https://lemmy.world/post/49736885
If you follow AI news at all as part of your self-hosting interests, you may have become aware recently that open AI (the frontier lab between behind chat GPT) has admitted (loosely) culpability in an cyber attack against HuggingFace (the major repository of open-weight models.)
The details that present are somewhat sketchy, but the gist of it is that open AI seems to have given unrestricted access to a AI agent, which then attacked hugging face, who in a twist of deliciousness, used an open source agent to defend themselves.
I’d joke and tell you to make sure that you haven’t left any open ports on your router, but if you’re here reading this I think probably you know better than that.
Less comically, there’s a weird intersection here between self-hosting, sovereignty and encroachment by big tech that is worth pay attention to.
It should certainly spur people on to seriously consider self-hosting as much of their infrastructure as they can (and securing it) if this is the preview of things to come.
Something is rotten in the state of Denmark.
I just wish I’d bought more SSDs.
OpenAI is trying to artificially plump themselves up before going for IPO. They “attacked” a vendor that dispenses LLM and LLM-adjacent products that are similarly aligned with OpenAI’s goals. It almost seems like it was a coordinated event to generate a sense of mystique around their premier models (à la Anthropic with Mythos).
What does self hosting look like in a world full of malicious AI agents?
I’m thinking of this post/thread from Veronica explains, where she explains that her hosted services are accessible only locally because tbe security headache isn’t worth it: https://explains.social/@veronica/statuses/01KWJCGV27JVBHP21E2JNWDBFH
As someone who doesn’t self-host but could and would want to, the state of AI has basically scared me off.
This is a big reason I only remotely access my services via TailScale / Wireguard.
Even if my highly restricted ISP let me open anything, I wouldn’t dare. I know for certain I don’t know as much as who/whatever is hunting for open ports out there. I have zero interest in instantly being assimilated into some botnet lol.
I host several services accessible via the open Web. They are isolated enough that a breach would most likely only compromise that service. They are also kept up to date, and logs are monitored.
There’s always a risk when exposing something, and I am limiting some services to access via VPN because either the data in them is too sensitive, or I don’t trust them to be secure enough.
You probably also aren’t a worthwhile target in most cases.
The takeaway here is that anything connected to the internet can probably be compromised. Am I crazy for thinking that? I don’t think my home lab can keep up with openAI’s new attack dogs if huggingface can’t either
Not at all. Anything an attacker can connect to is a potential vector.
Keep in mind, this goes for outbound connections as well. If something is compromised server-side, and you or your software reach out to it, that’s also a potential vector. Less likely, since the attacker has to compromise that server and pass their attack off as legit traffic, but it’s possible.




