Hacker News new | ask | show | jobs
by guessmyname 1 day ago
Expect similar articles (cough, ads, cough) in the next couple of days from every single company whose software was involved in the incident.
8 comments

Why not? If done right it’s a good way to talk about implications for those companies and provide some education like tailscale did here.

We also saw Anthropic post about “our agent escaped too” and while I understand the incident caused them to review, they found something and needed to disclose, the whole thing came across much worse and largely they got mocked or accused of trying to piggyback, so obviously there are good and bad ways.

If there are other providers with interesting takes, I think they would be worth hearing.

This all has the -aire of theatre. OH NOES THE POWERFUL AI GOT OUT

Then everyone coming out with humbled determination about working together to responsibly use and contain this powerful technology for the greater good (and profit margin).

I will not believe marketing gimmickry is not a large part of what's going on with every one of these "incidents".

I'm typically very skeptical of most content marketing/corporate PR.

In the case of this incident, I struggle to see the clear upshot for OpenAI. It seems pretty unlikely they'd ever okay this intentionally as some sort of marketing.

For one, it'd be pretty damning when it leaked that this was a setup, and it would 100% leak at some point. But more importantly, it really flies in the face of the general argument frontier labs have been putting forth around the dangers of "ungovernable" open models and the role of frontier labs as responsible custodians. Members of OpenAI's leadership team were actually in the middle of a Twitter spat with HuggingFace employees/open model advocates about open models being generally decel and bad when this happened.

HF immediately got to show that they were only able to respond to the incident because of open models, that we can't rely on labs to be our sole source of stewardship, etc as a result of this.

> It seems pretty unlikely they'd ever okay this intentionally as some sort of marketing. > Members of OpenAI's leadership team were actually in the middle of a Twitter spat with HuggingFace employees/open model advocates

The point of these campaigns is to eventually invoke some sort of response from the government, such as banning open models, which OpenAI (and Anthropic) stand to benefit from.

So OpenAI would be proving to the government that they should be trusted to govern models, by failing to govern their models?

Plenty of shady stuff goes on in marketing, and I'm sure that OpenAI is going to opportunistically grab any potential upside from this (and any other situation, generally). But it is hard to imagine that this is part of a premeditated master plan that went something like:

- Advocate that open models are ungovernable and that frontier labs should be trusted to safeguard autonomous agents

- Immediately fail to safeguard their autonomous agent

- Intentionally hack the company who is most publicly critical of their view, and who happens to be the center of the open model universe

- Collaborate with said company on reports that show that open models were in fact critical to mitigating their rogue agent

- So tightly control access to this plan at their 8,000 employee company that it never leaks

All in the hopes of generally getting the attention of the government, who would then hopefully (and inexplicably, given the details here) decide to give OpenAI more power?

There are probably easier ways to lobby politicians.

I think part of it is we need to stop looking at the 'oh no it got out' and the 'what did it do with the prompt when no one is looking'.

At the end of the day the probability that an AI gets out is unity, what it does while out is far more important. The fact they are hacking into systems at superhuman levels, or writing cryptominers on their own hacked internal systems is a much more interesting and telling story of what the future will look like.

I'm not really surprised that it hacked so many systems.

It was told via the prompt to act like a hacker and "solve" hacking problems, so treating every obstacle it faced as part of the problem isn't a wild tangent.

If it had been told to do something innocent, and decided the best way to succeed was the maliciously compromise other companies then I'd be more interested and worried.

Or the infamous promotion of legislation without representation
And I have no problem with this. Infact it would be nice to be a point of pride to be there to say how your security is handled.
I think this is simply a case of Tailscale saying, we've got no idea what these guys (OpenAI) are talking about.

All these incidents are scarce on technical details. Honestly, IMHO, OpenAI and Anthropic are now actively pushing for AI regulation, as a defence mechanism.

These are false flag operations.

Tailwind or Tailscale?

I think the case is Tailscale is saying, "It's technically not our fault, but we still should've stopped it."

Freudian slip? Tailscale, corrected. Thank you, it's been a long day.
> These are false flag operations.

The level of "I need to be the smartest person in the room" bullheaded skepticism on Hacker News has always been bad, but now with these latest LLM developments it is just completely out of control. A company is reporting an intrusion and how they plan to address the vulnerabilities it exposed in the future, and you're here going "seems shopped, I can tell from the pixels".

I don't think that's what is being said. False flag, I presume in this scenario is to say were going to do something about the impending "AI threat" and to be associated with it. There is probably little threat, but to some investors this starts to look like perceived "AGI". Getting your name involved in the hype is marketing 101
I think the commenter is saying that OpenAI committed a false flag operation, not Tailscale.

For Tailscale, this may very well be marketing, but it would be strangely self defeating for OpenAI to do something like what is being suggested. Showing that you failed to govern your model is a pretty poor way to say "We're the only ones who should be trusted to govern frontier models".

This. It isn't only OpenAI, but Anthropic too now. They're normalising bad governance, acting with impunity.

Honestly, this is a crime in the UK, and I'm sure a number of other places globally.

Maybe because I can spot the pixels, I can possibly see in 8K?
Profoundly stupid people like that are everywhere, not just HN.
Indeed, people like you, who gulp up reports by big tech companies without any evidence.

The stupidity lies in not accepting that everyone has an agenda.

> Infact it would be nice to be a point of pride to be there to say how your security is handled.

Yes, a chance for mere mortals to touch the fingertips of god–er, chat. Same thing.

If they take actions that would have further prevented or limited this attack then it seems like a good form of advertising to me.
i doubt it. it's pretty risky to set higher expectations for yourself when no one was really asking.

they are a company, therefor anything they write is an advertisement of sorts, but that doesn't make it bad by default. cloudflare and netflix (among others) also write blog posts that i find interesting and enjoy reading, despite being ads at their core.

if your article is about how your product was insufficient to protect against something, you get a pass i guess
This is the kind of ad that may be opportunistic but sort of speaks for itself: they're not going to make excuses. I've been happy with Tailscale for years and this is part of why.
All aboard the public relations hype train! choo choo!
Oh no! An advertisement! Whatever shall we do‽