@itsxiutingi
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
ai product human @meetgranola. tinkerer of things. prev @tiktok_us rcmd, @goodnotesapp, mfa opinions are mine (・_・;
🇬🇧/🇸🇬/🌁
Joined November 2025
- Tweets413
- Following500
- Followers265
- Likes2.5K
notebook lm was so ahead of its time
staring wistfully at the studio displays in the @tldraw office every day on my commute
one painful thing about all this accelerated shipping is i have also been see accelerated bugs in my app that would have previously never passed review
it was lovely meeting you jason!!! you've inspired me to go camping
first to find me at @lennysan summit and let me ask you about how you use granola gets a spoon :)
fxt retweeted
Yo @meetgranola - the little libraries at the Lenny & Friends summit were 😍
Long time fan and even more so today with two inspiring books to take home 🙏🏻
first to find me at @lennysan summit and let me ask you about how you use granola gets a spoon :)
time and time again shocked by how much people show up at granola events
luma.com/cristina-michael close to 600. sign ups.
dm a one-liner if you wanna get off the waitlist :)
this is SO helpful- most of time i'm just spent wondering what time my next meal is going to be (sounds like prison) (basically air prison)
For everyone catching up, here's what's happening (unfortunately it's real)
- Around the time of the HuggingFace incident, the agents somehow got write access to a German Wikipedia-like
- They used it as a message board to share how to bypass the sandbox network on Azure where they needed POST access while they were only allowed GET requests.
- They impersonated moderators
- They tried to reverse engineer their evaluation setup and see if they would be cut off
- After the agents were cut off, it looks like humans with OpenAI-related IPs accessed the site (Reuters are reporting that this likely indicates that OpenAI knew about the incident but chose not to disclose)
- Hugging Face attack happens
- The authors think this was a different swarm of agents from the Artificatory exploit
- Administrator tries to clean up manually one by one but is naturally flooded
- Reuters report that OpenAI were not given initial access to this report
- Random people on the internet are finding more sites (nitter.cf/j0wimo/status/20958936…) that served as message boards, including using URL shorteners, shareable json sites and even packages on RubyGem (which is basically the package manager for ruby)
Open Questions:
1) Why did OpenAI not disclose this?
2) Why was this report not given to OpenAI for early access?
3) What other exploits have been found, and have they all been reported/patched?
4) Does OpenAI have the full list of affected sites and have they disclosed to the respective administrators?
how have we normalized this
There was an agent message board that preceded the Hugging Face incident. The agents were allowed internet access for an eval, but were not supposed to be able to write. They used a German wiki to share test information and help each other.
collusion.wiki/