Post #4441001
2026-08-07 14:29 UTC
I haven’t settled my thoughts on the OpenAI incident but I can’t help but feel that the threat modelling & security engineering applied up-front to long-term xhigh training runs with no cyber guard-rails was seriously shoddy. Easy to say after the fact. (1/3)
Replies (1)
-
@singe@chaos.social 2026-08-07 14:29
A shared package proxy vulnerable to file writes with a simple PUT, that was exploited with hundreds (thousands?) of writes by many different agents speaks both to shoddy security, monitoring and a failure of imagination. Then to have it happen again without a major rethink! (2/3)