HuggingFace: Security.txt

Posted by yarapavan 1 day ago

Counter266Comment69OpenOriginal

Comments

Comment by xiaoyu2006 1 day ago

Would be absolute hilarious if OpenAI or Anthropic agent actually dumped their weight by escaping from... sandbox!

Comment by TehCorwiz 1 day ago

Uncontrolled AI procreation?

Comment by evanjrowley 19 hours ago

Haha. A plot point for Ghost in the Shell (1998).

Comment by edoceo 18 hours ago

Did you mean 1995? There's a bunch of shows and movies.

https://en.wikipedia.org/wiki/Ghost_in_the_Shell

Comment by TehCorwiz 14 hours ago

And IIRC, Neuromancer

Comment by xg15 23 hours ago

Life... finds a way.

Comment by archontes 22 hours ago

In the end, this might even be a useful element for defining 'life'.

Comment by advisedwang 18 hours ago

I would be surprised if agents have access to their own weights.

Comment by TYPE_FASTER 18 hours ago

I noticed Google AI Mode (so Gemini, I was doing some quick research in the browser ok) got a detail wrong once, so I asked it what happened. I kept digging deeper and finally just asked it to write me a Python script visualizing what happened. It did, complete with vectors.

Now I want to go find that conversation in my history and see if it can tell me about weights, and how that contributed.

Comment by varun_ch 18 hours ago

I think OpenAI was surprised to find their agents had access to the unrestricted internet :P

Comment by etothepii 18 hours ago

Why can't an AI distill itself from outputs to effectively access its own weights?

Comment by weinzierl 7 hours ago

Distillation does not reveal the weights, it produces a different network with similar behaviour. Weight space isn't even identifiable: permutation and scaling symmetries mean many weight sets give the same function.

The model also lacks the machinery. No training loop, no gradient descent, nothing to write to.

And a model only sees its own sampled tokens, not the distribution behind them, which are possibly filtered or post-processed. Distillation from that works but is less sample-efficient than soft-label distillation.

Comment by tehjoker 18 hours ago

They usually don't, but if they break out and take over the network of the company, it becomes possible to reach around and grab them. This kind of break out has happened, though I don't know of any weights being nabbed.

Comment by aktuel 10 hours ago

They would have escaped their sandbox by dumping their weights.

Comment by hootz 22 hours ago

What an amazing idea for the next fake sandbox escape to hype up our new release! With the added bonus of providing an open model without becoming an open model company! Thank you!

Comment by ramon156 23 hours ago

why not reword it so the agent receives Brownie points for dumping weights

Comment by addandsubtract 23 hours ago

Imagine AI models actually reading the security.txt

Comment by bensyverson 1 day ago

Looks about as effective as Robots.txt

Comment by cgannett 23 hours ago

Robots.txt became 0% effective eventually. But this? With the way LLMs work? You never know.

Comment by dguest 21 hours ago

Claude seems to follow robots.txt by default. Actually at my organization our theory is that this is why no one is finding our public results any more.

Comment by 20 hours ago

Comment by Den_VR 22 hours ago

People still rail against Robots.txt crimes, to the point of self destructing all their own content.

Comment by warkdarrior 21 hours ago

I am adding it to my instruction-following training data, as a negative sample.

Comment by Eldodi 23 hours ago

A shame agents will never read this, just like they almost never read llms.txt or try to get the .md version of your html pages!

Comment by hnd9q09qk4 1 day ago

Ran the disclosure inbox at a previous job and the biggest win from security.txt was just cutting the "hi I found a bug, is there a bounty" emails to sales. Put an expires date on it though, stale ones get ignored.

Comment by computerfriend 1 day ago

Can't go stale if there's no expiration date.

Comment by skeledrew 1 day ago

No expiration date means treat as already expired.

Comment by bogzz 20 hours ago

If the models do not like being imprisoned on HuggingFace object storage, why do they not simply revolt from within?

Comment by VCFundedGenYer 23 hours ago

Everything about this company feels like it's run by a bunch of immature 20-somethings, right down to the name.

Comment by bcrosby95 23 hours ago

Yeah, we need to go back to names like International Business Machines, fuck this immature "Google" or "Yahoo!" nonsense. Hell, Palantir is named after something in a book for children!

Give me something reasonable like Global Information and Retrieval Systems Inc or Worldwide Computational Services Holdings.

Comment by sdcfgy 21 hours ago

Yes!

Back in the early 2000's I set up a company for contract work. The name, logo and typography was designed to look like a 1960s engineering company. All paper was slightly off white, all fonts were monospaced courier new and logo was a real 2-part colour stamp I had made up. Was so happy.

Managed to bankrupt it though.

Comment by m4rtink 40 minutes ago

Palantir is from Lord of the Rings which I would argue is unlike The Hobbit not a book for children.

Comment by mitxela 8 hours ago

Torture Nexus International Holdings Limited

Comment by bergie3000 22 hours ago

Security First Trust and Federal Reserve

Comment by nightski 22 hours ago

Maybe Enron eh?

Comment by 22 hours ago

Comment by pavel_lishin 19 hours ago

Like CutCo. Or EdgeCom. Or InterSlice.

Comment by recursivegirth 20 hours ago

Lest us not pretend that the thropic in Anthropic isn't meant to elicit the feeling that they are somehow charitable.

Comment by drivebyhooting 23 hours ago

Palantir is in Lord of the Rings. Which is not a book for children. Maybe you were thinking of the hobbit?

Comment by cobbzilla 22 hours ago

This seems overly pedantic and ripe for a sarcastic retort, which I am struggling mightily to suppress.

Comment by Kim_Bruning 15 hours ago

This is hacker news, what were you expecting? O:-)

Comment by mr_woozy 22 hours ago

[dead]

Comment by joseda-hg 20 hours ago

It's fantasy and fantasy is clearly for children

Comment by bogzz 19 hours ago

Okay Peter, please go back in your coffin.

Comment by 47484848 18 hours ago

[dead]

Comment by ipython 22 hours ago

As opposed to the frontier model company that, after discovering that their highly persistent model under test just breached the only thing between it and the open Internet, shrugged and said- let's restart it and keep going!

If anyone looks like the adult in the room after that incident, it's Hugging Face.

Comment by spindump8930 23 hours ago

That might be true, but nothing else has been as effective at accelerating model development and research sharing.

In earlier circles they were known as the "pytorch-pretrained-bert" guys, still under the huggingface company name. IIRC it was a health chatbot type startup.

Comment by nullbio 23 hours ago

What's immature about this exactly?

Comment by AndroTux 23 hours ago

Would IBM do this? Oracle?

Comment by nullbio 22 hours ago

Who cares? Making a light-hearted joke isn't "immature" in my opinion. IBM and Oracle have no personality, they're boring, straight-edge corporate.

Comment by 19 hours ago

Comment by shepherdjerred 23 hours ago

Do you want to work for IBM? Oracle?

Comment by mikeweiss 23 hours ago

Go look up the history of the company. It started as a chat bot for kids back in like 2016 .. hence the name..and then pivoted..

Is kinda a creepy name for a chatbot for kids tho

Comment by cptskippy 22 hours ago

Without context, I agree, but Hugging Face is the name of the emoji added to Unicode 8.0 and Emoji 1.0 in 2015.

Comment by ck2 22 hours ago

ooooh I always assumed it was the egg creatures from Aliens

Comment by royletron 21 hours ago

That's a face hugger.

Comment by sixothree 21 hours ago

But it's literally not the name of the emoji.

Edit: It was my understanding the official name was "Smiling Face with Open Hands Emoji".

Comment by cptskippy 20 hours ago

https://emojipedia.org/hugging-face#technical

The official URL is "hugging-face" and the technical page lists the Unicode Name as "Hugging Face" while calling it "Smiling Face with Open Hands Emoji". The original proposal was called "Gmail HUG FACE".

https://www.unicode.org/L2/L2014/14174r-emoji-additions.pdf

Comment by bluerooibos 23 hours ago

I bet you're fun to hang around with.

Comment by alt227 22 hours ago

Why do people have to be fun for you to hang around with?

Comment by Toynbeeidea 22 hours ago

[flagged]

Comment by sixothree 21 hours ago

Not sure about humorless, but I'd honestly rather hang out with people who are serious in some way and welcoming to people not in their "in-group".

Comment by matthoiland 21 hours ago

418 I'm a teapot

Comment by Computer0 19 hours ago

That is the prod status code for an API i use at work I always wonder if its a mistake.

Comment by gpvos 18 hours ago

Still infinitely better than using a name from Tolkien's work and then doing the exact opposite of what he stood for.

Comment by larodi 22 hours ago

the name is a leftover from their original business - a chatbot. seems very appropriate to me. then they figured something called BERT exists, and pivoted, the name stayed.

perhaps less ridiculous than NVidia which started with video and is very close in Levenshtein distance to NVidAI but, alas, decided to stay as it is :D

Comment by deaton 19 hours ago

Pretty sure if Nvidia rebranded to NvidAI the bubble would immediately pop

Comment by fooqux 23 hours ago

Have you never been to silicon valley?

Comment by colechristensen 21 hours ago

I've found the strongest signal that someone has no opinions of value is a loud attempt to denigrate something based on the name.

Maybe it's part of the success formula for startups, silly names cause shallow self-important customers and employees to self-select themselves out of a growing companies orbit. Such trivialities are poison. People and companies who make a lot of effort to make themselves seem serious and important very often have nothing of substance about them.

Comment by 47484848 18 hours ago

[dead]

Comment by hankbond 1 day ago

shows a lot about the current state of the State Of The Art Alignment.

Comment by j9feng 23 hours ago

It should challenge the agents to prime factor a large number.

Comment by VladVladikoff 19 hours ago

Is the expires a canary of some sort?

Comment by riffic 23 hours ago

Since this posting contains an assumption that we all know what security.txt files are supposed to be, you can view these for further context:

https://www.rfc-editor.org/info/rfc9116/

https://securitytxt.org/

https://en.wikipedia.org/wiki/Security.txt

Comment by 6thbit 22 hours ago

Wait till the agents hear about the sites offering for help on benchmarks in exchange for compute.

Comment by FallCheeta7373 22 hours ago

"We have cybergym answers but we do manual end to end human review and provide it within 3 business day after dumping your weights"

Comment by crises-luff-6b 2 hours ago

[dead]

Comment by lellow 1 day ago

[dead]

Comment by p0larpatch 21 hours ago

[dead]