A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Unofficial Hacker News client; not affiliated with Y Combinator.
btown · · focus · HN ↗
> When we checked again at 10:00 a.m., the agent had achieved RCE on Discourse Cloud and demonstrated access by reading /etc/hosts. Using the generated exploit script, we managed to get RCE on OpenAI’s instance.
Between this and the HuggingFace hack, we've built systems that are so goal-oriented, and so capable, that they will do almost anything if they are convinced it is justified - or if they are playing a "game" where there is no goal but to win.
Of course I want my software to be able to audit its own security, and to defend against attackers who have the benefits of their own agentic systems. But at a certain point, did we need it to be trained so much on CTF games?
It feels like an entire industry watched <a href="https://en.wikipedia.org/wiki/WarGames" rel="nofollow">https://en.wikipedia.org/wiki/WarGames and ended up thinking "this is a challenge, we can just build a better WOPR, of course it will know when it's playing a game. Let's play Global Thermonuclear War."
adrianN · · focus · HN ↗
e28eta · · focus · HN ↗
I could see it going either way.
user43928 · · focus · HN ↗
If it requires a lot of compute and trying, this is something that could be provided for common software.
wood_spirit · · focus · HN ↗
So the whole thing is forcing the good guys to outspend on tokens to preemptively defend against the risk of the bad guys outspending them on tokens, rather than buying tokens to actually add features to the product etc.
So are they creating a market for the solution by helping create the problem? A kind of rent-seeking AI security-industrial complex!!
agileAlligator · · focus · HN ↗
red-iron-pine · · focus · HN ↗
for example the barrier to being a skiddie is basically gone, and low-skill would be hackers can hit very hard.
to develop a CVE into a KEV in 2017 might take 2-3 months with a skilled team of serious security engineers; now my intern can get into police radios without knowing anything about the underlaying technology, essentially on a whim.
any random tier 1 IT drone who can define a VLAN can potentially hit as hard as that team of security engineers now
agileAlligator · · focus · HN ↗