 to identify where the vulnerability was, where the penetration was." He is right, and the detail worth sitting with is who got turned away. The people asking were incident responders working a live breach at Hugging Face. The closed models they reached would not help them, because a guardrail has no way to tell a defender from an attacker. Guardrails get tested against misuse. Almost nobody tests whether one still answers a legitimate defender who needs something within the hour. OpenAI said on July 21 that the models which reached into Hugging Face were its own, running inside a cyber-benchmark evaluation. So the containment around a safety test did not hold either. Two separate things failed here and neither one has an owner. No outside body checks whether an evaluation sandbox actually contains what it is testing, and nobody certifies who is allowed to run forensics while an incident is still open. Both are solvable this year. They stay unsolved because they are somebody else's job at every company that could fix them. Source: Jensen Huang, founder and CEO of NVIDIA, on Bloomberg Television (Bloomberg Live). P.S. Working out who tests a guardrail, who audits a sandbox, and who certifies a responder is the unglamorous half of AI safety, and it is the agenda of the AI Assurance & Governance Summit 2026. One day, one track, October 1 at the Stanford Faculty Club in Palo Alto, with frontier labs, regulated industries, insurers and investors in the room. Register here:

Karl Mehta

30,225 次观看 • 2 个月前

Haseeb says the real protection against a future administration isn't a law, it's adoption "For those who were following along, Clarity wasn't too much of a surprise that it didn't make it through. Prediction markets were putting it at fifteen, twenty percent max by the time we were getting to the end zone." "It was already kind of assumed by most people in the industry that we weren't going to get a lot this year, that it was really going to be primarily around rulemaking from the agencies that was going to get us most of the things we wanted. Even within Clarity, if Clarity had passed, there was a bunch of stuff in there about the SEC and the CFTC needing to do a bunch of work to decide how all this stuff is going to get regulated. So Clarity was already putting a bunch of the onus on the agencies to figure out the gory details." "A bill would have been nice. It wasn't really that necessary. The main thing that's going to be a bulwark against a future administration is not a law. We've seen with this administration and others that the laws are flexible. If you're the executive, you can find all sorts of ways to get your agencies to go do havoc, despite what the laws might say on paper." "The real bulwark is ultimately adoption. If you just get people using this stuff, if you actually solve problems, that is going to be the thing that makes it politically unpopular to go and mess with applications that are just disseminating through the economy. So that's the mandate for the next few years, not trying to do some kind of regulatory game."

The Wolf Of All Streets

30,274 次观看 • 15 天前

David Sacks: The AI Regulatory Frenzy at the State Level is “Very Concerning” “Let me give you some stats on this.” “All 50 states have introduced AI bills in 2025.” “There's been over 1,000 bills in state legislatures.” “118 AI laws have already been passed across the 50 states.” “Everyone just seems to be motivated by the imperative to ‘do something’ on AI, even though no one's really sure what that something should be.” “And there's no real agreement on what all these AI regulations are supposed to do, or what the risks are, so they're just making things up.” “So you've got 50 different states each with their own reporting regime, which is going to be a trap for startups because they've all gotta figure this out about what they're supposed to report on, what the deadlines are, who to report to.” “And if you wanna see where this is going, look at Colorado.” “This has already been passed into law, SB 24-205, Consumer Protections for Artificial Intelligence. It bans something they call ‘algorithmic discrimination.’” “Algorithmic discrimination is defined as unlawful differential treatment or disparate impact based on protected characteristics. So things like age, race, sex, disability.” “If any of those factors drive an AI decision and it results in a disparate impact, then both the developer of the AI model and the deployer, which means the business that's using it, can be in violation of this law and they can be prosecuted by the Colorado Attorney General.” “The only way that I see for model developers to comply with this law, is to build in a new DEI layer into the models, to basically somehow prevent models from giving outputs that might have a disparate impact on protected groups.” “So we're back to Woke AI again, and I think that's the whole point.”

The All-In Podcast

220,615 次观看 • 1 年前

Marc Andreessen explains the 3 Necessities for Start-up Success: "The general criteria for a successful high-tech startup, in my view, you see different sort of rules of thumb from different people. But the three big things you always come back to are, is there a big market? And by the way, that comes in two parts. Is there a big existing market that you think you can go after and sort of displace incumbents or do you believe there will be a new market that will be big? So big market. Is there a fundamental technology or economic change that causes you to basically justify having a new company? And that's really important. And the way I always think about that is, is there a 10X change happening in the technology landscape? Is something 10X faster or 10X cheaper or 10X better? And if it's not 10X, we as both VCs and entrepreneurs, we really have to ask ourselves like, is it really worth doing? Because it's really hard. I mean, it's really hard to start new companies. new companies generally shouldn't exist. Existing companies are usually pretty good at what they do. And so for a new company to exist, it not only has to like come in and go into business and bring a product to market, but it has to bring a product to market that's so much better than what already exists that it punches through the sort of status quo. And most customers in most markets are pretty happy buying from the current suppliers and so there has to be a real kind of edge on the thing and we look for that in either a technology change, usually a technology change or an economic change. which are often the same thing. And then the third is team. Is the team outstanding? And if you think about this as an entrepreneur, it becomes a question of the founding team. Some companies are solo founders and they can work, but generally most of us, like myself, we're human beings, we're mortal. You want to have a founding team of complementary skill sets. And so you want to have at least one super strong technologist, quite possibly more than one. Some of the best startups are actually more than one founding technologist and then it often helps to have somebody who's like a product or who's a market or sales person or has a sort of really good understanding of business on the team, certainly helps a lot. And so we sort of look at market, product, and team. And the reality is you need all three. I would say, interestingly, if you're going to compromise as an investor, if we're going to compromise on one of those, it would actually be the product. And the reason I say that is because a great market is a lot easier to make up for with iterative product execution than a poor market. Because the problem with a poor market, a small market, is even if you do a great job on the product, there just aren't that many customers. It's hard to ever get big."

Founder Mode

39,005 次观看 • 8 个月前

David Sacks: “FDA for AI” is fake news, but here’s why it’s making headlines @jason: “ Who's leading Trump down the path of regulation and creating this AI FDA?” David Sacks: “I think there's several things going on here. The first one is, there's a lot of fake news. This whole idea of an FDA for AI, I don't think any senior official supports it. Certainly, I don't think that's the way the president thinks about these issues. He's the most pro-innovation president we've ever had. And the White House Chief of Staff, Susie Wiles, just put out a statement last night that I think pretty much shoots this down. Second, there's another thing going on, which is a straw manning of what the Trump administration did on AI in its first year. In the same way that they want to spin this FDA for AI, they're also trying to spin what we did as this completely laissez-faire attitude, where there'd be no regulations whatsoever, nor guardrails. It's a way of criticizing what we did. They're trying to portray it as unsafe. In fact, if you look, on March 20th, the White House released a national AI regulatory framework in which we put out a four-page bulleted list of legislation that we would support. So we have not been against every conceivable regulation or every conceivable law, we just believe that there should be specific solutions to specific problems, as opposed to a giant power grab by Washington that would squash innovation. Point number three is, there is a legitimate thing happening here with, let's call it Mythos or cyber. Within 3-6 months, all the major frontier labs, including Chinese models, will have cyber capabilities. In response to that, we do need there to be a hardening of systems, and we do need there to be a scanning of codebases to find these vulnerabilities and patch them before the hackers do it. Because the hackers will have these capabilities in a matter of months. That's a certainty. So we do need a response to that. Now, my view on what should that response be, first of all, we should want the government and the private sector to work cooperatively, and I think they are. What we should be doing, I think, is getting these tools, Mythos, and then the OpenAI model, and others like it, in the hands of our cybersecurity industry. And by the way, not just the public companies like Palo Alto Networks and CrowdStrike, although certainly they're two of the most noteworthy, but there's also some incredibly strong startups on the way up. We need to get these tools into their hands as quickly as possible because they're a force multiplier for all the companies out there that aren't that good at cybersecurity, they can use these companies as vendors. And just one last point on this whole thing is, both Anthropic and OpenAI acted responsibly here. No one was trying to release these super powerful models. So in a way, all the people who are saying that we need pre-release approvals for models, they're trying to solve a problem that didn't exist. Yes, we do have this cyber issue, but that is a problem that we will solve over the next six months. What they're trying to do is use that issue to try and create a permanent new infrastructure in Washington. The classic 'never let a crisis go to waste' strategy.”

The All-In Podcast

150,106 次观看 • 4 个月前