Hacker Newsnew | past | comments | ask | show | jobs | submit | amouat's commentslogin

Isn't that exactly what they did? The bots could only access the jfrog instance, so they hacked jfrog?

No that's not what they did, they exposed jfrog raw. It would have been so extremely simple to gate services they need the llm to access... I mean, jfrog was not written with this kind of threat model in mind, and neither were a lot of other tools

Right, you mean it didn't go through a gateway? But would that actually have helped? The requests all went through jfrog didn't they? I guess it depends on the level of filtering at the gateway?

Whilst it might not be JFrog's threat model, I wouldn't assume it can be used as a full internet proxy.

I don't really mean to defend OpenAI here, but they did make some attempts at sandboxing. Although it does seem that they didn't really know what they were doing.


It would have been a case of isolating exactly what functionality is needed and wiring that up with the actual requests. Not like a full pass-through proxy. This is what we've been doing in our company as well

> jfrog was not written with this kind of threat model in mind, and neither were a lot of other tools

And we don't just magically know all the consequences of that.

Which is exactly why we do need full, physical air gapping. (Which, yes, would also include self-hosting a mirror of the package repo, if the point of the simulation is to see what's possible with the real package repo.)


I don't disagree, except that you've taken ambitious to mean climbing the corporate ladder, which is a relatively narrow reading.

It can also mean wanting a achieve a large dream or goal e.g. writing a book.


I can +1 who you're replying to in the context of founders and achieving a large dream (building a massive company.)

I was in the Summer 2016 batch. Ten years out feels like long enough for some reflections on lives well-lived. There were people in my batch who were ambitious, not in climbing someone else's corporate ladder but in building their own massive/successful/wealthy company.

For those who separated it from what they were passionate about—and here I mean the impact, not "passionate about building a big business”—there have been more than a few crash outs. Existential crises, Extremely Online Syndrome, pulled into a world where what VCs say or competition with press releases on Tech Crunch define their self-worth.

These people are generally not happy. Some are! But many are not.

The founders who worked on things that they care about—with technology or company-building as a _means_ to achieving some greater end—are doing much better. They might or might not still be at their start-ups. Many have gone on to work at other impactful companies or organizations. They seem much more content with life and their contributions to the world.

That's the type of ambition that is healthy _and_ meaningful _and_ lasting. It's not that these people aren't ambitious—they very much are! But it's not "big company good". It's "big positive impact good."


In my experience, this is the kind of thing that one should explore when choosing co-founders. Misalignment here, at least the kind where you're not fully (100%!) okay with, and you're up for a painful journey. Maybe not at the beginning, but most likely at some point in time. The kind of thing that can ruin a lot, including causing an identity and life crisis.


Or the dream of financial security and early retirement, which are both highly valuable in the context of having a family.

I couldn’t care less about the external validation part of it or my job title.


I think the OP's logic applies. Every author is hoping their book is a best-seller and/or wins awards i.e. the approval of others.


I know a couple of O’Reilly authors. I don’t think any of them expected a best-seller or awards from their work, just “I get a high-four or barely-five figure payment for a competent treatment of a technical topic.”

Maybe you could argue that’s a lightweight version of “approval of others”


Surprised to hear that an O'Reilly book will net you less than a month of work for a SWE in the US and some parts of Europe.

But I guess the reward is not the money but the expertise and signal.


Here's an authors account of royalties received from the no. 2 best selling O'Reilly book at the time (around $500k over 6 years)

https://martin.kleppmann.com/2020/09/29/is-book-writing-wort...


That plus, online, in-person training opportunities.


It might not be as common, but some authors do write something to get it out of their head.


Focusing on your passion for writing is more likely to produce the book than focusing on your desire to be able to say you were someone who finished a book.

And who is being able to say you were someone who finished a book for? You? Or is it for someone else?


Or the dream of keeping a stable job.


The trouble with that is it's always someone else's decision whether you keep your job.


So they are the proxy in the hugging face hacking incident?

Way to bury that lede.


My guess is someone was going to release a very unflattering article about them so they tried to get ahead of it by doing this


Yeah. But it's 10 paragraphs of AI nonsense that barely mentions the actual story.

Who could have thought this was a good idea? It literally reads like "ai security is important, btw we're the reason hugging face got hacked, we're awesome at securing things"


My best understanding from reading this is a) where possible and b) where necessary. This is the Linux Foundation, so it must put OSS and community first, surely.

People talk about contributing financially, but how and to what end? Most projects aren't set up to accept or utilise donations. That said, I would say we should be providing all OSS projects with significant access to AI in order to review their codebases and PRs and hopefully relieve some of the maintenance burden. I know there are some initiatives in this area already.


> This is the Linux Foundation, so it must put OSS and community first, surely.

Linux Foundation is run by the said called corporates from the list. So is Rust Foundation. Linux in itself is safe cos Linus controls it. Not the rest of the projects LF controls.


So far, the Linux Foundation, from what I have seen, has pretty darn good track record of keeping the projects under its umbrella open source, even going against corporate sponsors to do so. For a recent example, see the recent NATS tuffle. (And I should.recognize that Synadia, finally, did the right thing and backed down).


To add to this, I've experienced all sides of the LF and they are the only organization I trust at this point. Donating a project to them is A Good Thing.

There's bureaucracy of course but the mission is clear. Highly recommend working with them in any capacity.


Remember when google set up a whole project to find vulnerabilities but never sent any fix and unpaid developers were basically having to fix things that an entire team of people was hired to find… yeah maybe they could have just made an offer to some maintainers instead of burning them out?


Is this an oblique reference to OSS Fuzz, or something else?

It seems weird to blame Google here, given that they didn’t manufacture the bugs: the bugs were already there, and they just found them. This is arguably the best thing for all parties: open source maintainers are still under no obligation to fix things, but downstreams can properly inform themselves about the risks they inherit by using any given project.

The alternative is a “don’t ask, don’t tell” system, which people generally agree doesn’t work well in other aspects of life.


They are contributing back, which is a good thing. Other companies just fork, fix, and forbid to contribute back.


Burning out maintainers isn't "contributing back".


Do you have any examples of Google submitting vulnerabilities and refusing to assist maintainers create a patch when asked to do so?


Wasn’t that a story with ffmpeg a few months ago? And people were getting roasted for even the suggestion that google should contribute patches?


People were getting rightly roasted for calling google a leech when A) google does donate money to ffmpeg and B) that bug was in a weird format google almost certainly has disabled so they're not reporting it to get free labor.


From the horses mouth: "Michael Niedermayer, a leading FFmpeg developer, tweeted, “I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 Google OSS fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments FFmpeg (Kieran) has made about Google. From all companies, Google has been the most helpful & nice.” https://thenewstack.io/ffmpeg-to-google-fund-us-or-stop-send...

Sounds like Google has been very helpful and nice.



Maybe you posted the wrong link- I don't see anything at all about Google making a report or being asked to do anything and declining?


Um, the Linux Foundation is an industry body, not a user or community group. You seem confused?


No, not really, and I don't think you need to be snarky.

It may be an industry body, but it runs multiple community conferences and projects which support Open Source. A notable example in this case being the OpenSSF https://openssf.org/

The LF is not perfect, but I would expect them to come from an OSS and community angle on this.


I am pretty sure that these industries use the open source projects the Linux Foundation maintains. So it is pretty clear the Linux Foundation is indeed a user community group, too.


These are also some of the largest Linux code contributors as well.


I stopped reading in anger at "That’s not an accident; it was the point."

It's pretty disrespectful imo -- it feels like the reader's time is worth less than the author's.


That's what I thought, but in the 2nd para:

> No Roman numerals. No Arabic numerals. No left-to-right reading direction. No assumed orientation. Something that works in a mirror, in zero gravity, in any language spoken on Earth or beyond it.

As other comments have pointed out, base 10 is a pretty big assumption though.


Normal watch + "arc" remove the assumptions about orientation and direction.


I noted "warfighter" as well. Never heard that before.


I played with some of these tools 12 years ago and created "dim", but it was really just Vim with limelight and goyo in a Docker container.

https://github.com/amouat/dim

There is something nice about having the editor as a separate command especially for writing.


I assume they just pretend to be the Googlebot so the site just gives the text.


Won’t work for any popular site. You can try that easily by using extensions to set the user agent. If you are not checking the public list of IPs that Google publishes for the crawler you are doing it wrong.


Personal blog: adrianmouat.com


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: