Everything I've seen simply suggests they're bad at computers.
My experience with startups is that the things that don't make money or make customers happy don't get any attention. Network/system security in depth is not one of those things. Sure, they've got a bunch of psi-brain neuroscientists and mathemagicians, and goodness knows lots of DEI-enforcers for alignment, but their repeated dumb mistakes in this department tells me they're not really hiring too many experienced ops, nevermind devops, types.
It's true for OpenAI and Anthropic both.
In the past YEAR they have:
- accidentally published the full Claude Code source (and then effectively... did nothing).
- Numerous Claude Code RCE/API-key vulnerabilities which could have been mitigated with at least one person on their core infra team aware of injection attacks.
- Publicly exposed their internal CMS (and files) to the Internet
- Had their training escape numerous times and hack other orgs
- hacked HF
They're not a serious company. Some are to be expected given their visibility and exposure, but you'd expect a bit more from a company implementing Skynet-level capabilities. However you slice it, they're fundamentally building weapons which can write poetry. A little more seriousness should be involved.