Exposed Hugging Face API tokens offered full access to Meta's Llama 2


And this tells me right here how much they value security.

"It was also blocked in Hugging Face's Python library by adding a check to the type of token in the login function."

Changing client libraries prevents accidents. It doesn't do squat against a malicious user.

