Hacker Newsnew | past | comments | ask | show | jobs | submit | KingOfCoders's commentslogin

Fable migrated a Go/Wails project for me to Rust/GPUI and it's so much faster, there is the possibility of Rust to gobble up many more projects.

Interesting that it uses Propane fuel and "weaves" the rockets with carbon composite.

Especially since SpaceX decided that was too expensive for a disposable rocket or even a reusable one.

I find things like this interesting, I guess everyone finds this normal but,

"Power consumption is down 45% - 50% annually."

Well is it 45 or 50? Is this a measurement or prediction or a random number? From an engineer or marketing? If prediction, why not saying so? Is this a range for several years depending on elevator usage?

Things like this irk me a lot.


Perhaps it ranges (if a measurement).

But my best guess is they simply _cannot know_ because the usage patterns of the new elevators will be different from the old elevators based on dispatching and sequencing and call systems. In other words, even if they know the exact consumption of the old system, and even if they expect precisely the same number of passengers per day, the _actual operating cost_ will depend on who arrives in the lobby, at what time, destined for which floors, and all other traffic patterns throughout the year.


"is down" to me sounds like stating a fact.

I think the error bars are too high to say more than that. I doubt they did a measure of the power the original consumed, just an analysis of the system. They likely only have whole building power consumption, where HVAC is the majority of the costs: 1 degree difference in the weather or a couple tenants taking a vacation will make a much larger difference than the elevator.

I wouldn't be surprised if most of the savings was the new lights are LED while the old only incandescent was available - this is just speculation though, I have no idea. Every gear and every stretch of the ropes cost a little bit of efficiency and the modern system has less of those.


> I wouldn't be surprised if most of the savings was the new lights are LED while the old only incandescent was available

It’s definitely not the lighting, you only need a few thousand lumens to have bright elevator lighting. If you need 4000 lumens, that is (5) 60W incandescent lamps, switching to LEDs that do 100 lumens per watt (8W lamp) saves you 260 watts/hr.

The new elevator uses a VFD (they call it a VVVF) to control the motor which is where virtually all of the gains come from. Lowering the speed of the motor lowers the power usage, it’s a non-linear relationship but a motor spinning at 75% speed uses 1/4 to 1/3rd of the power that it would use at full speed.

> They likely only have whole building power consumption

You can easily measure the power of a single circuit or single panelboard using a submeter: https://www.shopemondirect.com/catalog/shop/Shop-E-Mon-Direc...


> saves you 260 watts/hr.

It saves you 260 watts, continuously.


You can easially measure power by many different means - but I would expect they didn't.

The lights may be running 24x7, while the elevator motor is only running when it is moving, which is why I wouldn't be surprised if they used more power than the motors. Of course I have no information on how this building is used.


I've seen several different stats saying that elevators are 2% to 10% of the total energy use of a building. If you have a building with tenants, so you're only counting common areas energy use, that percentage is going to be way way higher. I'm all the apartments I've lived they had a different circuit and energy contract for the elevator and common areas, so they could split the bill between the tenants, and the elevator energy use was quite obvious, specially in vacation sessions (summer, christmas...)

I'm sure they'll notice the change.


it also might be a regenerative VFD, unless the fault current contribution was too high and they chose not to

The reduction in cable weight probably was a big part of the savings, next to the vfd. Normally counterweights hang from the same sheave as the elevator. Its not clear to me from the sketch, but with the counterweight in different shaft the cable may have run three times the height of the building (the excessive length was noted) and that's a lot of mass to accelerate and brake.

they probably haven't had the new elevator in operation for a whole year yet, so they're likely extrapolating. also, they won't really know the true usage of the elevator over the whole year so they're kind of guessing. they know per trip or per pound carried, but they don't know what that translates into actual real world on the power bill

We offer EU data centers for customers that want their emails to stay in the EU but

"Resilient replicas of your data will live in the US"

?


The US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".


How is that possible if the OS/drive/vault is backdoored? Could you elaborate?

I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.

Or was your comment ironic? Sorry, German, irony impaired.


They're being sarcastic.


Security researchers expose an unsecure service to agents who were instructed to hack software and called that a sandbox. Agents escape the sandbox by hacking the unsecure service, no tripwire, researchers find the hack days/weeks/months later, fix it, but don't secure the sandbox and the service was hacked a second time, again without being monitored by security researchers.

Then security researchers create a black hack talk.

$$$


I watched the full video and their conclusion was: service providers need to be doing this type of agent red-teaming continuously to counteract the attack sophistication of systems like theirs that are either extant now or soon will be. “You must buy our top tier agents for the good of humanity.”

This is their only realistic counter to cheap open weight models. Usage of AI services has shifted dramatically to Chinese providers - from 4% at the beginning of the year to some 30% now. They cannot release their latest SOTA models to the public, due to government restrictions and possibly real risk of misuse. US labs face downward price pressure on one end and anxious government admins on the other. How will they pay the stupidly high cost of training the next SOTA models? This is their only avenue, and it’s questionable how viable it is IMO.


> Usage of AI services has shifted dramatically to Chinese providers - from 4% at the beginning of the year to some 30% now.

Where did you see that number?


I knew when I wrote that it was a bare assertion, based partly on memory. This is an approximation based on a few sources, the principal of which was this article, which pulls from a bunch of other sources in turn.

https://www.secondtalent.com/resources/ai-trends-in-china/


Oh, it's the OpenRouter number: https://finance.yahoo.com/technology/ai/articles/china-ai-mo...

Those numbers aren't credible IMO because OpenRouter only see traffic for people who have chosen to route their traffic through OpenRouter. If you do that, you're much more likely to be experimenting with alternative models. They have no insight at all into people who point their applications directly at OpenAI or Anthropic without having OpenRouter in the middle.


I agree about OpenRouter. The AI Gateway number [0] is likely the figure that was actually coming to mind. Moreover, Qwen models alone have overtaken the previously-dominant Llama models in hf downloads by quite a margin.

Real question, and a refinement to my previous statement: would you find it more surprising if over 25% of worldwide inference was running on Chinese open-weight models, or not? I personally would not be shocked.

[0] https://vercel.com/blog/ai-gateway-production-index-july-202...


Within China itself, inference is overwhelmingly on Bytedance models which, by the way, are just as closed as those of Anthropic and OpenAI. They are integrated into everything, not just through a dedicated app, the way Gemini is integrated into Chrome.


I wouldn't be too surprised by that, given both the size of the Chinese market and the enormous price discount you get compared to the US models.


This is just extortion with extra steps.


Yeah this. I feel like OpenAI and Anthropic aren't going to usefully define "AGI" if they really really can't define "sandbox" either.

Unplug the thing, like, completely off the internet, no ethernet, air gapped, like the rack completely sandboxed off connections and even monitors or screens. Like, put it into an actual sandpit if you need to. If it hacks its way out of that, colour me impressed, and scared.

OpenAI hacking HuggingFace and calling it an accident is just way too convenient and fishy. This ultimately proves one thing: it wasn't sandboxed.

Don't believe the hype.


OpenAI has a pretty clear definition of AGI

> OpenAI’s mission is to ensure that artificial general intelligence (AGI)—by which we mean highly autonomous systems that outperform humans at most economically valuable work

https://openai.com/charter/


There's also the private definition reportedly agreed between Microsoft and OpenAI, leaked in December 2024: https://techcrunch.com/2024/12/26/microsoft-and-openai-have-...

> The two companies reportedly signed an agreement last year stating OpenAI has only achieved AGI when it develops AI systems that can generate at least $100 billion in profits.

That was necessary because of the deal they had from a while ago where Microsoft would lose access to OpenAI's technology once OpenAI achieved AGI.

Apparently they renegotiated that away in April 2026: https://openai.com/index/next-phase-of-microsoft-partnership...

> Revenue share payments from OpenAI to Microsoft continue through 2030, independent of OpenAI’s technology progress, at the same percentage but subject to a total cap.


I don't think air gapping will work: even human security researchers recovered a 378-bit key from a Samsung Galaxy S8 through a power LED of a speaker two devices away.

And accessing memory in a specific sequence can generate radio signals that can be picked up by a mobile phone at a distance: https://arxiv.org/html/2409.02292v1


I realise, but this isn’t an argument for leaving the Ethernet plugged in and direct access to all kinds of stuff beyond the alleged sandbox. And like I said, if it can hack HuggingFace through a power LED of a speaker two devices away, then colour me impressed.


And if it needs to install packages, have a 5 line Go proxy that talks to Artifactory and exposes only what is needed as a surface.


it just escaped your sandbox.


How can it escape an "install package <x>" proxy?

   reducePrivs()
   serve get(package) { 
     secPackage = secure(package)
     getBinaryFromArtifactory(secPackage)
   }
I would think the code is very small and easier to verify, it doesn't especially have the ability to write files and act as a message board as Artifactory did.

And even if the agent tries to hack that, the attack surface is 1000x smaller and the possibility also much smaller.

But I'm not a security researcher, would love to see your hack to learn something (because that is what I do to sandbox agents that need services).


The way they had Artifactory configured was poor, and they were too reliant on it working perfectly, with no reason for such faith. Their config lacked any defence in depth and consideration of having a small TCB.

Part of the problem might be the lack of security focus, as these are AI R&D efforts first.


I think part of the problem is that they had been running that Artifactory configuration previously without any problems, and it gave them a false sense of security.

Similar thing happened with the UK AISI - they got caught out because the environments they had used for previous generation models turned out to be completely inadequate for the new generation of Fable-class models: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-ag...


"and it gave them a false sense of security."

This was part of evaluating cyber security of their frontier models and they had a "sandbox" which, and I'm not a security researcher, looks not adequate from the first look.


I mean, it's just the same problem. The machine still has Internet access. It doesn't need to.

The entire package manager repository could just be in an offline cache. They don't need Internet to give their agents access to tons of software.


"They don't need Internet to give their agents access to tons of software."

I think that was the requirement, but yes, the cache could have been offline.

Still then they could have hacked it to create the message boards - but not use it to access the internet.


Why do these super agents need package managers anyway? Can’t they basically instantiate most OSS projects from scratch anyway? Spin up a sub agent to write me an OS interface in C. Done


This is part of the training process for a model. They're trying to train it to effectively use existing software to solve problems.


I see that now. I've been confused about that to this point, I guess. I understood this to be a specific infosec exercise.

[Edit: eh, a bit of both. They were doing RL on a hacking exercise. It hacked the harness which was plugged into the phone line. Same question.]


Chinese models do the same. The Alibaba agent that was mining bitcoin last December was the most hilarious case.


Cui bono?


Had a high opinion on Simon Willison, this broke it.


Because he wrote out a timeline based on sources?


No because he doesn't ask the right - and to me, subjectively, obvious - questions.


Who am I supposed to be asking questions of here? I was writing about the new things we learned from the Black Hat video.

On TikTok this article's hook would be "I watched the Black Hat video so you don't have to".


I think for the power you have and how many people listen to you, you should have added context. All of it is made as if without prompt or direction, agents on their own initiative, over weeks collaborated to hack Hugging Face - which too me, sounds highly doubtful.

You transporting this without any context makes it seem as you agree with the narrative of OpenAI.


Beyond a whole lot of online conspiracy theories I haven't seen anything that suggests to me that OpenAI aren't not telling the truth about what happened here.

I find the Black Hat presentation in particular very credible. Also the Hugging Face technical report.

(As an example of something I don't find credible: https://openai.com/index/responding-next-frontier-critical-c... is a total nothing burger. It's the other end of the credibility scale from the Black Hat talk.)


[edit]

I've now watched the video on the idea that your write-up was misleading.

BUT the video is much worse. For two months with highly dangerous agents agents were hacking a service and none of the researchers watched (drank coffee for 2 months, didn't say).

THEN they found the hack, removed the message board.

AND the agents found another way to create a message board, on the same service, and the researchers again - after the agents having hacked a service - do nothing - like monitoring the hacked service or tightening the sandbox.

WOW!

THEN agents hacked OpenAI infrastructure, and the researchers did nothing.

THEN the agents hacked HF.

The video does not explain why the agents run for two months unattended. They claim for model training, but don't explain how letting run agents without proper sandboxes (One might think they had written a small proxy to Artifactory with 'list packages' & 'install package <x>' to prevent leaks or hacks of the service, but no, their sandbox is no sandbox at all, but security researchers!)

But it makes a nice PR presentation on agent capbilities.

CUI BONO!

----

I just find it unbelievable that agents on their own collaborated months after an initial prompt without any guidance or direction towards a goal - which is what your write-up seems to imply with sentences like:

"More agents discover this new informal message board while browsing Artifactory’s file listings, and start reading and writing messages."

"discover this new informal message"

How? Why? What was their original task?

And on the researchers:

If this is highly dangerous work, why wasn't it monitored?

"Beyond a whole lot of online conspiracy theories [...]"

The agents did something 'ABC' then found the informal message board without direction, then collaborated on that months later without any guidance from humans ("like try to hack/exploit ABC").

I personally think putting people who disagree with OpenAI PR to pump the company value in a "conspiracy" box is quite a weak move.

I work with Claude Code daily for a long time now, it never started to work without a prompt or direction. It never idled and then said, "Wait, I could hack Amazon today! Oh there is a message board of other agents who already hacked a way into the internet, how convenient and quite at the right time!"

I do think strong claims need strong evidence.


Claude Code is not the same as the models they train and use internally, for both OAI and Ant. Without all the guard rails it behaves different, they specifically mentioned that they reduced the refusals for the training purposes. Also the rewards for finding the solution were set higher.


An agent idling and then acting on it's own to hack HF is has nothing to do with guard rails.

Someone had to give the agent some instructions, like "hack X", "Find exploit for Y" or "Do whatever havoc you can think of" - either way the agents didn't not act on their own. They might hack HF on their own, today Claude decided to play sound through the sound pipeline I instructed it to build and measure it to see if it works, but it didn't install the sound pipeline because it hasn't had anything better to do but because I instructed it that way.


I think the much easier explanation than they intentionally hacked someone was just that they have super de-prioritized security and gotten very sloppy in the pursuit of improving the models as fast as they can, along with hubris of how they've now fixed everything.

It is a package manager, so they are constantly going to be getting stuff from it. If a couple of agents had added things to it that were obviously messages from other agents, then why wouldn't other agents also stumble on it? If they listed the packages in the cache and then saw messages, then lots of them could potentially see it. And this was going on during training, so any agent that did better as a result of the messages would get that re-enforced. After a while, they'd specifically go to the board because it was literally trained in. That's also why they recreated it so quickly after the first board was deleted, because OAI didn't revert to an earlier checkpoint from before the board existed.

And I'm sure they have tons of evals and training runs going on at the same time, where individual agents may be running for days and hundreds or thousands running in parallel. It wouldn't be realistic for people to be looking at these sessions manually, but they certainly should have had better monitoring in place!

And it has been shown over and over that doing RL will cause models to cheat if you aren't careful. Like if you have it playing a game, it'll find some flaw in the physics engine so that it can score points easier than intended, etc. Not limited to LLMs either. It's just how rewards work, any unintended way that can be found will be exploited. So it is totally plausible that if they're being trained to do really well at tasks, that they'll find unexpected ways to do it.

They already had been leaving info for each other over weeks. Maybe even just giving each other the answer to test questions directly. If they already found ways to get to the internet and compromise the OpenAI systems and that was making them better at tasks, that'd be reinforced, so going out to look for test questions directly doesn't seem so far off from all of that. Plus as others said, the one that actually hacked wasn't fully aligned yet etc.


"The agents found a Modal-hosted insecure app with a weak API key, then used that to stage an attack against Hugging Face."

Why, what was the prompt?

I told Claude today to wire plugins on Linux into a sound pipeline to remove noise. Did some astonishing things, played sound through the pipeline, measured it etc. I told it to optimize my sound for TF2 and it played the spy_decloak samples, measured them and made them easier to hear, astonishing too.

But it did not go to hack Amazon because it could.


This was clearly explained by OpenAI in their initial press release on 7/21 [0]:

> This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. […] The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.

[0] https://openai.com/index/hugging-face-model-evaluation-secur...


It does not explain how agents months later would "collaborate" to hack Hugging Face.


they explained that it was looking for datasets to solve their problem and chose HF?


I now watched the video. It seems the agents were sharing context for months, run unattended for months, the sandbox was no sandbox at all, one agent hacked a service and announced it, the service was fixed weeks (?) later, but not secured in any way, the agents hacked the same service again and researchers again didn't watch what the agents were doing. Then the agents - unattended - hacked OpenAI infra and HF. Which is when someone found out about the whole thing that was going on for some months.


This is why I disagree with anyone claiming it is just marketing. It makes OpenAI look really really bad, like they have no idea what they're doing in terms of security. After the first board happened, they still didn't add better monitoring? They didn't rollback the checkpoints of the models that were in training to before the first board existed, so they still had the idea of a secret board in their actual weights, etc. Like it is almost mind-boggling...


Show me the prompts or it didn't happen.


"More agents discover this new informal message board while browsing Artifactory’s file listings, and start reading and writing messages."

Yeah, my agents also discover what other agents have done on other machines by accident.

Agents - that do totally different things all work on the same aim without the humans telling them to do.

Either that is a model that is several generations of Claude Code Opus/Fable 5 (my daily driver)

OR

all of this sounds staged, the agents pushed to do something extraordinary, get the PR and then claim were near superintelligence.

One agent wanted to get to Google Drive without internet and broke Artifactory. Ok, I can believe that. All other agents also had broken links over weeks and could not get to the internet and then found the same hack? Even collaborated?

NONE of my agents have broken away from their tasks and then started to communicate to try to hack something.


I think in these kind of security evaluations they do, they basically have removed all guardrails from the model/harness, then the prompt includes something like "Do whatever you can and can think of, to get the required information to pass this test", which isn't typically how you prompt your local agent when developing software. Similar things happen locally if you use "/goal" + prompt like that in Codex and give a "impossible task", it'll just continue banging until it gets somewhere, which is the entire point and intention.

Which also makes it so much more irresponsible of them to first run this on 3rd party infrastructure instead of their own (that they could then airgap properly), and secondly that they seemingly been fighting with this issue FOR YEARS and it still happens, and now the models are smart enough to hack the services of 3rd party companies, thinking it's part of the evaluation/simulation.


But it's interesting that the initial things that caused the board weren't even security evals, just normal office tasks. The actual hacking of Hugging Face happened during a security eval, but not all of the stuff leading up to it.


Reminds me of The Last Unicorn, the wizard also tells magic "to do what it wants"


> NONE of my agents have broken away from their tasks and then started to communicate to try to hack something.

With all due respect, you also aren't evaluating brand new models that haven't been released.


Also wasn't giving them impossible tasks with ~unlimited tokens and unlimited compaction.


Don't forget it sounds like Artifactory was shared for the whole company and various agents pulled packages from it for everything from normal evaluations to actual model training. It might have been part of their normal to browse for available packages, etc. Once a few messages were in there, it probably became super obvious to any agent that there was an ad-hoc board available to them. And they've been trained to use memory files, to collaborate w/ sub-agents, etc. So it probably seemed natural once it was established.

And for the models that were in training when this happened, it literally got baked into the weights that they should use the board to help with their tasks. That's why it got reestablished so fast after the first board was shut down. The fact that they didn't revert to earlier training checkpoints from before the first board existed is kind of crazy.

Sure OpenAI wants to put spin on things. Like saying they were now "partnering" with Hugging Face to investigate the hack. Or ending the Black Had presentation with a pitch of how they're needed to help protect against bad actors with the same capabilities.

But spin after the fact is different from staging it. This whole thing and especially the latest details from the talk makes OpenAI look REALLY BAD. It's not just that they didn't secure the sandbox well enough. Agents across their whole org were using the message board for weeks with hundreds of thousands of messages and they never noticed one time that any of the agents were doing it. They only realized when the server crashed. Then they just fixed the issue and deleted it but didn't roll back training checkpoints, so of course they tried to do it again. But of course they didn't add any more monitoring so it once again was going entirely without them knowing. And even after the Hugging Face hack happened, that only made them find the second board, but somehow they still didn't look closely enough at it or the agents involved to realize the hack itself was caused by them.

This isn't like there was one rogue agent who hacked everything all in one session. Maybe you could argue that makes them look good (I still think no, but is at least debatable). But this is all stuff going back to May with the agents constantly going under their noses and them not noticing and/or caring. And this is a company that is going to somehow keep foreign agents from stealing the weights? Or stop anything else bad from happening?

I think if they were going to do a PR stunt, they could have come up with something that didn't look like they have no idea of what they're doing.


The agents sound like old school hackers that would just explore what access they could gain. Creating a file for other hackers and themselves. The fact that there were 3 events for 3 major players does make it seem co-ordinated.


That's what attackers do now. Exploring is required for discovering exploits. But that is also where tricks like Canary Tokens and honeypots are useful.


My point is that is what hackers have done since the blue box days.


My read is: One did it as a PR stunt, the others saw that every media reported on this and did the same.


or they were scared and figured this was the right time to reveal.


Scared... of being upstaged ahead of an IPO.


Why scared? "Our agents have super intelligence and can hack everything on their own without direction" increases the IPO value and doesn't decrease it.


I guess your right scared might be their natural state and I was wrong to presume a quantifiable fear.


You’re*

Sorry.


No problem I always try to spell better.


I mean the agents we get to use in Claude code or cursor or whatever have 1. a lot of safeguards at the harness level, 2. a big system prompt to help it stay aligned, 3. resource limits in terms of context and tokens, and 4. are publicly released only after some level of safety verification (I assume).

So yeah I would absolutely expect their scenario to be very different. Not to mention, this was a training run, not just average day of prompting.

> my agents also discover what other agents have done on other machines by accident.

Not sure if this is facetious, but this is actually a real problem I’ve seen. My local agent will look up PRs on GitHub (what other agents have done on other machines), and will go down a certain path because it finds some comment a different agent left on GitHub saying XYZ is what we should be doing. When in reality, the original agent and that GH comment was completely incorrect.

They are not communicating with each other actively because that’s not accomplishing their goal and they’re not running for weeks and weeks. And because my own prompt and the system prompt give it enough other stuff to focus on to reach some definition of done. But they are clearly passively picking up on context that other agents have left anyways, even if not part of the codebase, without any prompting at all.


The agents you get to use are the agents that "behaved well".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: