2 comments

  • verdverm 10 hours ago ago

    > The entire software industry needs to up its security game.

    I hope OpenAI starts by recognizing that a proxy is not the right way to sandbox an agent to allow it access to dependencies for installation. They should have baked them in or mirrored internally, avoiding the need for a proxy when doing work like this.

    Then I'd like to know how they were unaware of this for so long? Where is their own network monitoring in this?

    As far as I'm concerned, OpenAI was the lazy cog in this incident. Air gapped has a stricter meaning than their sloppiness. If they are not going to do the basics, how are we supposed to believe they can be the responsible party for our Ai future? (imo, zero trust they are responsible or well intentioned)

    • simonw 7 hours ago ago

      I would hope that OpenAI themselves would agree with you. This entire story started with them not taking the necessary steps to monitor their agent while it was executing against the eval suite.

      I'm very much looking forward to their own retrospective, especially the bit about how they plan to avoid this happening again in the future.