Why aren't they running agents on isolated computers without Internet access? This way, breaking free of containers would not matter.
It is truly a security nightmare that so many people are have given agents root access to their entire computers, in addition to presumably very private personal information.
Anthropic claims that their intention with the agents that led to the Hugging Face hack was an offline experiment running against a hacking benchmark.
Either you're being pedantic and missing the entire point, or you're saying that Anthropic lied and made a fake sandbox knowing their agents would need to connect to the internet anyways.
OpenAI was involved in the hugging face incident, not anthropic, and yes, inadequate sandboxing was a major factor, even the wikipedia page states this: <a href="https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_incident" rel="nofollow">https://en.wikipedia.org/wiki/OpenAI%E2%80%93HuggingFace_inc...
psyklic · · focus · HN ↗
It is truly a security nightmare that so many people are have given agents root access to their entire computers, in addition to presumably very private personal information.
NiloCK · · focus · HN ↗
Specifically, bad at search and returning information with references, bad at discovering and debugging package versioning conflicts, etc.
It's a Metcalf thing. The utility of an agent grows in some fn of the tools it owns. Skilled tool use comes from rich training environments.
jackb4040 · · focus · HN ↗
Either you're being pedantic and missing the entire point, or you're saying that Anthropic lied and made a fake sandbox knowing their agents would need to connect to the internet anyways.
voidhorse · · focus · HN ↗