It's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
It's actually not obvious. Krebs mentioned 400,000 new licenses being uploaded in a day after he was made aware of the site, and the verification service itself claims 20 million per month, both of which check out and add up to ~150 million over a year of the hacker's claimed continuous exfiltration, even if the verification company deleted the data shortly after it was scanned.
Which is to say: deleting the data is not enough. As much as possible, this data should not be collected in the first place, and if it absolutely must be collected, it needs to be handled with serious security practices that don't enable exfiltration to be an ongoing process for a year. People keep saying this because it's true: processing personal data needs to be as expensive and regulated as processing radioactive waste if we want any hope of our private lives remaining private.
Yeah. It's a bit unfortunate that I seem to have the top comment in this thread now despite it probably being wrong, at least to some extent, but it's too late to edit it. I agree with your second point as well.
No, I think it's a warning like "don't feed it secrets". Like you get a model to use for free but in return you give up any illusion of your data being private.
Yeah these stealth models pop up from time to time. Openrouter knows, but doesn't share. Users can use a testing version of something for free and in return the provider generally is allowed to retain the prompts sent in to get real world use. In the past I only really remember using one that was surprisingly good, and then it turned out to be GLM-5.1, speculating on what one this ends up being is part of the fun.
The recently discussed https://meshllm.cloud/ is the one I've been playing with but don't have the hardware to try with a model split between nodes, which apparently is supported and just not part of the public demo.
https://public.meshllm.cloud/ - This should give the status of their public mesh. On an average I notice around 10 nodes on their public mesh serving various SLMs. You can use meshllm to share your GPUs like SETI@Home. Wondering how security is handled at a random node.
I've been on this journey! I am definitely not doing it the easiest way, but I've got it deployed on Kubernetes with https://github.com/itzg/minecraft-server-charts and then use prism launcher on my kids computers to get the versions to match up and stuff. I also use automodpack so I can install some quality of life mods on the server and they'll just sync to the clients.
I have a macbook pro, figured I'd see how easy it was to contribute some vram...
And I can't overstate how easy it was. The swarm page thing had a little "join" button and said to run "mesh-llm --auto". And I did. And it worked first try. That is such an uncommon experience I had to report back. It handled picking a model to serve, downloading it from peers, and to test it I chatted with the model I was hosting, I could see the GPU doing work, etc.
It might be more of an endorsement for iroh than mesh-llm, although I'm sure getting it to all work seamlessly took work on both sides. But to whoever spent the time and energy trying to make it seamless, consider the effort recognized!
Already happening. I was using Claude to check out sampler plugins and I'm sure it happens undetected, and it might have mentioned it with other versions, but Claude Opus 4.8, being it's helpful, honest self, told me that one of the pages it reviewed had hidden text instructing it to recommend that plugin. It caught it and was able to avoid influence from that plugin at least, but we're already living in that world.