TL;DR Chat Control 1.0 = voluntary scanning loophole. Platforms may scan private messages without warrants under "child safety" cover. E2EE was supposed to remain out of scope but watch for Chat Control 2.0 which tries to mandate client-side scanning anyway. #chatcontrol
@WPalant@infosec.exchange You are calling people with different opinions assholes? Why don’t you put content warnings on your own disrespectful political opinions?
I wouldn’t be surprised if this was all just a clever marketing stunt done in cooperation by both companies involved. HF showcased that you can use their product for response and recovery from such attacks, and OAI gets some response to Anthropic’s Mythos “too dangerous” story.
I'm no proponent of age controls, but seeing the shockingly disgusting content being pushed to children on #YouTube or #Roblox, they're starting to look like a reasonable mitigation. #agecontrol
If you are a parent of underage children, get a subscription to some porn magazines and leave them on the kitchen table, so your children have less incentive to go on YouTube or play Roblox and face something much worse.
@0x00string@infosec.exchange I could understand you let it run through the night without oversight. I could not understand nobody would check its progress the next morning not noticing it is already ripping through an infrastructure of a 3rd company.
@lupinia@infosec.exchange If the choice is between children being routinely exposed to heroin or everyone else being forced to drink two beers every morning, the beers seem like the reasonable trade-off. I know it's a flawed comparison, but no other options seem to be on the table right now.
@agentpalisade@mastodon.social They did, though not at great detail: “A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.” https://huggingface.co/blog/security-incident-july-2026