← Back to context

Comment by ctolsen

20 hours ago

> Are "half skilled human operators" "easily" able to find zero-day vulnerabilities in a sandbox with only one line to the internet (the commercial package registry cache proxy)?

Yes. It’s a fairly simple SSRF attack as far as I can tell. One of the first things I’d try. Especially considering that I would already be armed with the information that I have no internet access except through a thing that downloads things off the internet for me.

Calling it zero day makes it sound elusive. It’s a bug in closed software that has like 40 CVEs this year alone. Tools like that, especially in internal networks, don’t get much scrutiny and are often riddled with issues.

> Calling it zero day makes it sound elusive ... has like 40 CVEs this year alone.

1. I clicked into ~20 of the recent CVEs, and it looks like about all of them came from openai or anthropic research?

2. In fact, every CVE in the last 2 years came from the last few months -- i.e. other than these recent CVEs, you'd have go back more than 2 years ago to find a single other CVE.

  • So like I said: unscrutinised and riddled with issues.

    • >>>> a sandbox that a half skilled human operator could have broken out of easily

      >>> Are "half skilled human operators" "easily" able to find zero-day vulnerabilities in a sandbox

      >> Calling it zero day makes it sound elusive ... like 40 CVEs this year alone.

      > [The CVEs] came from openai or anthropic research? In fact, every CVE in the last 2 years came from the last few months

      I still don't understand how you can specifically point to zero CVEs being discovered by humans for year(s), then ~40 being discovered once OpenAI/Anthropic start looking at it, as the only(?) piece of data you provided to support the claim "a half skilled human" could have "easily" found/done this?

      14 replies →