At the time of recording, Hugging Face reported an active incident where an AI LLM agent was being used to probe and attempt to breach their systems.
Snapshot · The a16z Show
At the time of recording, Hugging Face reported an active incident where an AI LLM agent was being used to probe and attempt to breach their systems.
Where this was said
At 18:30 · chapter starts 17:30
Krishnan grew up on open source and is a genuine believer in its security advantages. [1] — Sriram Krishnan "Linus Torvalds said 'given enough eyes, all bugs are shallow.' Sriram Krishnan applies this to AI: open-weight models downloaded from Huggi…" 17:30 He invokes Linus's Law — 'given enough eyes, all bugs are shallow' — to argue that open-weight models are more secure than closed ones because anyone can download them from Hugging Face and inspect every layer. You simply cannot do that with a closed API model. But he immediately counterbalances this with a sobering real-time data point: on the day of the recording, Hugging Face reported an active incident where an AI LLM agent was being used to systematically probe and attack their systems. The uncomfortable irony: the answer to AI-powered cyber attacks is almost certainly AI-powered defense — which requires defenders to have access to the best models. If American frontier model safety guardrails make those models less useful for security work, defenders are already at a disadvantage. [2] — Sriram Krishnan "Hugging Face attacked by AI agent: At the time of recording, Hugging Face reported an active incident where an AI LLM agent was being used …" 18:30
Linus Torvalds said 'given enough eyes, all bugs are shallow.' Sriram Krishnan applies this to AI: open-weight models downloaded from Hugging Face can be inspected by the entire world, making them inherently more auditable than closed frontier models. Security through transparency, not obscurity.
Open-weight models downloaded from Hugging Face can be inspected, fine-tuned, and modified by the entire global community, making them inherently more auditable than closed models.
Every AI model from the original GPT onward was trained by distilling human knowledge from the internet. The controversy around Chinese models distilling from American ones ignores the fact that distillation is foundational to how all models are built — the real issue is the asymmetric legal playing field.
Ad-based monetization works well for game apps where users spend extended time in-session, as seen with Grid and Wordle.
Tool-focused apps like PuffCount are poor candidates for ad monetization because users don't stay in-session long enough.
A hard paywall is a screen that blocks all app features unless the user pays or starts a free trial — it cannot be dismissed.
Mobile apps are primarily monetized through either ads (best for games) or in-app purchases/subscriptions (best for tools).
According to the episode, YouTube outperforms every other social platform for building trust and driving SaaS conversions.
Vasco stated that the majority of his app's user base came directly from his YouTube channel.
SEO Bot features a 'Boost My Domain Rating' button that routes users directly to Listing Bot, an example of in-product cross-selling.
The founder's entire product portfolio is AI-related, making it easier to package products attractively for directories.
The founder attached their SaaS demo to the trending debate about whether AI coding is actually good enough to build a full SaaS product.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.