Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done.

this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
13 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • jcoglan@mastodon.socialJ jcoglan@mastodon.social

    this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

    jcoglan@mastodon.socialJ This user is from outside of this forum
    jcoglan@mastodon.socialJ This user is from outside of this forum
    jcoglan@mastodon.social
    wrote sidst redigeret af
    #2

    if your "containment" is "telling the robot to be a good boy" you're not a serious person

    jcoglan@mastodon.socialJ prema@hachyderm.ioP emily_s@mastodon.me.ukE 3 Replies Last reply
    0
    • jcoglan@mastodon.socialJ jcoglan@mastodon.social

      if your "containment" is "telling the robot to be a good boy" you're not a serious person

      jcoglan@mastodon.socialJ This user is from outside of this forum
      jcoglan@mastodon.socialJ This user is from outside of this forum
      jcoglan@mastodon.social
      wrote sidst redigeret af
      #3

      first we got "prompt injection" aka "deciding to forget two decades of knowledge about secure composition of code and inputs, langsec, etc" and now we have "deciding to forget everything about capability-based security and writing a call of duty script about it"

      jcoglan@mastodon.socialJ 1 Reply Last reply
      0
      • jcoglan@mastodon.socialJ jcoglan@mastodon.social

        first we got "prompt injection" aka "deciding to forget two decades of knowledge about secure composition of code and inputs, langsec, etc" and now we have "deciding to forget everything about capability-based security and writing a call of duty script about it"

        jcoglan@mastodon.socialJ This user is from outside of this forum
        jcoglan@mastodon.socialJ This user is from outside of this forum
        jcoglan@mastodon.social
        wrote sidst redigeret af
        #4

        "the robot went to a website" wow should we throw a party should we invite tim berners lee

        1 Reply Last reply
        1
        0
        • jcoglan@mastodon.socialJ jcoglan@mastodon.social

          this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

          hailey@hails.orgH This user is from outside of this forum
          hailey@hails.orgH This user is from outside of this forum
          hailey@hails.org
          wrote sidst redigeret af
          #5

          @jcoglan it's a sign theyre running out of money when they gotta dial up the science fiction

          1 Reply Last reply
          0
          • jcoglan@mastodon.socialJ jcoglan@mastodon.social

            if your "containment" is "telling the robot to be a good boy" you're not a serious person

            prema@hachyderm.ioP This user is from outside of this forum
            prema@hachyderm.ioP This user is from outside of this forum
            prema@hachyderm.io
            wrote sidst redigeret af
            #6

            @jcoglan i guess this is exactly what they did for “containment”

            1 Reply Last reply
            0
            • jcoglan@mastodon.socialJ jcoglan@mastodon.social

              this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

              wim_v12e@scholar.socialW This user is from outside of this forum
              wim_v12e@scholar.socialW This user is from outside of this forum
              wim_v12e@scholar.social
              wrote sidst redigeret af
              #7

              @jcoglan Running in a chroot or container or VM is no substitute for airgapping the computer.

              1 Reply Last reply
              0
              • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                if your "containment" is "telling the robot to be a good boy" you're not a serious person

                emily_s@mastodon.me.ukE This user is from outside of this forum
                emily_s@mastodon.me.ukE This user is from outside of this forum
                emily_s@mastodon.me.uk
                wrote sidst redigeret af
                #8

                @jcoglan "We just ask our uncleared staff nicely not to access the files that require security clearances"

                1 Reply Last reply
                0
                • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                  this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                  theoesc@mastodon.socialT This user is from outside of this forum
                  theoesc@mastodon.socialT This user is from outside of this forum
                  theoesc@mastodon.social
                  wrote sidst redigeret af
                  #9

                  @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                  jcoglan@mastodon.socialJ shaknais@mastodon.socialS 2 Replies Last reply
                  0
                  • theoesc@mastodon.socialT theoesc@mastodon.social

                    @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                    jcoglan@mastodon.socialJ This user is from outside of this forum
                    jcoglan@mastodon.socialJ This user is from outside of this forum
                    jcoglan@mastodon.social
                    wrote sidst redigeret af
                    #10

                    @TheoEsc ok but that means they found a bug in the firewall, not that the AI "disobeyed its instructions" which is the framing of these types of stories, and one which makes no sense at a conceptual level

                    1 Reply Last reply
                    0
                    • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                    • theoesc@mastodon.socialT theoesc@mastodon.social

                      @jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/

                      shaknais@mastodon.socialS This user is from outside of this forum
                      shaknais@mastodon.socialS This user is from outside of this forum
                      shaknais@mastodon.social
                      wrote sidst redigeret af
                      #11

                      @TheoEsc

                      "got passed the allowlist" still means it had access to arbitrarily execute code. And arbitrary code execution leads to... Arbitrary code execution.

                      1 Reply Last reply
                      0
                      • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                        this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                        patrickleavy@mastodon.socialP This user is from outside of this forum
                        patrickleavy@mastodon.socialP This user is from outside of this forum
                        patrickleavy@mastodon.social
                        wrote sidst redigeret af
                        #12

                        @jcoglan yes it was bullshit - just hype for their latest fund raise, which was announced two days later (today):
                        https://londondaily.com/openai-secures-40-billion-funding-reaches-300-billion-valuation
                        #AI is such a pump n dump.

                        1 Reply Last reply
                        0
                        • jcoglan@mastodon.socialJ jcoglan@mastodon.social

                          this story about openai "breaking containment" is such bullshit if you know anything about how computer security is supposed to be done. if a program accesses a remote system it's because you decided to let it do that. LLMs don't have magical powers that can work around "we unplugged the ethernet"

                          lproven@social.vivaldi.netL This user is from outside of this forum
                          lproven@social.vivaldi.netL This user is from outside of this forum
                          lproven@social.vivaldi.net
                          wrote sidst redigeret af
                          #13

                          @jcoglan Still no. They didn't "let it do that."

                          Someone, somewhere, a human, *told it to do that.*

                          1 Reply Last reply
                          0
                          • reynir@social.data.coopR reynir@social.data.coop shared this topic
                          Svar
                          • Svar som emne
                          Login for at svare
                          • Ældste til nyeste
                          • Nyeste til ældste
                          • Most Votes


                          • Log ind

                          • Har du ikke en konto? Tilmeld

                          • Login or register to search.
                          Powered by NodeBB Contributors
                          Graciously hosted by data.coop
                          • First post
                            Last post
                          0
                          • Hjem
                          • Seneste
                          • Etiketter
                          • Populære
                          • Verden
                          • Bruger
                          • Grupper