Like, what does this actually mean? Was OpenAI using HuggingFace to generate a ‘photograph of my future girlfriend’? Was it stealing trade secrets? Like what is the actual nature of this breech? The fact that big tech companies won’t release details makes me think it’s even more smoke and mirrors (I.e. that they are trying to cover something up, possibly their own involvement in this crap).

Ok admittedly they’ve explained a little more than I’d expected them to. Still though, there’s a lot of uncertainty at work here
We can’t be certain OpenAI is faithfully reporting the initial hacks to gain internet access, or I suppose that anyone is faithfully reporting (since there’s basically no oversight). But I’d be surprised if Hugging Face and OpenAI were working together on obfuscation here. As a kinda funny aside, Hugging Face tried to get help from cloud AIs for fixes, but got refused on security grounds. So they resorted to using a self-hosted model (GLM) to shore things up. OR, they found a way to make the whole thing marketing for themselves too. Who knows!
I’m not sure why that would be surprising. Hugging Face has partnered with several AI companies including Open AI. Everyone involved has a vested interest in making llm based ‘AI’ seem more capable than it is.
I suppose I think of them as competitors, but you’re right of course. Just talking through it makes kayfabe seem more likely.
My point about them covering up wasn’t so much that the companies were working together (or specifically that they were working together). Maybe the guys at OpenAI had their model purposely hack HuggingFace is another possibility. Also, openAI isn’t the only incident: did you hear about Anthropic AI?
Aye, there are a bunch of examples from Anthropic (here’s 3). But there are way more examples of AI being used to intentionally hack, and I wouldn’t rule out that possibility here. It’d certainly be a way for one AI lab to hack another and call it an accident. Though I’m not sure what they’d be looking to gain from an intentional Hugging Face hack other than publicity.
That’s my point, and why I believe it (may have been) intentional
Even more here: https://huggingface.co/blog/agent-intrusion-technical-timeline
Fascinating