Self-hosting, data sovereignty and cyberattacks [AIT]

lemmy.world/post/49736885

If you follow AI news at all as part of your self-hosting interests, you may have become aware recently that open AI (the frontier lab between behind chat GPT) has admitted (loosely) culpability in an cyber attack against HuggingFace (the major repository of open-weight models.)

The details that present are somewhat sketchy, but the gist of it is that open AI seems to have given unrestricted access to a AI agent, which then attacked hugging face, who in a twist of deliciousness, used an open source agent to defend themselves.

I’d joke and tell you to make sure that you haven’t left any open ports on your router, but if you’re here reading this I think probably you know better than that.

Less comically, there’s a weird intersection here between self-hosting, sovereignty and encroachment by big tech that is worth pay attention to.

It should certainly spur people on to seriously consider self-hosting as much of their infrastructure as they can (and securing it) if this is the preview of things to come.

Something is rotten in the state of Denmark.

I just wish I’d bought more SSDs.

lemmy.worldOpenAI admits responsibility for HuggingFace Attack - an agent from an internal evaluation is reportedly the cause - Lemmy.WorldReproducing here an interesting comment I saw on Reddit: > OnlineParacosm • 23m ago > > I’ve read security disclosures for 15 years and let me tell you guys I’ve never read anything quite like that blog post. > > Based on this blog, it sounds like they intentionally turned off safety guardrails to test offensive capabilities. The deception here is burying the lede: they appear to have intentionally unleashed an unrestricted offensive cyber-agent, connected it to a system with a path to the internet, and it immediately attacked a major partner. The blog glosses over the gross negligence of giving an autonomous, unrestricted cyber-offense model a pathway to lateral movement. > > There’s an entire cybersecurity specialization just for just vendor supply chain risk assessment, and their job is essentially to audit who you do business with as a company to determine if they are jokers. I would pay money to be a fly on the wall of one of those emergency meetings taking place right now after h

Replying to @⁨SuspiciousCarrot78@aussie.zone⁩

What does self hosting look like in a world full of malicious AI agents?

I’m thinking of this post/thread from Veronica explains, where she explains that her hosted services are accessible only locally because tbe security headache isn’t worth it: explains.social/…/01KWJCGV27JVBHP21E2JNWDBFH

As someone who doesn’t self-host but could and would want to, the state of AI has basically scared me off.

explains.socialVeronica Explains (@veronica@explains.social)Literally every service available outside the firewall is a vulnerability waiting for exploitation. And I like sleeping at night more than I like having access to my media libraries when I'm on vacation.
en