Hacker Newsnew | past | comments | ask | show | jobs | submit | rvz's commentslogin

This whole blog-post is impressive with the chain of vulnerabilities involved. However...

> OpenAI also paid us a $6,500 bounty.

?

That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.

This is like getting close to breaching the main monorepo at Google: google3.

If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.

Come on.


My guess is that OpenAI has done a lot more to prevent exfil of their model weights than the codebase of their main web app and client.

The unfortunate truth of doing the right thing. Also, correct me if I'm wrong but there are too many bad things out there and companies can't give 1 million bounty for stuff like that. I'm sure they could but in the long run, wouldn't it be unsustainable?

It’s an interesting bet then.

Pay next to nothing every time, accept one financially-depressed researcher sale to blackhats causing tremendous business disruption every n years. Cheaper than honest payouts to [keep] researchers [honest]? Keep paying chump change. (Booo)


How much would a nation state pay for a complete copy of OpenAI’s github repositories? I doubt there are many full chains laying around like this.

No more unsustainable than these companies already are by default. The bounty should have been proportionate to how important and pressing the findings were.

Correct. It is another way to divide people again, just like people who are pro-AI vs anti-AI.

Do not fall for it.


You are conflating "divide people" in the sense of "turn people against each other in order to divide and conquer" with "divide people" in the sense of "define groupings so that it is possible to have conversations about differing experiences". One is discussing a goal while the other is discussing a tool. Notably that tool does not necessarily need to be used for evil and often isn't.

This does not make any sense whatsoever.

I thought I made it clear right up front. 'Why agents need their own CLI'

What's not clear about that?


Here's a good set of questions for any write up:

Who are we talking about? What's their role? (What agent? What is the job to be done?)

What is the status quo? What's the problem with the status quo? What else has been tried? What's the consequence of not solving the problem? What more important problem do you need to work on that you're blocked because of this problem? What's the ideal solution? What's the current offer? Why would someone say no to any given solution? How have you addressed those problems?


Both uutils and coreutils should be GPL3 at this point.

Exactly. Once lots of vulnerabilities are discovered they would then have to think twice about this policy.

> Instead you propose that this project should be funded by a for-profit company with it's own objectives in this world (that often starts with "more money"), again leading me to ask why?

You understand that Mozilla Firefox is not funded by the "community" and is completely funded by Google's money. Even donating does not fund the browser.

Mozilla knows that the open source "community" has no money, and cannot replace the amount of money Google is paying them and the employees who work on the browser.

The question is are you ready to fill the $600M a year black hole for Google to NOT pay Mozilla to fund Firefox?

It only makes sense for Servo to get funding from for-profit companies at this point, which is one of the only ways open source can work.


This has been posted many times here: [0] and it is a [dupe] of a recently commented thread 16 days ago in https://news.ycombinator.com/item?id=49512975

[0] https://hn.algolia.com/?q=ASCII+City


If you followed the link you'd find your link is a yt video, whereas this link, isn't.

As much as I am a fan of Woz on his technical achievements, at least he knows that he fell off out of relevancy when he launched / shilled a crypto coin and now goes out to sell (mediocre) merch. I respect that grift.

DF (daringfireball) however, continues to be increasingly so irrelevant that they sometimes veer off into unrelated Apple news to increase their clicks on their blog, without knowing it.

In fact, it makes sense. Apple cares more about X than they do about DF. Not even Apple cares about DF anymore ever since they didn't invite the author over to the HQ.

Woz still gets invited to the HQ to this day.


> they sometimes veer off into unrelated Apple news...

Gruber has always done that. Years ago I made a Chrome extension to filter out all of his detours into baseball, James Bond, politics, and I can't remember if I let the Kubrick stuff stay in or not.

Ultimately I just stopped using Macs, so the blog was no longer relevant to me. Mark Gurman seems to have taken over the role of Apple whisperer anyway.


> Woz still gets invited to the HQ to this day

Isn't Woz technically still an honorary Apple employee, or am I misremembering that?


I didn't know people read him regularly. All i know about him is he made markdown and then cried when people tried to standardize it because it was underspecified.

Stopped reading DF ever since his unhinged posts mocking the war crimes being committed in Palestine at the hands of Israel.

"F*k around and find out" he quote tweeted a news article that talked about how phone and internet services were cut out in Gaza as armed Israeli occupational forces entered Gaza.


First of all, this is a pre-1.0 release that requires a nightly Rust compiler (if you choose the SIMT track with cuda-oxide) so that one is going to be unstable software.

Secondly, When an issue occurs with a kernel or you want to write your own custom kernel in Rust, now we need to diagnose if the problem came from either cuda-oxide (SIMT), Rust's side, CUDA or Tile (If you decide to choose the Tile track).

Another dependency into the list and course everything is open source except CUDA itself. So any issue that happens on the CUDA level, you are forced to wait for them to fix it.


Backup both locally and everywhere no matter what.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: