Live data from Hacker News

A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

effort.news

221–230 of 260 posts

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#222

Earlier quoted context omitted.

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

Air gap?

There has to be a route to where the LLM is running, and if there's a route for that there's probably a way for the machine to use it to route traffic somewhere else.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#223

Earlier quoted context omitted.

Air gap?

So just enable access to a completely offline, cached, and transparently proxied, copy of the internet.

Isn't that essentially what they trained with, anyway?

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#224

Earlier quoted context omitted.

Air gap?

So just enable access to a completely offline, cached, and transparently proxied, copy of the internet.

I think that was the plan. But OpenAI hacked the proxy

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#225

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

How do you test and monitor outbound access against program that adapts itself to get around things? if your MITM and filtering keywords etc, cant it just .. encode it traffic somehow or another.. If you're looking at traffic volumes, cant it just go slow.. If you have strict ACLs, we've already seen in the HF case, traversal from an intermediate system..

> How do you test and monitor outbound access against program that adapts itself to get around things?

Literally what the industry has been doing since public networking is a thing. Adapt yourself.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#226
post #85

This is interesting and might be a good reason to stop working with Irregular. But I assume the alignment people want models not to hack other companies, even if they get put in a badly configured sandbox.

or rather, hack just enough and within what the user asks and not more.

Yeah precisely. If you tell an agent "get me some milk" it's no comfort if it says "oh well I wouldn't have stolen the milk if you had explicitly told me not to".

This article is dumb.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#227

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

The explanation is that it was missed on purpose.

Mistakes - even stupid ones - happen all the time

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#228

The Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-inciden...

> "Ultimately, most of the issues we’ve discovered were due to internet access controls."

You just cannot bring yourself to say lack of internet access controls, can you?

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#229

Earlier quoted context omitted.

Air gap?

There has to be a route to where the LLM is running, and if there's a route for that there's probably a way for the machine to use it to route traffic somewhere else.

No, just allow the firewall to access the LLM endpoint, nothing else. And protect the firewall settings from the agent.

Re: A single firm is behind OpenAI, Anthropic, and Meta hacking scandals

#230

Earlier quoted context omitted.

The site owner generates stories from AI consensus and data. The owner is pro-trump though. So you only get stories that agree with his agenda. It becomes a bit more obvious when you see other stories from him like "How Biden Used Religious Charities to Fund the Great Replacement".

Was that a real title, or are you referring to “The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups”?

On the About page :

""" Brian Chau Founder and CEO, Effort News """

https://www.effort.news/about

---

On the "Auron Show" Podcast :

""" How Biden Used Religious Charities to Fund the Great Replacement | Guest: Brian Chau | 8/12/26 """

https://podcast24.fi/jaksot/the-auron-macintyre-show/how-bid...

Post reply on HN