Comment by serbuvlad

1 day ago

> or you proxy through your own service where you can ratelimit, inspect, and restrict the traffic

It literally seems like they are doing just that, and the agents are just finding holes in that.

If you own a network and the servers, you can DPI every single packet and see literally every bit of information. All of the text to the "forum" that they created must have been in -outbound- packets to their compromised package manager, by definition. If they can't properly analyze network traffic, they should not be running 'sandboxes'.

Anything beyond baseline would be observable- silence, malformed packets, too much egress, unusually large packets, etc

OpenAI should really do better. If you want to build a mostly airgapped system, you find the surface that bridges the inside part to the outside part, and you enumerate every single thing that can get through. Which presumably should be a very very small list and should not include DNS.

If you are using a firewall, you are already doing it wrong. Don’t list thinks to block - list things to allow and make that list small.

  • Yep and this is literally the most basic security 101. It isn't hard. They've had literally years and years to iron out the kinks in this setup as well. The only reason not to do it is pure negligence