4 ms·
Agents need packages like the rest of us. Ruby gems, npm packages, Maven, pip, docker images.. Not surprised this is always what they have and hack. Who would
by stephbook 17d ago
Agents need packages like the rest of us. Ruby gems, npm packages, Maven, pip, docker images..
Not surprised this is always what they have and hack.
Who would use an Agent that spends $10,000 re-implementing some OAuth lib or reverse-engineering a proprietary lib when it's free on the internet?
- tancop 17d agoYou don't need a full air gap. Set up a microVM with network access limited to local network and send all package requests through a filtering gateway that only allows normal download endpoints. Or self host a big collection of popular packages if you need extra security.
- amouat 17d agoIsn't that exactly what they did? The bots could only access the jfrog instance, so they hacked jfrog?
- exfalso 17d agoNo that's not what they did, they exposed jfrog raw. It would have been so extremely simple to gate services they need the llm to access... I mean, jfrog was not written with this kind of threat model in mind, and neither were a lot of other tools
- amouat 17d agoRight, you mean it didn't go through a gateway? But would that actually have helped? The requests all went through jfrog didn't they? I guess it depends on the level of filtering at the gateway? Whilst it might not be JFrog's threat model, I wouldn't assume it can be used as a full internet proxy. I don't really mean to defend OpenAI here, but they did make some attempts at sandboxing. Although it does seem that they didn't really know what they were doing.
- exfalso 16d agoIt would have been a case of isolating exactly what functionality is needed and wiring that up with the actual requests. Not like a full pass-through proxy. This is what we've been doing in our company as well
- zahlman 16d ago> jfrog was not written with this kind of threat model in mind, and neither were a lot of other tools And we don't just magically know all the consequences of that. Which is exactly why we do need full, physical air gapping. (Which, yes, would also include self-hosting a mirror of the package repo, if the point of the simulation is to see what's possible with the real package repo.)
- KaiserPro 17d ago> Agents need packages like the rest of us. Ruby gems, npm packages, Maven, pip, docker images.. Yes, yes they do, but read through artifact proxies are dodgy as fuck, which is why and facebook (and I assume a fuckload others) don't have them. Also semi-airgapped labs are a lot less expensive than you think at that scale. Once you have to do multi-region VLANs with machine certs before you get access to juicy VLANs, the difference between "no internet for you" and "mostly airgapped" falls to almost zero. Also I would want an artifact mirror because a) that give a good signal about how the model reacts, and what training material its latched onto, b) it hides what the models are doing from the outside.
- Topfi 17d agoThere was and continues to be no reason to share the package manager between models. This was begging for abuse.