Reproducing here an interesting comment I saw on Reddit:

OnlineParacosm • 23m ago

I’ve read security disclosures for 15 years and let me tell you guys I’ve never read anything quite like that blog post.

Based on this blog, it sounds like they intentionally turned off safety guardrails to test offensive capabilities. The deception here is burying the lede: they appear to have intentionally unleashed an unrestricted offensive cyber-agent, connected it to a system with a path to the internet, and it immediately attacked a major partner. The blog glosses over the gross negligence of giving an autonomous, unrestricted cyber-offense model a pathway to lateral movement.

There’s an entire cybersecurity specialization just for just vendor supply chain risk assessment, and their job is essentially to audit who you do business with as a company to determine if they are jokers. I would pay money to be a fly on the wall of one of those emergency meetings taking place right now after hours.

Any CISO in here looking forward to explaining this one tomorrow? Here I’ll open with the dumbest question you’ll get “ how can we protect ourselves [from out partner that we won’t fire]”

    • deadcream@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      69
      ·
      edit-2
      22 hours ago

      That’s their modus operandi. Next they will claim that it’s totally an agi and is too dangerous to release, before starting to sell it. Or is this anthropic’s playbook?

      • boonhet@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        11
        ·
        13 hours ago

        Both of them. Dario started doing it when he was still in OpenAI and now does it with Anthropic.

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      21
      arrow-down
      3
      ·
      20 hours ago

      Is it really great marketing to admit that you’re too incompetent to contain your own AI models? And that your irresponsibility caused serious damage to an open source contributor?

      • Dave.@aussie.zone
        link
        fedilink
        English
        arrow-up
        9
        ·
        19 hours ago

        Seems like a quick way to get all your research and assets forcefully absorbed into a shadowy government department.

      • architect@thelemmy.club
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        15
        ·
        19 hours ago

        Yall are like “AI SUCKS AT EVERYTHING CAN’T EVEN TELL ME WHEN MY ASS NEEDS WIPING! INCOMPETENCE”

        To: oh ai can hack major platforms they are incompetent!

        Pick a fucking lane.

        • artyom@piefed.social
          link
          fedilink
          English
          arrow-up
          11
          arrow-down
          1
          ·
          18 hours ago

          Not sure what you mean. Those are both excellent examples of incompetence.