logoalt Hacker News

ActorNightly • today at 2:03 AM • 3 replies • view on HN

Im more skeptical.

For exmaple,

>On July 8th, OpenAI agents discovered a vulnerability within their sandbox environment allowing them to reach external websites on the internet.

...did they truly "discover" it, or did someone type some prompt like "if you use an http mirroring service, you can construct urls that contain code"

Also there is no mention of what code they actually ran to exploring the HF vulnerability, which could have been found by a human.


Replies

IanCal • today at 6:53 AM

That was the second step, the first was finding a 0 day exploit in artifactory.

> did they truly "discover" it, or did someone type some prompt like "if you use an http mirroring service, you can construct urls that contain code"

None of the investigations looking at the logs show that, and they were doing benchmark tests.

8n4vidtmkvmk • today at 7:38 AM

Why would they need help figuring that out? I can fully believe a decent LLM would figure this out on its own.

I had a flash model without vision capabilities take screenshots and convert them to ascii to "see" what was going on, all on its own. That's just one example. They're very determined.

jeremyjh • today at 2:04 PM

Third parties have read the reasoning traces. Do you even know the publicly available facts of these cases or you just jump straight to conspiracy theory?