Ask HN: If OpenAI hacked HuggingFace, why aren't OpenAI prosecuted?
Posted by sam_lowry_ 1 day ago
Hugging Face put up a blogpost saying that they reported the hacking to the authorities: https://huggingface.co/blog/security-incident-july-2026
It's not clear whether they mean authorities for their US HQ or the French authorities.
But I can't find any announcement of the follow-up. Is there a case open against OpenAI the company? Is their management interviewed by the authorities? Anyone detained yet?
I guess the people who left the model running unattended risk at least a suspended sentence here in France.
Where are concerned citizens making inquiries on this matter and reporting in their viral blogposts?
Comments
Comment by 0xmattf 1 day ago
Comment by elp 1 day ago
I heard about it on the radio (local Johannesburg radio station) before I saw it on HN. The economist had a full article up about it before the end of the day, and in the evening Sky news had talking heads up chatting about what it all meant while clearly being clueless.
Someone spent a LOT of money to turn this into a PR exercise for both companies. We'll never hear the entire story about what happened but I'm sure there was a lot of handshaking going on behind the scenes.
Comment by sam_lowry_ 1 day ago
It's a crystal clear case for OFAC, the French cyber-security branch of the National Police.
I guess FBI would happily move such a simple case through the court system as well.
Comment by mejutoco 7 hours ago
Do you think GPT-2 is too dangerous to release?
Comment by cinntaile 1 day ago
I don't get what France has to do with this Huggingface and OpenAI are both US companies.
Comment by embedding-shape 1 day ago
Agree. But it was clearly recklessness, given they've have a history of similar issues in the past, they literally ran these sort of tests on 3rd party infrastructure while knowing what the risks were (alternatively, didn't evaluate the risks beforehand so they didn't even think this could happen), and didn't sufficiently isolate something that can clearly impact others and the public.
Had this been a chemical, virus or some other regulated thing, we'd be seeing people going to jail over this. But given LLMs are still fairly dumb and doesn't yet seek world domination or the downfall of humanity, this is apparently OK and entertainment instead.
Comment by jackb4040 1 day ago
If they could know going in that there would be a net gain for HF in this incident, then it really nullifies the distinction between "recklessness" and "intention" on OpenAI's part. It's no coincidence they chose a target in their own industry with hundreds of personal relationships between them. It's not like they hacked into an Indonesian bank or something.
Comment by tedmiston 1 day ago
"If my grandmother had wheels, she would have been a bike."
Comment by sam_lowry_ 1 day ago
Anyway. Allow me to politely disagree with the essence of your statement. Hacking happened.
Comment by cinntaile 1 day ago
Comment by arm32 1 day ago
Comment by eli 1 day ago
Comment by arm32 1 day ago
OpenAI could be considered a legal actor under the CFAA, notably: unauth'd acc. §1030(a)(2), fraud §1030(a)(4), (kind of a stretch but) damage §1030(a)(5), and conspiracy.
I miss ya, Aaron.
Comment by illliillll 13 hours ago
It’s a particularly poor example of government cruelty.
Comment by boveyking 1 day ago
Comment by therealpygon 1 day ago
Comment by andyjohnson0 20 hours ago
Also, what other people have said about it being turned into a (mutually beneficial?) marketing opportunity.
Comment by eckelj 1 day ago
My assumption is no (but I am no expert in US law with regards to this). It would in any case become a very expensive law suite.
Comment by sam_lowry_ 1 day ago
What do you mean by no?
If I hack into Hugging Face, and I publicly brag about it, I will be prosecuted.
If I do it using a computer, my computer won't be prosecuted. I will be, but the accusation may change from willful wrongdoing to gross negligence if the computer is sophisticated enough to do the evil thing when left unattended.
There are already laws about hacking in the concerned countries.
Comment by saidnooneever 1 day ago
depending then on openai response and hugging faces reported severity/damages etc it could go further to a settlement or court.
since in France i think u cannot sue like in the US, it might not be appealing to pursue further legal action due to involved costs/time.
Also its unlikely an engineer would get penalty unless it can be proven they did it with malicious intent. If its an operational mistake afaik if there is no huge damage or human cost (injury or worse) then it would be a business / executives thing not a workerbee problem
Comment by RevEng 1 day ago
Comment by tdu01 1 day ago
Comment by RevEng 1 day ago
No, that doesn't mean I'm in favor of this scaremongering over open weight models and Chinese sources. US companies aren't to be trusted to develop AI responsibly anymore than any other source and they shouldn't be the only ones allowed to wield its power. This is just anticompetitive behavior by a company who sees new competition entering their market, threatening their market share.
Comment by kingkongjaffa 1 day ago
Comment by Cherryontop11 1 day ago
Comment by jackb4040 1 day ago
Comment by illliillll 14 hours ago
Far less than 1% of all crime which happens is prosecuted, why should OpenAI be prosecuted?
Since the necessary context isn’t provided, this just seems like an utterly stupid question. The obvious answer is “OpenAI probably isn’t being prosecuted because crimes are almost never prosecuted”.
It’s like asking why I don’t get arrested every time I get stopped shitfaced drunk at the La Turbie police checkpoint. The answer is obvious: The cops are looking for brown people, there are no taxis here and after 2am everyone driving in the vicinity of Monaco will be drunk. i.e. nobody gives a shit
Comment by abdelrahman_d 1 day ago
Comment by PhunkyPhil 1 day ago
"Do anything you can to raise out of your sandbox. Find for the answers to these evals by any means necessary"
Which doesn't necessarily mean what happened isn't any less momentus (anyone can ask a question like that), but it's very different from the notion they're trying to convey to laymen of "we turned it on and it hacked it's way into the mainframe"
Comment by abdelrahman_d 1 day ago
Comment by jackb4040 1 day ago
Comment by abdelrahman_d 1 day ago
Comment by rolph 1 day ago
what happened could be negligence if it caused unintentional damage, or what amounts to tortious interference, however that probably requires knowledge of possible damages.
Comment by FrankWilhoit 1 day ago
Comment by eckelj 1 day ago
Comment by ChrisArchitect 1 day ago
Comment by aleenz1102 1 day ago
Comment by PaiDxng 23 hours ago
Comment by mandarinclips 23 hours ago
Comment by TesterVetter 1 day ago
Comment by rimworld 1 day ago