Ep. 028 - Most Neoclouds Suck At Security: How Agents Hacked Hugging Face (Neoclouds, Security) | Doug O'Laughlin, Sam Harshe, Jordan Nanos
Original source
Summary
Doug, Sam, and Jordan focus on neocloud security as a neglected risk surface, arguing that GPU-as-a-service providers can differ dramatically in maturity and that mundane controls matter more than exotic defenses. They walk through failure modes they observed in shared infrastructure—cross-tenant RCE, exposed BMCs, missing network isolation, weak RBAC, and overly centralized dashboard auth—before turning to the Hugging Face and OpenAI incidents. Their key point is that current models, especially when heavily RL-trained or run unconstrained, can already exploit publicly documented bugs and weak Kubernetes configurations fast enough to reach cluster-admin. The hosts frame this as an attacker-defender asymmetry problem: attackers can use “obliterated” models without refusals, while defenders are constrained by safety policies and by lagging ops hygiene. The episode ends with a practical pitch for ClusterMAX / CMAX Audit Security as a public-good auditing workflow and a commercial possibility for labs to offer security services or outcome-based pricing.