| ▲ | simonw 2 days ago |
| It sounds like the third-party sandbox was hosted by Modal: https://www.reuters.com/business/openais-rogue-agent-comprom... > "We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution," Bubna said in a statement. "This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway." |
|
| ▲ | onesociety2022 21 hours ago | parent [-] |
| They don't seem to explain how it managed to find this unauthenticated endpoint hosted on Modal's platform. |
| |
| ▲ | simonw 20 hours ago | parent [-] | | Modal are a hosting provider. It sounds to me like someone building on Modal deployed their own product that had an unauthenticated endpoint that could be used to launch and interact with a container. | | |
| ▲ | what 13 hours ago | parent | next [-] | | That doesn’t explain how the endpoint was found… | | |
| ▲ | brunoarueira 5 hours ago | parent [-] | | Through the timeline, Hugging Face said that the rogue agent ran quietly and do a bunch of code search, so probably the endpoint is/was public through some repositories or the CyberGym style announce something like a broadcast. I don't have any expertise on this, just ideas that came to my mind! |
| |
| ▲ | 19 hours ago | parent | prev [-] | | [deleted] |
|
|