4 ms·
An ethical company would have reframed the scenario as a fascinating discovery, a failure of internal practice, and a warning to the public coupled with some ki
by gwerbin 2mo ago
An ethical company would have reframed the scenario as a fascinating discovery, a failure of internal practice, and a warning to the public coupled with some kind of commitment to produce safer models. OpenAI on the other hand used it as a marketing and lobbying opportunity: advertising their capabilities to potential buyers, while nudging the public to support protectionist import bans.
- Arnt 2mo agoUh, is that what they did? I didn't read their blog posting like that. But let's put that aside and focus on something else. How was it a failure of internal practice, what did they do wrong? AIUI they used a proxy with a bug, which they reported as soon as they discovered it. Right? What should they have done, and what's the difference?
- queenkjuul 2mo agoMonitoring that didn't take days to notice unauthorized external traffic would probably be a good start
- Arnt 2mo agoI see. I had the impression that "days" is already good as these things go, "months" being more common.
- queenkjuul 2mo agoMonths to recognize traffic escaping a sandbox you set up yourself?
- Arnt 2mo agoNo, unauthorised traffic across a firewall in general. This involved some lateral movement, ie. traffic didn't just cross the intended sandbox border. Is that kind of thing simpler to detect than an intrusion?
- queenkjuul 2mo agoThe lateral movement was outside OAI's network. The security sandbox should have had an offline package cache and a strict internet whitelist. Detecting unauthorized traffic seems like one of the highest priorities of designing a security sandbox.