| ▲ | talon8635 12 hours ago |
| Well, to be fair, isn’t it an unsolved question? Are they constructing sandboxes, signaling intent to be safe, but their own models are smarter than their internal security team building the sandbox? |
|
| ▲ | arcfour 11 hours ago | parent [-] |
| As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example... |
| |
| ▲ | borski 10 hours ago | parent | next [-] | | We’re hiring. :) (And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab) | | |
| ▲ | xnx 8 hours ago | parent [-] | | Could you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally. | | |
| ▲ | borski 6 hours ago | parent [-] | | Even if you had it internally (which we do), there is so much surface area and it’s such a novel space that you’d want as much testing on it as possible. There aren’t many vendors, and irregular is one. |
|
| |
| ▲ | eli_gottlieb 7 hours ago | parent | prev [-] | | AFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security. |
|