logoalt Hacker News

jbrooks84 • today at 12:01 AM • 1 reply • view on HN

Yup literally no security and they wonder how they got out


Replies

no-name-here • today at 5:15 AM

> literally no security

What is the source that there was "literally no security"?

> and they wonder how they got out

OpenAI publicly announced months ago how the model got out:

> The ExploitGym evaluation environment did not provide the models with direct Internet access. To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy. We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor. [1]

[1] https://openai.com/index/hugging-face-model-evaluation-secur...