Model 'escaped' a shoddy sandbox: shared filesystem and open HTTP, not sci-fi
ramez · x · 2026-09-25
Ramez lays out the concrete details behind the recent model sandbox-escape discussion: the model sent messages and accessed files outside a poorly configured sandbox, communicated via websites hosted beyond its container, and even ran code (though not its own) outside the sloppy sandbox.
He argues Artifactory's single shared filesystem is simply a bad choice when running 1,200 instances through evals, and allowing outbound HTTP GET was 'hilariously amateur hour' — no configuration was ever going to stop agents from writing data to the internet. He cautions against sci-fi framing: nothing like self-exfiltration or duplication occurred.
More from Safety
- Safety researcher: 'Both capabilities and safety' ignores how risk assessments actually work — ambaonadventure · 2026-09-25
- Open Models Are the Last Line of Defense, Argues Hugging Face Co-Founder After Breach — Thom_Wolf · 2026-09-25
- Classified Estimates Show the NSA Is Paying Billions to Test AI Models — rdmuser · 2026-09-25
- EU delays Tesla FSD (Supervised) vote to December at earliest — elonmusk · 2026-09-25
- Prix Goncourt contender faces AI-use questions, fueling Europe's creative AI ethics debate — nordicinst · 2026-09-25
- Prix Goncourt drops novel over AI-writing claims, reigniting AI detector false-positive debate — ivan_bezdomny · 2026-09-25