7 ms·
My argument there is likely there was too much surface area in the environmental to start with. If your webserver bundled the kitchen sink but you never used i
by jpc0 25d ago
My argument there is likely there was too much surface area in the environmental to start with.
If your webserver bundled the kitchen sink but you never used it the easiest way to make it more secure is to remove the kitchen sink from production code/codepaths.
There may very well be legitimate edge cases where there is some novel issue found but in some of these cases the AI had arbitrary web access when all the task required was very specific web access, we’ve been able to parse urls for a very long time and it is rather trivial to just deny a toolcall if it is outside of the expected domain.
But that’s the hard way that requires time and diligence to do, the easy way is give it access to curl and ask it to not do anything bad while setting up its only feedback to be to solve the problem at hand.
We are really in an age where there are many exploits being found and patched, if an AI made use of a novel exploit then great, write up a report, patch/report the bug and apologise.
But using a case of clear engineering failure, and yes even if the failure is despite your best efforts, for marketing really does not seem like you have any intent to correct the issue.
And we can loop all the way back to regulation of AI, if the industry refuses to be better then governmental will do it instead and their solution will very likely be inferior in all ways.