HuggingFace hacked – Space secrets leak disclosure

Date:

Back to Articles


Space secrets leak disclosure

Hugging Face's avatar

Earlier this week our team detected unauthorized access to our Spaces platform, specifically related to Spaces secrets. As a consequence, we have suspicions that a subset of Spaces’ secrets could have been accessed without authorization.

As a first step of remediation, we have revoked a number of HF tokens present in those secrets. Users whose tokens have been revoked already received an email notice. We recommend you refresh any key or token and consider switching your HF tokens to fine-grained access tokens which are the new default.

We are working with outside cyber security forensic specialists, to investigate the issue as well as review our security policies and procedures.

Over the past few days, we have made other significant improvements to the security of the Spaces infrastructure, including completely removing org tokens (resulting in increased traceability and audit capabilities), implementing key management service (KMS) for Spaces secrets, robustifying and expanding our system’s ability to identify leaked tokens and proactively invalidate them, and more generally improving our security across the board. We also plan on completely deprecating “classic” read and write tokens in the near future, as soon as fine-grained access tokens reach feature parity. We will continue to investigate any possible related incident.

Finally, we have also reported this incident to law enforcement agencies and Data protection authorities.

We deeply regret the disruption this incident may have caused and understand the inconvenience it may have posed to you. We pledge to use this as an opportunity to strengthen the security of our entire infrastructure. For any question, please contact us at [email protected].

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

Popular

More like this
Related

I ditched Squarespace for this platform with no fees

Skip to content Image: StackCommerce TL;DR: Save 77% on a DoRoyal...

Do smartphones eavesdrop on conversations? New evidence says yes

Skip to content Image: Cast Of Thousands/Shutterstock.com You’ve probably already noticed...

Baldur’s Gate III adds native game mods on PC

Image: Larian Studios Baldur’s Gate III was an absolute smash...

Get this RTX-powered HP laptop with i9 CPU for $400 off today

Image: HP Powerful gaming laptops can be pricey, so we’re...