| ▲ | arcfour 11 hours ago | ||||||||||||||||
As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example... | |||||||||||||||||
| ▲ | borski 10 hours ago | parent | next [-] | ||||||||||||||||
We’re hiring. :) (And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab) | |||||||||||||||||
| |||||||||||||||||
| ▲ | eli_gottlieb 7 hours ago | parent | prev [-] | ||||||||||||||||
AFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security. | |||||||||||||||||