upvote
For those unclear, the above quotes are from the OP link. I checked the bios for the first couple of authors and they do not seem to be from OpenAI.

OpenAI's details on the incident are at:

* https://openai.com/index/hugging-face-model-evaluation-secur...

* https://openai.com/index/hugging-face-incident-and-the-road-...

* Technical report: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78...

* METR Report: https://metr.org/blog/2026-08-26-openai-hugging-face-inciden...

* Presentation talk video: https://www.youtube.com/watch?v=87DyyMV0kCY

reply
> to make ‘GET’ requests, meaning they could <not> send data to them.

no way, I refuse to believe this is quote from that report. Can someone please point out what I'm missing here?

reply
I think it’s just to distinguish two stages of the attack. They figured out how to make get requests, then how to use that to make others which was required for accessing the sandbox on modal iiuc.
reply
TFA seems to be sloppy in writing, they should have kept the "meaning... [Some incorrect assumptions about GET]" out of the paragraph.
reply
You're not missing anything. TFA really state this wrong assumption in their own voice.
reply
Wait - so the cross-site scripting, to modify the innerHTML text on the page via the GET URLs as they are rendered by the screenshot proxies... that was so they could use the screenshot services like a Wiki, and embed messages to each other in the modified images on the screenshot sites?

That's pretty damn clever. Got to give the AI models credit for thinking of that one.

reply