The Hugging Face Incident Is Not an AI Story
A security engineer’s analysis of the OpenAI-Hugging Face incident, what failed in the architecture and incident response, and the lessons security teams can learn from it.
Essays about building, operating, and understanding software systems in an AI-assisted engineering world.
A security engineer’s analysis of the OpenAI-Hugging Face incident, what failed in the architecture and incident response, and the lessons security teams can learn from it.
AI can generate code faster than most developers can evaluate it. The risk isn't only bad output. It's losing the understanding you need to tell good code from plausible code.
AI makes it dramatically cheaper to produce software that appears to work. But 'building an app' and 'engineering a system' are two different activities that people keep confusing, and the gap between them is where most of the actual work lives.
Security is having a moment: new tools can read code, find bugs, and even suggest fixes. Some people took that to mean cybersecurity is basically over. This is my take from the inside: what’s actually changing, what isn’t, and why security was never just a code problem.