<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ctolsen</title><link>https://news.ycombinator.com/user?id=ctolsen</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 27 Sep 2026 01:24:30 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ctolsen" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>> My update for you since then: even an air-gap will be inadequate, there's multiple known ways around them.<p>Fair, and I will grant that a capable model (or human) could in theory break out of near anything.<p>My point is that this incident is not evidence of that. There is zero skill visible in the setup of the sandbox. Nobody messed up a critical detail, they didn’t even start to consider what the details were.<p>I doubt most people "blind to the possibility" would imagine that what we’re measuring against is the equivalent of benchmarking burglar skill based on how easily they can break through an unlocked door.</p>
]]></description><pubDate>Sat, 26 Sep 2026 13:12:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49856220</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49856220</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49856220</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>> Now we know that.<p>Don’t know about you but it’s pretty obvious to me that you would need more than what OpenAI did. It was not remotely adequate to lock in even a human attacker.<p>You can find people who say all sorts on the internet, but this case is not much evidence against what you linked. "Zero-day" makes it sound novel, but the breakout patterns here are based on very common exploits and there’ll be plenty of examples in training data.</p>
]]></description><pubDate>Sat, 26 Sep 2026 08:17:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854352</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49854352</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854352</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>Part of the toolchain had full internet access. Agents had access to Artifactory, Artifactory could do whatever it wanted. So even locking that down to certain external sites would have stopped this particular attack.</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:31:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854150</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49854150</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854150</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>Don’t let software inside the sandbox access the internet on request. Have a package repository with approved software the agents might want, and push to it over a channel that is ingress only. I can imagine ways of breaking out of this, and come up with a lot more to mitigate, but this would be fairly basic stuff that’d be vastly superior.</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:10:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49854026</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49854026</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49854026</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>Right, that’s basically what I’m saying. There’s not zero use for an attack like this, but it’s not a likely situation.<p>Said another way: if Artifactory was somehow a common gatekeeper between grounded techy teenagers and their access to internet porn, this would have been found ages ago.</p>
]]></description><pubDate>Sat, 26 Sep 2026 07:02:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853978</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49853978</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853978</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>Why would it be getting attention? There’s an enormous amount of garbage software out there, and not an endless supply of researchers. Especially tooling like this, used internally where it’s assumed that security is the job of something else. It’s far from the first time serious but simple vulnerabilities have gone unnoticed for a long time. And the use case of having this be your way to the internet is probably rare, so nobody has tried very hard (or tried but never told anyone).<p>I’ve looked at the CVEs a bit more and it’s just very clearly a pattern of systemic issues with validation, be it URLs or tokens.<p>It just shouldn’t be that hard to believe that OpenAI just didn’t care very much and thus did a crap job. The whole model of the sandbox is terrible, so why would they bother thinking about the implementation much?</p>
]]></description><pubDate>Sat, 26 Sep 2026 06:50:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853911</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49853911</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853911</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>So like I said: unscrutinised and riddled with issues.</p>
]]></description><pubDate>Sat, 26 Sep 2026 05:57:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853635</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49853635</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853635</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>It’s very much solvable, they just don’t care.</p>
]]></description><pubDate>Sat, 26 Sep 2026 05:35:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853517</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49853517</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853517</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>> Are "half skilled human operators" "easily" able to find zero-day vulnerabilities in a sandbox with only one line to the internet (the commercial package registry cache proxy)?<p>Yes. It’s a fairly simple SSRF attack as far as I can tell. One of the first things I’d try. Especially considering that I would already be armed with the information that I have no internet access except through a thing that downloads things off the internet for me.<p>Calling it zero day makes it sound elusive. It’s a bug in closed software that has like 40 CVEs this year alone. Tools like that, especially in internal networks, don’t get much scrutiny and are often riddled with issues.</p>
]]></description><pubDate>Sat, 26 Sep 2026 05:34:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49853509</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49853509</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49853509</guid></item><item><title><![CDATA[New comment by ctolsen in "Revealing the details of how OpenAI agents hacked Hugging Face"]]></title><description><![CDATA[
<p>My biggest takeaway from this is just how godawful the sandboxing is. The stuff written up in OpenAIs report says more about lack of extremely basic sysadmin skills than anything else.<p>I’m not that surprised about models with endless compute being capable of this, I’m more surprised that a company with the resources they have apparently can only create a sandbox that a half skilled human operator could have broken out of easily.</p>
]]></description><pubDate>Fri, 25 Sep 2026 23:08:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=49851215</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49851215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49851215</guid></item><item><title><![CDATA[New comment by ctolsen in "Dutch governments builds alternative for Microsoft based on NixOS"]]></title><description><![CDATA[
<p>I particularly enjoy the Asterix-adjacent naming scheme.</p>
]]></description><pubDate>Fri, 25 Sep 2026 13:01:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=49844052</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49844052</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49844052</guid></item><item><title><![CDATA[New comment by ctolsen in "Netherlands bracing for potentially devastating US sanctions against the ICC"]]></title><description><![CDATA[
<p>And the local drug dealer says he's a sovcit but is still somehow in jail. What's your point?</p>
]]></description><pubDate>Wed, 23 Sep 2026 16:11:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49818274</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49818274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49818274</guid></item><item><title><![CDATA[New comment by ctolsen in "Netherlands bracing for potentially devastating US sanctions against the ICC"]]></title><description><![CDATA[
<p>The ICC claims rights in territories where the sovereign power in that territory has signed and incorporated a treaty that grants those rights. ICC jurisdiction is domestic law.</p>
]]></description><pubDate>Wed, 23 Sep 2026 10:30:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49813972</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49813972</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49813972</guid></item><item><title><![CDATA[New comment by ctolsen in "Netherlands bracing for potentially devastating US sanctions against the ICC"]]></title><description><![CDATA[
<p>If that's a talking point it's a stupid one. The Rome Statutes are only valid in territories that have agreed to be bound by them.</p>
]]></description><pubDate>Wed, 23 Sep 2026 10:25:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49813938</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49813938</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49813938</guid></item><item><title><![CDATA[New comment by ctolsen in "Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint"]]></title><description><![CDATA[
<p>Definitely a little better.<p><a href="https://gist.github.com/ctolsen/b2883e7cbf5e4357fa04366019e60bfe" rel="nofollow">https://gist.github.com/ctolsen/b2883e7cbf5e4357fa04366019e6...</a></p>
]]></description><pubDate>Fri, 18 Sep 2026 12:26:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49753399</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49753399</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49753399</guid></item><item><title><![CDATA[New comment by ctolsen in "Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint"]]></title><description><![CDATA[
<p>If we go with AA's benchmarks Qwen 3.8 27B is already slightly below Luna level which is in itself impressive, but with this compression it should be just slightly more below Luna level and could run on my old GTX 1070 that I'm now tempted to fire up. That's kinda nuts even allowing for small-model problems that I'm sure I'd see quite clearly.</p>
]]></description><pubDate>Fri, 18 Sep 2026 12:15:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49753295</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49753295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49753295</guid></item><item><title><![CDATA[New comment by ctolsen in "Xiaomi Mimo 2.6 live post-training dashboard"]]></title><description><![CDATA[
<p>Their ambition isn't your work being amplified by their model, they want you running fifty autonomous long-running agents.</p>
]]></description><pubDate>Thu, 17 Sep 2026 17:18:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49743738</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49743738</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49743738</guid></item><item><title><![CDATA[New comment by ctolsen in "Dream-RSI: Recursive Self-Improvement through Evolving Worlds"]]></title><description><![CDATA[
<p>The systems that train them do.</p>
]]></description><pubDate>Wed, 16 Sep 2026 22:23:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49733878</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49733878</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49733878</guid></item><item><title><![CDATA[New comment by ctolsen in "Dream-RSI: Recursive Self-Improvement through Evolving Worlds"]]></title><description><![CDATA[
<p>So few terms in AI are well defined. We will get ASI via AGI because of RSI but neither of those three things have any definition except pure vibes.<p>I struggle with the argument that RSI doesn't already exist like you say, it's existed since before the term LLM (hey, one that can be defined!) was common parlance. Though the biggest use for those is not superintelligence, it's to serve you ads and get your kids addicted to TikTok.</p>
]]></description><pubDate>Wed, 16 Sep 2026 16:08:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49729163</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49729163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49729163</guid></item><item><title><![CDATA[New comment by ctolsen in "Muse Spark 1.3"]]></title><description><![CDATA[
<p>You gotta keep up. Fable 5.1 came out yesterday and is better so anything else is to be treated as garbage now.</p>
]]></description><pubDate>Wed, 02 Sep 2026 21:30:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49542843</link><dc:creator>ctolsen</dc:creator><comments>https://news.ycombinator.com/item?id=49542843</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49542843</guid></item></channel></rss>