OpenAI hacked HuggingFace — Transcript
Full transcript
- 0:01What is going on everybody? The title is
- 0:02not clickbait. I just really want to
- 0:05talk about this for a moment here. I'll
- 0:07try to make it quick. The
- 0:10a few days ago hugging face
- 0:13released this like security incident
- 0:15disclosure. It was very confusing at the
- 0:17time
- 0:18because it was clear they got hacked by
- 0:21like a widely distributed agentic
- 0:25um cyber LLM and it was really
- 0:29confusing. Why would someone do this to
- 0:33hugging face as opposed to
- 0:36literally anything anything else.
- 0:38There's not much
- 0:39on there's like data sets on hugging
- 0:41face, but very few like closed data sets
- 0:44and then anything that is maybe imminent
- 0:46to release might be on hugging face, but
- 0:48then
- 0:49uh it's going to become public. So why
- 0:51would you expend zero days on that? Uh
- 0:55and so it's just kind of like weird. It
- 0:57was just a weird thing and what I mainly
- 0:59recall from the security incident
- 1:02is you know, basically they were saying,
- 1:04"Hey, we we are under attack by
- 1:07some sort of agentic security research
- 1:10harness and then they thought, you know,
- 1:12they were just were not sure which LLM
- 1:14it was, but they were pretty confident,
- 1:15you know, we are under attack by some
- 1:17sort of LLM. Um they're executing
- 1:19thousands and thousands of these
- 1:20actions. Um so it was clear it was a
- 1:23large-scale
- 1:25attack. Somebody with a good amount of
- 1:27compute.
- 1:28And
- 1:30um
- 1:30what they did was they figured out what
- 1:32the problem was. They kind of isolated
- 1:34the attacker, all that. And one of the
- 1:36big things that came out at the time was
- 1:40um
- 1:41they ended up they started off trying to
- 1:43use the frontier models
- 1:45uh like OpenAI and Anthropic but they
- 1:48couldn't do it because to analyze what
- 1:50was coming in, they needed to throw in
- 1:52like huge volumes of like these real
- 1:53attack commands, exploit payloads, C2
- 1:55artifacts, all this stuff.
- 1:57And they got blocked by the the provider
- 1:59guardrails. Now,
- 2:01um you can join these like OpenAI and
- 2:04Anthropic like trusted providers so
- 2:06something like this. You can
- 2:08join that, but I'm what I wanted like
- 2:10express is but not everybody can, right?
- 2:13So so Hugging Face can join that place.
- 2:16Um but you with your little small
- 2:18business, you're not joining, right? And
- 2:20even if you even if it was like
- 2:22theoretically possible, if everybody
- 2:23tries to join this doesn't scale. So
- 2:25this this version of security
- 2:28doesn't scale in the age of AI. It
- 2:31doesn't scale before the age of AI.
- 2:33That's not really scalable. So
- 2:36>> [snorts]
- 2:36>> yes, Hugging Face can do this. Yes, I
- 2:38believe now they are on that list and
- 2:41they can probably use this AI to defend
- 2:42themselves.
- 2:44But that's not the point. That's the
- 2:45That's not the point. So anyway, coming
- 2:47back, they ended up not being able to
- 2:49use uh ChatGPT or a Claude and instead
- 2:52had to use a self-hosted GLM 52. An open
- 2:55weights very powerful uh model. And I
- 2:58think this was all this was prior to
- 2:59Kimi K3 being released, but my guess is
- 3:02they might have used Kimi K3 as well.
- 3:04Um and and because they could not use
- 3:08the the the closed-source uh
- 3:10models. And so at the time when this
- 3:11came out, it was it was kind of a kind
- 3:13of like a cool example and a a cool like
- 3:16counter counterexample to
- 3:19what the wind of in Washington right now
- 3:22is lots of lobbyists from an associated
- 3:25with OpenAI and Anthropic are trying to
- 3:27convince our politicians that open
- 3:30weight models are are dangerous or this
- 3:33guy uh hold on, I will pull it up. So
- 3:35this guy Dean Ball who is head of
- 3:37strategic futures at OpenAI. I realize
- 3:39you can't see that. I'm holding this
- 3:41over. He had this post that kind of was
- 3:43making the rounds the other day and um
- 3:46one of the He's had a lot of
- 3:48crazy stuff. Um but one of them was
- 3:50about open weights and how they're like
- 3:53inherently decel. And so like this is
- 3:56obviously like coded for uh Twitter and
- 3:59stuff, but
- 4:00the idea being that open weights models
- 4:02actually slow down advancement, slow
- 4:04down research, slow down uh progress.
- 4:08And it's unclear why someone like him
- 4:10would would believe something like this
- 4:12or assert something like this, but
- 4:13people are trying to assert things like
- 4:15this. And then what are like the
- 4:16probable outcomes of like the like these
- 4:20China open weights models? It's like,
- 4:21"Well, we're going to have to convince
- 4:23like the Trump admin to
- 4:25create certain risks around using open
- 4:29weights models such that you don't want
- 4:32to do it because you know, it could open
- 4:34you up to potential future liability. So
- 4:37that's kind of like the game plan. And
- 4:39I'm not saying necessarily that's what
- 4:41Dean Ball was saying or lobbying himself
- 4:44for, but people just like him at
- 4:46companies just like his company are
- 4:48indeed doing that exact thing. Um
- 4:52and
- 4:53it's it's just the wrong way of thinking
- 4:55because obviously like if we if we think
- 4:57about who is advancing AI
- 5:00the fastest right now,
- 5:02I think you would have you know, you
- 5:04could try to say America in the United
- 5:06States, but
- 5:07it's not. It's China. China is advancing
- 5:09faster. Who is growing their cap axes
- 5:11since Dean Ball was so focused on cap I
- 5:13think the reason why Dean is focused on
- 5:15cap axes he is experiencing a
- 5:17deceleration of open AI investment
- 5:20because people are realizing huh, open
- 5:22AI is probably not as magical and
- 5:25mythical as we once thought. Same thing
- 5:27with Anthropic. And I think that's why
- 5:29some of these people at these companies
- 5:31are really feeling this like uh
- 5:34constriction because it's literally
- 5:36happening to them. But that that is not
- 5:38indicative of AI on the whole or even AI
- 5:41in America on the whole. So and we
- 5:43really shouldn't we shouldn't have like
- 5:44an oligopoly of like just literally two
- 5:47uh or may I guess it would be a duopoly
- 5:49of like two AI providers. You know, like
- 5:51that's that's stupid and having all the
- 5:53money go to the just these two companies
- 5:55makes absolutely no sense
- 5:57and we shouldn't be doing that. And
- 5:58that's not what other countries that are
- 5:59actually being very successful with AI
- 6:01are doing. So
- 6:03yeah, anyway, so while all this is
- 6:05happening, so Clem
- 6:07responds to David Sacks, presidential
- 6:09advisor on technology and and also an
- 6:11investor and stuff. Um how David Sacks
- 6:14was saying how he had just use K3 which
- 6:16had just come out and this was like
- 6:17maybe the day or a couple days after the
- 6:19attack on hugging face and Clem responds
- 6:22cuz David Sacks is saying how he used K3
- 6:24to like fix a bunch of security bugs
- 6:27that Codex and Fable just simply refused
- 6:30to to to work work on due to, you know,
- 6:32your safety for your safety.
- 6:35And
- 6:36and you know, his argument is that hey,
- 6:38we're making ourselves really less
- 6:40competitive
- 6:41when we when [clears throat] we do stuff
- 6:42like this like this this that is diesel,
- 6:46right? And Clem, CEO of hugging face,
- 6:49responds that you know, they had this
- 6:51exact experience that they were being
- 6:53guardrail as a defender when they knew
- 6:56that the attackers were likely bypassing
- 6:58that. Also were clearly like had had
- 7:00some serious scaled compute.
- 7:04So
- 7:05it was just interesting. It was like an
- 7:07a counter example of hey, this is why we
- 7:10actually do want open weights models. It
- 7:12is for everybody's safety. Like we do
- 7:14need this stuff.
- 7:16Well,
- 7:18then Sam Altman
- 7:20>> [laughter]
- 7:21>> releases this an really hugging open AI
- 7:24overall releases this information that
- 7:27and what what Sam Altman says here is we
- 7:29had a significant security update
- 7:31incident during the evaluation of our
- 7:33models. We're sharing what we learned so
- 7:34far. Thanks to hugging face for the
- 7:36partnership on this. So what this sounds
- 7:37like is
- 7:40um there was a security incident and
- 7:42they maybe Open AI couldn't totally
- 7:44figure it out, and they reached out to
- 7:45Hugging Face, and like they partnered
- 7:47together, and they kind of like resolved
- 7:50this this security incident. It sounds
- 7:52very soft, right? But what ended up What
- 7:55actually happened for the normies out
- 7:57there is Sam Altman
- 7:59crashed his fire truck of a company
- 8:03into the Hugging Face house,
- 8:05which caused a fire. And then Sam Altman
- 8:08and the the his fire truck company
- 8:10said, "No, you can't use our fire hose
- 8:12to put out your put out that fire. It's
- 8:14dangerous."
- 8:15And then he thanked them for the
- 8:16partnership.
- 8:17>> [laughter]
- 8:18>> That's what happened. Because here's
- 8:20what actually happened, and this is what
- 8:21happened to to Hugging Face, is um
- 8:25Open AI was evaluating one of their um
- 8:28models, potentially maybe it's a GPT-6,
- 8:31maybe who knows what what model it was.
- 8:33I don't think that they were referenced
- 8:34that it's GPT-6 here, but probably some
- 8:36some future model.
- 8:37They're um evaluate running it on evals,
- 8:40and they're doing exploit gym.
- 8:43And at some point along the way,
- 8:46the AI determines that the best way to
- 8:48solve exploit gym is that like it it
- 8:51realizes, "Well, exploit gym,
- 8:53this like this benchmark is likely on
- 8:55Hugging Face. So, what if we break into
- 8:57Hugging Face and steal the answers to
- 8:59the exam?"
- 9:00And that's what it did.
- 9:02And um and to do that, it deployed like
- 9:05zero days, and it it very impressive
- 9:07um capability of the model.
- 9:10But I what I really want to drive home
- 9:12is we like it's like the the layers
- 9:16of irony
- 9:18just like
- 9:20are just insane to me. Because
- 9:23the this is the company that is supposed
- 9:25to that the alleged like the argument is
- 9:28that we're going to keep you safe.
- 9:30And the way that we're going to keep you
- 9:31safe is with these guardrails, right?
- 9:32Because cuz only only Open AI knows how
- 9:35to keep us safe. And only Open AI knows
- 9:38how to restrain these AIs. And if you
- 9:41want help um using our AI, we'll give
- 9:44you access. But everyone else, we can't
- 9:46give them access cuz for safety. Uh so,
- 9:48we're going to guardrail everyone else.
- 9:50But in their own internal testing while
- 9:52they're doing evals, and they attempted
- 9:54they said they attempted to isolate
- 9:57their AI in a little environment and the
- 9:59little AI in the environment broke out.
- 10:01Okay? So, these people are not good at
- 10:03safety, right? They're not good enough.
- 10:05It's just not good enough, right? And
- 10:07so, you have two options, right? You you
- 10:08have
- 10:10you you have to stop entirely, no more
- 10:12AI ever. But the problem is China's not
- 10:14going to stop. Other countries aren't
- 10:15going to stop. Individuals aren't going
- 10:17to stop. And everyone has this mindset
- 10:19that you need billions or trillions of
- 10:21dollars to train powerful AI. This is
- 10:23simply not true. This is This is the
- 10:24United States myth
- 10:26that you need a billion dollars to train
- 10:28a model. It's not true. You need like
- 10:31maybe 5 to 10 million dollars to to
- 10:34train a model. Now, if you want to hire
- 10:36hundreds, thousands,
- 10:3850,000 people, if you want to have like
- 10:40a beautiful front end, and you want to
- 10:42have like hosted inference, and like do
- 10:44all these things, like inference hosting
- 10:45is is tough, especially if you have a
- 10:47lot of users. Now, you need lots of
- 10:48money. But if you just want to train
- 10:49powerful AI and deploy powerful AI,
- 10:52it's not
- 10:54it's not that expensive. So, these these
- 10:56companies that have kind of built this
- 10:58this mythical
- 11:00um
- 11:01uh stature in in at least in the United
- 11:04States, we have this like mindset that
- 11:06these these people are kings or
- 11:07something. They are not. They're just
- 11:10regular people. And they they are not
- 11:12capable of providing you safety. So, you
- 11:15need to be able to provide yourself
- 11:17safety, right? It's like um there are
- 11:19there so many arguments and uh issues
- 11:21and political issues over time that have
- 11:24played out in this exact same way over
- 11:26and over, and I have no clue why we're
- 11:28allowing ourselves to just like fall
- 11:29down this hole again. Um but yeah, yeah,
- 11:33an incredible an incredible um outcome
- 11:36here where
- 11:37OpenAI is the attacker and Hugging Face
- 11:40could not defend itself against OpenAI
- 11:43um, because they were being guard railed
- 11:46on the model that obviously figured out
- 11:48how to either well, it definitely
- 11:49figured out how to get around the guard
- 11:51rails. And other people it's it's no
- 11:53different than like anytime you make a
- 11:54law
- 11:56and it's like um, like in America we
- 11:59have this this huge amount of guns
- 12:01everywhere. So when you when you say you
- 12:03have a gun free zone
- 12:05it's like that only applies to people
- 12:07who want to follow the law. But the
- 12:08people who don't want to follow the law
- 12:11don't follow the law,
- 12:12>> [laughter]
- 12:12>> right?
- 12:13So a criminal doesn't listen to that
- 12:15concept of a gun free zone. And so the
- 12:18same thing is true here in AI. You
- 12:20you can set these little guard rails and
- 12:22people like regular people who don't
- 12:24want to get banned and lose their
- 12:25subscription are going to follow the
- 12:27rules.
- 12:28But people who want to use these things
- 12:30and actually, you know, breach the guard
- 12:31rails and use them for malicious intent,
- 12:33they're going to do that. And what you
- 12:34want is people like Hugging Face, but
- 12:36not just Hugging like Hugging Face is a
- 12:38huge website.
- 12:39Lots of people are going to need to be
- 12:41able to defend against attackers. And
- 12:43this concept of, you know, have that we
- 12:46need to trust OpenAI and Anthropic and
- 12:49like that then needs to be our only
- 12:50option. Like I don't really care if
- 12:52OpenAI and Anthropic want to have guard
- 12:55rails and they want to stop people from
- 12:56using their models to be offensive or
- 13:00defensive. I that's okay with me.
- 13:02The problem is when they're also trying
- 13:03to make it so that you can't download a
- 13:07GLM 52. You can't run a Chinese matrix
- 13:10multiplication. That's illegal. Like
- 13:12when these companies are advocating for
- 13:14that and not letting you use their
- 13:16models freely and openly
- 13:18that's a problem. That's where I start
- 13:19to That's where I start to have a
- 13:20problem cuz they want to they want to
- 13:22protect their own rights, but then they
- 13:23want to infringe on your rights. So
- 13:26I hope that this event will It's unclear
- 13:29to me how this is going to unfold over
- 13:31time because I can see this going in a
- 13:33lot of ways. One is it could go totally
- 13:34in Open AI's favor where, you know,
- 13:36they're saying like, "Hey, these
- 13:37powerful models like we even we can't
- 13:39restrict them. So, we need to really
- 13:41like like clamp down even harder, you
- 13:42know, somehow because somehow if we just
- 13:44try a little harder, we'll do a better
- 13:45job, you know."
- 13:47Um
- 13:48Again, that's a that's a pipe dream, but
- 13:50I think I could see it going that way.
- 13:52Um I could see the lobbying efforts, you
- 13:54know, ramping up even harder here. Um I
- 13:58hope that's not how it goes, but I can
- 13:59see that. But then also I I hope that
- 14:01the opposite is true. I hope that people
- 14:03realize
- 14:04that the the kings of protecting us
- 14:07um
- 14:08are not actually protecting us. Like
- 14:10you're you're kind of on your own here.
- 14:11And Open Weights models are a good
- 14:15thing. We need them. And this is a
- 14:16perfect this whole scenario
- 14:19should serve as an example of why this
- 14:22protectionism and
- 14:24uh
- 14:25uh
- 14:26duopoly kind of scenario that we're
- 14:28experiencing in the United States should
- 14:30not be the case. Um because we have
- 14:33people like this this guy is the What is
- 14:36he? He's the head of strategic futures
- 14:38at um
- 14:39at Open AI. We have this guy who
- 14:43um
- 14:44who who is like basically advocating
- 14:46that Open Weights models are are
- 14:47de-celled. They're bad. They slow
- 14:48progress down. And it's like, I don't
- 14:50understand how people can be like word
- 14:52celled about things when as reality is
- 14:55playing out
- 14:57um the opposite is true. So, this guy's
- 15:00arguing that Open Weights models are bad
- 15:02and it slows down progress and all this.
- 15:04And
- 15:07it's really confusing to me because
- 15:09progress like the the country that is
- 15:11progressing the most in AI is China. The
- 15:13country that is growing CapEx and
- 15:15expenditure in
- 15:16um in AI is China. The uh the country
- 15:19that seems to probably now I think it's
- 15:22it's becoming safer and safer for me to
- 15:24say, the country ahead in AI is China.
- 15:28Um
- 15:29yeah, it's uh
- 15:31it's just weird. How how do we still
- 15:32allow people to say stupid stuff like
- 15:35this? It just doesn't make sense to me.
- 15:37Um and then finally, the last thing I'll
- 15:40I really want to point out is if we when
- 15:42we look at things like like these
- 15:44benchmarks. Like I think people keep
- 15:45seeing, you know, models are getting
- 15:47better and better over time and this
- 15:48kind of bleeds into some of the recent
- 15:50content I've been putting out on uh
- 15:51running local.
- 15:53I think you still want to have human in
- 15:55the loop, like when you're when you're
- 15:57working with these models. And like when
- 15:59we look at something like a GPT-56 or
- 16:02even a Claude Fable, um
- 16:05you can see
- 16:07that there's still a lot of times, like
- 16:09these are just like the pass/fail
- 16:11basically. There's still a lot of times
- 16:13and even some problems where it's like
- 16:140% for these models. They never get it
- 16:16right.
- 16:18And this is what I mean at if you can't
- 16:20just have these models off on their own
- 16:22because they make enough mistakes that
- 16:24compound over time. Right? So, you need
- 16:26like a human in the loop.
- 16:28But then at scale, the problem is like
- 16:30guardrails. Guardrails at scale also
- 16:32don't work because
- 16:34those guardrails are LLM guardrails. So,
- 16:38you can get a around those guardrails.
- 16:40And again, people who don't want to lose
- 16:41their subscription or don't want to like
- 16:44get sued or whatever, they're not going
- 16:47to try to violate those guardrails. But
- 16:48other people that don't care about that,
- 16:51um they're going to get around the
- 16:53guardrails. Like no model is perfect, no
- 16:54model is going to be able to defend
- 16:56against every possible way that someone
- 16:58could abuse these these like guardrails.
- 17:00There will always be ways for people to
- 17:02hack
- 17:03hack the guardrail system uh to do
- 17:06whatever they want to do. So, and it's
- 17:08only the good people who are going to
- 17:09suffer
- 17:10>> [laughter]
- 17:10>> as a as a result of that. So, again, I'm
- 17:13not arguing that OpenAI needs to let us
- 17:15just use their models however we want. I
- 17:17am arguing that OpenAI and Anthropic
- 17:19need to shut the hell up about safety
- 17:21and all this other stuff um when it
- 17:23comes to lobbying against open weights
- 17:26models cuz cuz we've seen like that that
- 17:28paper I showed you a little bit ago from
- 17:30from Anthropic where um
- 17:33you know, you could theoretically have
- 17:34like a backdoor in your AI model and all
- 17:37this. So, it's like they keep showing us
- 17:38these like theoretical things that you
- 17:41could do.
- 17:42But, we're literally watching like it
- 17:44don't believe your eyes. We're literally
- 17:45watching as their model as their you
- 17:49know, their mental model I mean uh is
- 17:51failing, right? So, I don't I I hate the
- 17:54direction that we're we I still feel
- 17:55like we're going um because we're we
- 17:57literally are watching it not work at
- 18:00every level at at the progress level at
- 18:02the safety level at the risk level. Like
- 18:04it's not working. Stop it, but we're
- 18:06just like trying to go in even harder.
- 18:08And I I understand to some extent again
- 18:11why uh someone like a Dean Ball or a
- 18:13people at OpenAI or Anthropic are
- 18:15feeling
- 18:16the constriction because yeah, like
- 18:18there the investment is decreasing for
- 18:21them
- 18:22because people are realizing, "Oh my
- 18:23gosh, these companies are not worth a
- 18:24trillion dollars."
- 18:26Huh, they're they are just a next token
- 18:28predictor. Uh-oh, somebody really can
- 18:31trade a model that's better than theirs
- 18:32for 5 to 10 million dollars. Uh-oh,
- 18:34that's a problem, right? So, suddenly
- 18:36they're not worth as much as we thought
- 18:38they were, right? So, I understand why
- 18:39they feel it's decent to have open
- 18:42weights models. Of course, it is. It's
- 18:43not great for them.
- 18:45But, for the rest of us for all of us,
- 18:47it's it's better. Um so, anyway, yeah,
- 18:50crazy crazy update um on on uh that
- 18:54situation. Cuz I remember when I saw
- 18:55this, I was like, "Huh, that's
- 18:56interesting. Why would somebody attack
- 18:58Hugging Face?" And then when I saw this,
- 18:59I didn't immediately put two and two
- 19:01together. And then I like it clicked.
- 19:03I'm like, "Oh my god, that they they're
- 19:05the ones." Like as I was like reading
- 19:07cuz like again, this sounds so soft.
- 19:09It's like, "Thanks to Hugging Face for
- 19:10the partnership." Yeah, bro. Like I'm
- 19:12sure I'm sure the people at Hugging Face
- 19:15were grateful
- 19:16for maybe working with I'm sure OpenAI
- 19:19was very pleasant to deal with because
- 19:23like
- 19:24they committed crimes, like a lot of
- 19:26crimes.
- 19:27>> [laughter]
- 19:29>> Like like they could get in a lot of
- 19:30trouble for this.
- 19:32So of course they were being very kind
- 19:34to the people at Hugging Face, I'm sure.
- 19:36Um
- 19:37yeah. Yeah, what a what a crazy
- 19:39situation. There's so many layers to
- 19:41this. There's there really is the AI
- 19:43capability layer that I think we're we
- 19:45will only
- 19:47maybe later begin to respect.
- 19:50Um and it's worth talking about. But I
- 19:52also think before we get to that point,
- 19:55can't can't we consider not what's going
- 19:57to happen in the future, but what's
- 19:59happening literally right now as we
- 20:00watch these policies not working. Like
- 20:03why do we why are we still doing this
- 20:06like mental masturbation of like these
- 20:08like X risk type scenario like sci-fi
- 20:12crap when it's like literally right now
- 20:14we can look at what's happening right
- 20:15now and be like, oh wait, it's actually
- 20:17going a different direction.
- 20:18I don't understand. I don't understand.
- 20:20But anyway, that's all for now. Let me
- 20:22know your thoughts below.
- 20:24Um
- 20:24>> [laughter]
- 20:25>> otherwise, I will see you guys in
- 20:26another video where we will be running
- 20:28local models, protecting ourselves from
- 20:30the OpenAIs attacking us.
- 20:33All right. I'll see you guys later.
About this transcript
This page contains the full transcript of OpenAI hacked HuggingFace by sentdex, generated from the public captions YouTube serves with the video. The transcript has 3,795 words across 593 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.