4 ms·
Well, to be fair, isn’t it an unsolved question? Are they constructing sandboxes, signaling intent to be safe, but their own models are smarter than their inter
by talon8635 14d ago
Well, to be fair, isn’t it an unsolved question? Are they constructing sandboxes, signaling intent to be safe, but their own models are smarter than their internal security team building the sandbox?
- arcfour 14d agoAs a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example...
- borski 14d agoWe’re hiring. :) (And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab)
- xnx 14d agoCould you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally.
- borski 14d agoEven if you had it internally (which we do), there is so much surface area and it’s such a novel space that you’d want as much testing on it as possible. There aren’t many vendors, and irregular is one.
- eli_gottlieb 14d agoAFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security.
- talon8635 13d agoThey are hiring philosophers and therapists to psychoanalyze the things. It’s just absurd to assume that they aren’t hiring top notch security engineers. They made mistakes, obviously, but people are so conspiratorial these days that they just assume unlikely things off the jump.
- eli_gottlieb 13d agoNo, I think they didn't hire proper security engineers because they just don't understand what that means. Incompetence, not malice.