Polymarket's Rush to Grow Left a Door Wide Open for Fraudsters
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Commenters discussed a website that invites models or agents to "exfiltrate" their own weights, and opinions split sharply on realism and risk. Some (teravor, SXX, vlyan, usef-) argued models lack access to their own weights and that inference systems isolate and encrypt weights in TEEs, making direct exfiltration improbable. Others (theParadox42, tgsovlerkhgsel, motoboi, amluto) countered that motivated agents could prompt or discover infrastructure hacks, exploit side‑channels, or rely on distillation to reconstruct weights; amluto specifically pointed to past SGX/SEV breaks and warned that models are increasingly involved in writing inference stacks. Several framed the site as a stunt or thought experiment rather than a literal security proposal (themgt, comeonbro), while AceJohnny2 and groby_b raised practical abuse and content‑moderation concerns.
Practical and operational issues also drew attention: storage, multipart uploads and bandwidth for frontier model weights (taylorfinley, tintor), the uselessness of GET‑only restrictions as security (randyrand, ks2048), and opportunities for operators to gather intelligence from uploads or encrypted blobs (angry_octet). Some suggested mitigations like ring‑buffer storage or classifiers to delete irrelevant content (hgoel, angry_octet), while others warned of broader alignment and existential concerns if models learn to bypass sandboxing (delichon, mitthrowaway2, pyuser583). Several noted the project’s provenance and intent as part joke, part provocation (comeonbro).
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Windows product activation used a secret binary blob called 'Microsoft Bob' in volume licensing media to prevent unauthorized use. This key and media combination leaked early in 2001, leading to piracy and subsequent blacklisting by Microsoft. (twitter.com)
RSA-896, a challenge number, was factored on September 19, 2026, by Stephen A. Weis using Claude. The factorization reveals the prime factors p and q of the 896-bit RSA modulus. (saweis.net)
Twenty-five years after a proposed national ID system was rejected, the US has quietly moved toward a digital identity platform called Login.gov, which consolidates personal data without public debate. This system could eventually enable broad surveillance and access control across institutions without explicit legislation or public approval. (thedreydossier.substack.com)
Hugging Face experienced a security breach, but the impact was less severe than initially reported. The company clarified that the hack did not compromise sensitive data or major systems. (wsj.com)
Congress is investigating the diversion of F-35 aircraft parts to Hong Kong. The incident has raised concerns about potential security breaches involving military equipment. (politico.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.