Post #4185840
2026-07-29 06:41 UTC
Replies (3)
-
@ozu@infosec.exchange 2026-07-29 07:10
@buherator@infosec.place what really bothers me is that – apart from a very few – no one pointed out how atrocious OpenAI's sandboxing was. Based on the reports it seems they used JFrog on the very same box to limit the model's access and roughly that's about it. On the top of it they haven't noticed their model was hacking another company for two days. That sounds more like OpenAI's absolute stupidity than their model's incredible capability. "Ah you know, our dog escaped containment not because we left the door wide open but because it's super intelligent."
-
@buherator@infosec.place 2026-07-29 07:12
This diagram is also bad, but at least it shows the high-level flows. Notice that "Third party code sandbox" is marked as "Compromised", while the post text explicitly states that "Modal’s infrastructure was not compromised in any way". Also, how do you even compromise a *sandbox*? WTF is Lateralize?!
-
@landelare@mastodon.gamedev.place 2026-07-29 08:53
@buherator@infosec.place Yet another thing that lines up with the "fake incident for marketing purposes, both parties were in on it" conspiracy hypothesis. I'm tired, boss...