← Back to context

Comment by talon8635

12 hours ago

Well, to be fair, isn’t it an unsolved question? Are they constructing sandboxes, signaling intent to be safe, but their own models are smarter than their internal security team building the sandbox?

As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example...

  • We’re hiring. :)

    (And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab)

    • Could you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally.

      1 reply →

  • AFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security.