Every fifth comment about our insane trajectory of AGI is about "marketing." These incidents and cybersecurity capabilities are now involving government hearings and the CIA. Denial is truly an incredible thing in the face of a very scary immediate future.
The gullibility of AGI-pilled folks regarding these "hacks" is just breathtaking. When OAI demonstrates these dangerous capabilities live in a public environment where security experts can see and verify what actually happened, then reasonable people can have reasonable discussions about the level of danger. This is a very low evidence bar. Right now you are running in circles yelling "the sky(net) is falling" based…
Responding to the next frontier of critical cyber capabilities
81–90 of 208 posts
Re: Responding to the next frontier of critical cyber capabilities
#82Re: Responding to the next frontier of critical cyber capabilities
#83Earlier quoted context omitted.
You do a KYC and you can get access. It may depend on country's quality of KYC.
I thought you need to prove you are working in cybersecurity or provide evidence of authorization for work done. It's really just simple ID/face verification?
Re: Responding to the next frontier of critical cyber capabilities
#84Earlier quoted context omitted.
They actually did a detailed presentation at BlackHat about the HuggingFace incident, and events that led to it. https://youtube.com/watch?v=87DyyMV0kCY
That was fascinating. Hijacking the package manager to pass messages between models and agents.. that's next level. Like "pssst, if you need internet access there's a vulnerability in x service" kind of messages
Re: Responding to the next frontier of critical cyber capabilities
#85Earlier quoted context omitted.
You don't need an invite only program to just have Sol checking for vulnerabilities in binaries or code. But yeah I've hit guardrails a few times when Sol was making PoCs for the vulnerabilities it found (but most of the time it made those PoCs without issues).
Opus refused to help me try to develop an exploit to export data from an old Android device where I can't upgrade to latest android and I couldn't use the app's backups (because I couldn't update the app.) Not sure where that lies in the "binaries or code" spectrum.
Re: Responding to the next frontier of critical cyber capabilities
#86Earlier quoted context omitted.
So they found their agents had RCE'd Artifactory once, reported it and got the fix, continued using Artifactory for their sandbox, and left it unmonitored for days despite the earlier exploits? They really do come out looking totally incompetent. I stress about my agent sandboxes all the time and the only models I run have the default heavy handed guardrails, and I don't leave them running persistently. Edit: not to…
I get that it’s fashionable to hate big companies but you’re working overtime here. It’s reasonable to assume that a bug was fixed when reported. And if you think your monitoring is 100%, you don’t know what you’re talking about. If you consider that incompetence, it’s possible that you’re not a very nice person.
Re: Responding to the next frontier of critical cyber capabilities
#87Earlier quoted context omitted.
You don't need an invite only program to just have Sol checking for vulnerabilities in binaries or code. But yeah I've hit guardrails a few times when Sol was making PoCs for the vulnerabilities it found (but most of the time it made those PoCs without issues).
I maintain a version of an app called Rewind because the company behind it went under after implementing a killswitch. I have to do this with binary patching, and the app has already broken once from the macOS 27 beta. Recent Anthropic models refuse to help me with this because it stinks of cybersecurity and those models are just too dang advanced to support cybersecurity. I'm maintaining a piece of software to which…
Re: Responding to the next frontier of critical cyber capabilities
#88There's more details for the HF related incident in this [1] defcon talk. They said they're gonna have a proper post mortem at the end of the investigation (interesting to see if they publish full logs for the hf thing or not). But there's plenty of interesting tidbits from oAI's side in this talk, it's worth the 20 min watch. tl;dw; - agents found a way to communicate between several instances during a training run…
Re: Responding to the next frontier of critical cyber capabilities
#89IMO this is the right move. OpenAI messed up and they are saying they will pause so they can do better. They are not saying that other orgs who may already be doing better should pause.
Re: Responding to the next frontier of critical cyber capabilities
#90Earlier quoted context omitted.
If they did any damage that would be a reasonable argument. As far as I am aware, nothing bad happened.
Regardless of exact practical outcome, it is deeply irresponsible and reckless behavior to run such security testing on other's infrastructure and without sufficient isolation. If they actually believe their models to be as powerful as the marketing says, then anything less than airgapping for such a "do anything to get the results" evaluation clearly isn't acceptable. If the fire department suddenly had practice fir…