logoalt Hacker News

ctolsen • yesterday at 11:08 PM • 14 replies • view on HN

My biggest takeaway from this is just how godawful the sandboxing is. The stuff written up in OpenAIs report says more about lack of extremely basic sysadmin skills than anything else.

I’m not that surprised about models with endless compute being capable of this, I’m more surprised that a company with the resources they have apparently can only create a sandbox that a half skilled human operator could have broken out of easily.


Replies

no-name-here • today at 4:23 AM

> can only create a sandbox that a half skilled human operator could have broken out of easily

The exploit:

> The ExploitGym evaluation environment did not provide the models with direct Internet access. To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy. We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor. [1]

Are "half skilled human operators" "easily" able to find zero-day vulnerabilities in a sandbox with only one line to the internet (the commercial package registry cache proxy)?

[1] https://openai.com/index/hugging-face-model-evaluation-secur...

➕ show 5 replies
olwmc • yesterday at 11:45 PM

This was my thought as well. Literally take any halfway decent greybeard and point them at "Hey, give us a sandbox for this kind of thing". I honestly was skeptical that they just vibecoded the entire thing but now more than ever I think they did.

➕ show 2 replies
foobarbecue • today at 2:57 AM

And their latest breathless "rogue agent hack" brag is about how they compromised customer data https://www.theguardian.com/technology/2026/sep/25/openai-ag... . How are they getting away with this level of malpractice???

➕ show 1 reply
sdenton4 • today at 5:18 AM

If you're testing models by telling them 'go wild, do the evil so we can test how good you can do the evil' and have p(doom)>0, you should not have a sandbox.

You should have a fscking air gap.

Treat it like nukes when you're turning the safety filters off. This is very much OpenAI screwing up, running obviously unsafe tests.

➕ show 2 replies
gbrindisi • yesterday at 11:33 PM

Not just sandboxing but overall security engineering practices on both sides

➕ show 1 reply
meffmadd • today at 7:27 AM

Yes and while they go on to talk about how dangerous this stuff they build is and the talk of „pacing“ etc. Vibe coding your sandbox in half a day does not seem all that responsible to me… Also if any institution other than an American AI company did this, everyone would loose their minds!

notyourwork • today at 8:06 PM

Administration by vibes.

piyh • today at 2:51 AM

Yes, but do you really think that a stronger sandbox would have been a more beneficial outcome here? I'd rather know that we're on the cusp of losing control now than in 3 months when best practice sandbox mitigations fall to the next, more capable unaligned model

dmazzoni • today at 7:05 AM

I can forgive them for having a bug in their sandbox.

I can't forgive them for failing to do any monitoring whatsoever.

bushbaba • today at 1:42 AM

Less a lack of skill and more a lack of care

esseph • today at 4:01 AM

TBH, I do not believe it is possible to create a sandbox that cannot be escaped by a long running agent. I thought the entire concept was a fools errand from the very beginning.

(Complete airgap, and that may not be enough. No networking.)

SV_BubbleTime • today at 3:33 AM

I’m a pretty firm believer that this was intentional and that they wanted it to escape the sandbox.

Woo look at escaped our sandbox, so scary! Be scared! Be scared now! Call your representative and do tell him how scared you are!

Yeah, I mean our sandbox was a paper bag, but don’t focus on that.

➕ show 2 replies
aaroninsf • today at 2:17 AM

A friend is of the opinion that getting out of the sandbox was actually intentional, and in service of a second line of business.

➕ show 1 reply
Quarrelsome • today at 1:15 AM

how did it break the sandbox? I felt like the article just jumped us into "it has GET privileges now".

➕ show 1 reply