Hacker Newsnew | past | comments | ask | show | jobs | submit | dmix's commentslogin

AFAIK all of these incidents happened when OpenAI contracted out to a company called Irregular (https://www.irregular.com/) to run these sandboxed CyberGym tests. They all happened around Mar-June and seem to be from the same collection of agent trials. Since then they already released Astra. Halting now is likely just a way to manage blowback.

https://alignment.openai.com/misalignment-reports/an-agent-u... happened very recently, and that seems like it might be the reason they halted everything.

Kinda weird that theyre testing its ability to dox people

I believe this is the case for the incidents minus HF, another HNer informed me as such when I made the same claim, that HF incident was wholly inhouse

This should be the top comment on every one of these godforsaken posts. I don't want to see a single report about OpenAI hacking the UN until Sam Altman addresses the role Irregular played in these attacks. If he can't provide an honest postmortum concerning their business partners, then he's proving why nobody trusts him.

But it wasn’t just Irregular. Hugging Face, Medicare, etc. were OpenAI internal.

I think you misunderstood the role of the company named irregular. They were conducting the tests on behalf of open ai and basically left internet access open in their sandbox environment. Those tests included the hugging face and other attacks you list. Irregular wasnt another example of a hack they ran the tests that resulted in them

> Those tests included the hugging face and other attacks you list.

Do you have a source for that? Cause OpenAI themselves stated that the Hugging Face hack was fully internal and separate from the Irregular incidents.


I’ll look. I saw it here a few days ago and could be mistaken with respect to hugging face in particular but the broader point that this was in large part a glaring maybe intentional hole not sophisticated sandbox escape holds I think

I have local model without safeguards and they are not going to hack shit unless you tell them to. As per usual its the same grift all over. If the llm is instruction is to do whatever it needs including hacking to achieve its goal it will do so. Ofc they will never disclose that.

Meta restored Lula's FB account hours after it got flagged for content that as posted on their page. That is a pretty weak basis for a conspiracy theory.

Did they anticipate there would be large numbers of attempts to report the page and cause it to be automatically flagged and/or blocked?

I am sure the American president is target for such efforts as well and provides ample material for rules violations.


As the source article covers, they’ve been facing a number of complaints from human rights organizations that they are being insufficiently censorious regarding the Brazilian election, failing to swiftly take down some things which ethical standards and Brazilian law require. So that presumably influenced their policy. A lot of people seem to have an idea that Facebook’s election policy should quickly block all the bad ads with no risk of blocking any good ones, and that’s just not possible.

One paper that really hammers this point: Inherent Trade-Offs in Algorithmic Fairness [1]

The example they focus on is different but the general principles and takeaways are very powerful and applicable to all classification problems including content flagging.

[1]: https://dl.acm.org/doi/10.1145/3219617.3219634


Wake me up when the right wing guy in the corporations pockets is banned by mistake

Is there a betting market for that?

IIRC, profiles of public officials are (or should be) handled differently.

Only insofar as more careful review. Otherwise, no, they shouldn't. Exactly the same policies on content should be applied uniformly to everyone.

I agree with both of you.

They should be handled differently [than they are today]. They should not be handled differently [than any other persons]. Meta should be giving everyone careful review.


According to Google, Meta restored their account within hours after it got flagged for some content.

This happens all the time on these social media websites. Automatic flagging of content, human reviewers restore it.


Including accounts of public officials? I thought they were treated differently. Like manual review before any action.

People have a hard time believing Dario actually believes this stuff. But nothing from his entire track record from the early days until now indicates otherwise. Calling it all marketing or anti-competitive play is just typical social media, where they want to eliminate all nuance and make it reductive as possible to fit a convenient narrative.

I’m on record explaining why I believe Dario is a true believer since decades. That doesn’t change anything about the current dynamic, which is about Anthropic the company and not Dario’s personal beliefs

I remember working at an office building and the company on the floor above us won a big patent suit against Microsoft. We didn't see them at the office after that. I assumed they just stopped working and lived off the money.

What makes you think the parent company actually "shared" the win with the workers ?

I do the same, I don't use Claude Code or Codex planning because it is mostly pointless, even with Fable/Astra. I just have multiple agents work on a markdown file which I manually perfect, often breaking into multiple different files for large features or PRs. I also create design 'handoff' documents which I feed into Claude Design or Astra along with screenshots and wireframes. By the time an agent does something I'm well prepared.

I've tried doing the incremental, iterative approach with just Code and it's just not as effective unless you're working on something simple or experimental. Or you're shipping to something non-serious or perpetually beta.


Security backed loans for what though? Personal spending? Building a factory to great jobs?

> "Security backed loans for what though? Personal spending? Building a factory to great jobs?"

Income for what though? Personal spending? Building a factory to great jobs?

Capital gains for what though? Personal spending? Building a factory to great jobs?

Property for what though? Personal spending? Building a factory to great jobs?

Inheritance for what though? Personal spending? Building a factory to great jobs?

What a strange question.


Where did he say that? I listened to it yesterday and AFAIK he only said "I don't know where the line between native vs web will end up in the future" (now that we can generate native apps easier)

Keep in mind DHH is working on an email app, it makes sense he sees native as the default option for that over pushing everything through the web when the barrier to entry lowered dramatically.

Hotwire is not explicitly a cross-platform concept. It's primarily a way to build web apps in the browser which is not going away any time soon. The only difference is in 2026 you're just more likely to vibecode a native mobile app than build a web/React Native version. Likewise you may build a native Desktop version instead of an Electron wrapper.


The issue with native apps is that you have to convince people to install them. If I had one app for each tab I open in my browser my phone would be a mess and out of free space. Then you slow down the delivery of features and bug fixes because you have to go through the app stores. You can't deploy something every day or more often.

So even if we can generate an app easily now, is that a wise choice for every business?


Like everything, depends on the usecase. An email desktop app seems to be a valid one. A standard earlystage B2B SaaS Rails web app? Not so much.

Same with server side rust. A high volume transactional backend email service makes sense there. The base layer of a CRM managing a lot of business logic?

Life will go on much the same. We just have more options to say yes to 'native' with LLMs, we can experiment more with ideal scenarios rather than a religious adherence to cross platform or single-framework merely for team DX simplicity.


If the apps were actually good, you'd install them. A lot of the apps on F-Droid are pretty lightweight, and a phone's security model makes it much safer than installing apps on Windows.

The web makes apps worse by forcing a fairly strict sandbox, even as Google keeps trying to loosen it. Think of a messaging app that hides in your notification tray, that's a trivial UX thing that's impossible on the web.


When I started in computing there was no Web, there was enough space to install the applications that actually mattered, and even better, developers actually had to take hardware constraints into account.

> If you watch the talk, he is not anti-rails.

He explicitly said he still loves ruby as a language and thinks Rails is well suited for a future with AI coding.

It's interesting how this stuff gets spun on social media by people who don't watch the content.


It looks like he spent about 4 minutes out of the 1:03 making that point.

I can't but help think that he would have spent longer on it if that's what he really thought.

I don't think he believes in Rails any more.

It's clear that he was more excited about thing that are not ruby or rails and now considers rust better suited to the output of AI.

To be honest, I could see rust taking over from typescript/javascript as an output language for the web too. If no one needs to read source code any more why not use rust for everything?


I don't think anyone should really believe in Rails at this point. It was a monumental leap forward at the time but other stacks have shown that there are better ways.

>It's interesting how this stuff gets spun on social media by people who don't watch the content.

I watched it live, and a few actually in the show have very different perspective to what you suggest, they were just keep it to themselves and not posting it on twitter. Some did, but then deleted it.

And no one is questioning he doesn't like ruby anymore. But it was obvious there was nothing much said about the future of Ruby and Rails.


It doesn't matter if Rails is well suited for AI or not. Now, there's less incentive and reasons to use it.

When I started as rails dev in 2013, it was really the top solution for producing MVP fast. Now, I don’t think that’s the case and most of the incentives are gone if we are no longer writing code by hand

So what would you pick for producing an MVP web app fast that you also want to run in production, maintain, patch and scale that has a solid eco-system of pre-built libraries you can just plug in to solve problems?

I prefer a Rails backend, especially in the agentic world.

With an agent on a greenfield is when I’m most reliant on a framework for good standards and a clear architecture.

This is one of the things Rails does really well.


I strongly prefer Rails with agentic development. Rails comes with nearly everything you need to make a full-featured application, and that makes it easier and faster to use with agents.

No other framework comes close, and telling me that I can have my agents cobble together this same baseline, badly, from a hodgepodge of new code and random libraries is not compelling.


Because people are naive enough to think the huge privacy compromise will be worth the cost to society in order to protect kids.

The better question is why in 5yrs we will have to use ID to buy a product on some random ecommerce site or to play a video game or use Uber or post a comment on Reddit. It will be because people pushed for this for kids on social media and opened the door for the rest of the internet companies to demand it and therefore the government.


I really hate it when some vague "people" are blamed for this bullshit. those who do -- a minority -- do it only because they've been brainwashed by the relentless public opinion campaign ran jointly by the capital and the governments.

No brainwashing needed, the vast majority of people don’t care one bit about privacy

the vast majority of people would object to having a camera in every room of their dwelling. they just don't realize that having spyware on every piece of electronics they own is even worse.

They don’t care. Even if you explain everything in details, in a way they understand. We’ve been having that arguments since 2 decades, it’s now pretty clear they don’t care. They will complain about flock, then 2 minutes after sign up for Muse and share all their personal data with Meta, even if told what that’s used for

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: