Register and share your invite link to earn from video plays and referrals.

s1r1us
@S1r1u5_
wannabe hacker | founder @HacktronAI
Joined July 2015
2.6K Following    25.7K Followers
I want to be very clear about this. just because we found one serious exploit on openai does not mean we know how to secure an organization that complex. openai has security people with far more experience and better qualified doing that than us, and i don’t want to pretend we have solutions. note, i was saying "they are building manhattan project", it is not a belief i strongly hold, i don’t like making confident predictions about the future. it is the labs that make those comparisons. what I know for a fact is that these models already have serious offensive cyber capabilities, what that does to the world, I don’t know, but my loosely held view is that it might lead to a period of turbulence because i think its offense dominant than defense having said that, what i don’t understand is this, if the people building these systems truly believe they are powerful enough to create nuclear level risks, and they are talking about slowing down because of those risks, why is that work is done through ordinary saas products? why is it happening through slack, managed github, employee browsers, and apps accessible from the public internet? every third party and library they use becomes part of the attack surface. remember the jfrog registry in the hugging face agent swarm? it didn’t matter that it was a third party, it was in the path. an attacker, or an unaligned model, doesn’t care who owns it or its out of scope. they will hack whatever is in the path to achieve their goal. one more concerning thing is, why are codex cloud, claude(assuming anthropic does the same) publicly accessible web applications connected directly to private github repositories? again shouting my lungs out, coding agents on the cloud is worst thing happened in terms of security, it is going backwards. your browser becomes a attack surface, a lame xss, stolen creds, phishing, browser exploits, all these bugs can achieve similar impactful bugs as we shown. like, you don't need to pivot anymore and worry much about exfiling, just compromise cloud agent its all over either through client-side browser or the server.
Show more