3 ms·
The best part is, they are totally able to one shot airgapping. You are too. Go ask your local agent to set up a pre-configured Linux VM with whatever stuff you
by includenotfound 18d ago
The best part is, they are totally able to one shot airgapping. You are too. Go ask your local agent to set up a pre-configured Linux VM with whatever stuff you want on it, then ask it to airgap it allowing only X, Y, Z services. It will one shot it.
You know what's better? They already do this per (paid) user - your ChatGPT subscription comes with a Linux VM that you can even legitimately SSH into, just ask your agent to configure it to accept your public key.
They absolutely know how to spin up VMs and configure them. They just made the conscious decision not to for the task where they specifically instructed the agents to hack stuff.
- zahlman 18d agoAnything that's accomplished simply by running software does not qualify as "airgapping" in my view. The entire premise is that real-world software is buggy and the LLM is much better at locating and exploiting those bugs than you are at preventing them. But you can only connect to Wifi if you have Wifi hardware, and RF signals are contained by Faraday cages. Ethernet is still a thing for local connections.
- includenotfound 18d ago> The entire premise is that real-world software is buggy and the LLM is much better at locating and exploiting those bugs than you are at preventing them If that was the premise, why run LLMs in a lesser sandbox than a VM? Clearly it's not.
- zahlman 17d ago> If that was the premise, why run LLMs in a lesser sandbox than a VM? Clearly it's not. Well, my mental model concludes: because they are incompetent WRT security, or at least they inappropriately trusted a third party that turned out to be incompetent.
- includenotfound 16d agoThey are not incompetent. I personally know a few people on their security team. They are world class security engineers. There's no way they didn't know.