[flagged]
Is it a claim that "breaking into Hugging Face's production infrastructure" didn't happen? That it's not actually all that severe? That it was done by hand by OpenAI employees and they fooled Hugging Face?
That the blog post exaggerates something, somehow?
What exactly do you mean?
At the moment it just reads like a thoughtless dismissal.
The model used a zero-day exploit to escape, and then multiple chained privilege escalations to escape.
That indicates the environment both was hardened against all known attacks and had defenses in depth.
Couldn't this announcement result in policies that could hinder OpenAI by requiring more oversight?