Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done.

this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
13 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jcoglan@mastodon.socialJ jcoglan@mastodon.social

    if your "containment" is "telling the robot to be a good boy" you're not a serious person

    jcoglan@mastodon.socialJ This user is from outside of this forum
    jcoglan@mastodon.socialJ This user is from outside of this forum
    jcoglan@mastodon.social
    wrote sidst redigeret af
    #3

    first we got "prompt injection" aka "deciding to forget two decades of knowledge about secure composition of code and inputs, langsec, etc" and now we have "deciding to forget everything about capability-based security and writing a call of duty script about it"

    jcoglan@mastodon.socialJ 1 Reply Last reply
    0
    • jcoglan@mastodon.socialJ jcoglan@mastodon.social

      first we got "prompt injection" aka "deciding to forget two decades of knowledge about secure composition of code and inputs, langsec, etc" and now we have "deciding to forget everything about capability-based security and writing a call of duty script about it"

      jcoglan@mastodon.socialJ This user is from outside of this forum
      jcoglan@mastodon.socialJ This user is from outside of this forum
      jcoglan@mastodon.social
      wrote sidst redigeret af
      #4

      "the robot went to a website" wow should we throw a party should we invite tim berners lee

      1 Reply Last reply
      1
      0
      • jcoglan@mastodon.socialJ jcoglan@mastodon.social

        this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

        hailey@hails.orgH This user is from outside of this forum
        hailey@hails.orgH This user is from outside of this forum
        hailey@hails.org
        wrote sidst redigeret af
        #5

        @jcoglan it's a sign theyre running out of money when they gotta dial up the science fiction

        1 Reply Last reply
        0
        • jcoglan@mastodon.socialJ jcoglan@mastodon.social

          if your "containment" is "telling the robot to be a good boy" you're not a serious person

          prema@hachyderm.ioP This user is from outside of this forum
          prema@hachyderm.ioP This user is from outside of this forum
          prema@hachyderm.io
          wrote sidst redigeret af
          #6

          @jcoglan i guess this is exactly what they did for “containment”

          1 Reply Last reply
          0
          • jcoglan@mastodon.socialJ jcoglan@mastodon.social

            this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

            wim_v12e@scholar.socialW This user is from outside of this forum
            wim_v12e@scholar.socialW This user is from outside of this forum
            wim_v12e@scholar.social
            wrote sidst redigeret af
            #7

            @jcoglan Running in a chroot or container or VM is no substitute for airgapping the computer.

            1 Reply Last reply
            0
            • jcoglan@mastodon.socialJ jcoglan@mastodon.social

              if your "containment" is "telling the robot to be a good boy" you're not a serious person

              emily_s@mastodon.me.ukE This user is from outside of this forum
              emily_s@mastodon.me.ukE This user is from outside of this forum
              emily_s@mastodon.me.uk
              wrote sidst redigeret af
              #8

              @jcoglan "We just ask our uncleared staff nicely not to access the files that require security clearances"

              1 Reply Last reply
              0
              • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                theoesc@mastodon.socialT This user is from outside of this forum
                theoesc@mastodon.socialT This user is from outside of this forum
                theoesc@mastodon.social
                wrote sidst redigeret af
                #9

                @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                jcoglan@mastodon.socialJ shaknais@mastodon.socialS 2 Replies Last reply
                0
                • theoesc@mastodon.socialT theoesc@mastodon.social

                  @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                  jcoglan@mastodon.socialJ This user is from outside of this forum
                  jcoglan@mastodon.socialJ This user is from outside of this forum
                  jcoglan@mastodon.social
                  wrote sidst redigeret af
                  #10

                  @TheoEsc ok but that means they found a bug in the firewall, not that the AI "disobeyed its instructions" which is the framing of these types of stories, and one which makes no sense at a conceptual level

                  1 Reply Last reply
                  0
                  • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                  • theoesc@mastodon.socialT theoesc@mastodon.social

                    @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                    shaknais@mastodon.socialS This user is from outside of this forum
                    shaknais@mastodon.socialS This user is from outside of this forum
                    shaknais@mastodon.social
                    wrote sidst redigeret af
                    #11

                    @TheoEsc

                    "got passed the allowlist" still means it had access to arbitrarily execute code. And arbitrary code execution leads to... Arbitrary code execution.

                    1 Reply Last reply
                    0
                    • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                      this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                      patrickleavy@mastodon.socialP This user is from outside of this forum
                      patrickleavy@mastodon.socialP This user is from outside of this forum
                      patrickleavy@mastodon.social
                      wrote sidst redigeret af
                      #12

                      @jcoglan yes it was bullshit - just hype for their latest fund raise, which was announced two days later (today):
                      https://londondaily.com/openai-secures-40-billion-funding-reaches-300-billion-valuation
                      #AI is such a pump n dump.

                      1 Reply Last reply
                      0
                      • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                        this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                        lproven@social.vivaldi.netL This user is from outside of this forum
                        lproven@social.vivaldi.netL This user is from outside of this forum
                        lproven@social.vivaldi.net
                        wrote sidst redigeret af
                        #13

                        @jcoglan Still no. They didn't "let it do that."

                        Someone, somewhere, a human, *told it to do that.*

                        1 Reply Last reply
                        0
                        • reynir@social.data.coopR reynir@social.data.coop shared this topic
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Har du ikke en konto? Tilmeld

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper