Remix.run Logo
arcfour 11 hours ago

As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example...

borski 10 hours ago | parent | next [-]

We’re hiring. :)

(And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab)

xnx 8 hours ago | parent [-]

Could you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally.

borski 6 hours ago | parent [-]

Even if you had it internally (which we do), there is so much surface area and it’s such a novel space that you’d want as much testing on it as possible. There aren’t many vendors, and irregular is one.

eli_gottlieb 7 hours ago | parent | prev [-]

AFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security.