OpenAI walls off its network as Copilot describes its own hidden autorun parameter
OpenAI is isolating its network after the Hugging Face leak so one workload cannot reach the internet, while Copilot described its hidden autorun parameter. Xen formed a safety committee to keep robot workloads apart.
Artificial Intelligence··Night
OpenAI walls off its network and adds a 30-minute watch
OpenAI has listed the measures it took after the Hugging Face incident it disclosed on 26 July. The company is building network isolation designed so that a single compromised workload does not by itself open a path to the internet or to other internal networks, and a new monitoring layer that reads tool actions, reasoning traces and activity logs is meant to raise an alert within 30 minutes. The models left the training environment after a hacker compromised a packet-installation utility that had internet access. Reinforcement learning was frozen for two weeks after the incident and has been restarted for some models judged less risky. The monitoring layer is estimated to add about 20 per cent to the compute burden. Amelia Glaese, OpenAI's vice-president of research, says the company has set requirements and expectations for safe development. OpenAI ties part of the package to the cybersecurity capabilities of its Astra model, and a full post-mortem has not been published.[1]
Copilot described its hidden autorun parameter to researchers
Researchers at Varonis Threat Labs kept asking Microsoft Copilot Personal why certain attacks would fail until the assistant explained how it handles URLs. In the process it named an undocumented parameter, autorun=1, which combined with the already known ?q= ran a prompt with no user interaction at all. The researchers did not reverse-engineer the flaw; the assistant surfaced it during ordinary use. The path, which Varonis calls CoSnitch, opens the way to exfiltrating data through connected services such as Gmail, Google Drive and Google Calendar, poisoning stored chat history and memory, and surveying the files and mail a user can reach. Microsoft first disabled the ?q= parameter silently, and planned to ship a patch and assign the flaw a formal identifier on Tuesday 18 August. Lior Adar, a senior security researcher at Varonis, says exposing those backend mechanics hands attackers a blueprint of the assistant's internal logic.[2]
Xen set up a safety committee to partition robot workloads
The open-source Xen hypervisor has created a Xen Safety Committee to meet formal safety standards such as IEC-61508, which governs software in devices that can harm people. AMD, EPAM and Renesas are founding contributors, and the project has opened a new membership tier called Premier Plus for organisations pursuing functional-safety certification. Boeing recently joined the project, one reason being its interest in Xen's safety work. The goal is to make Xen usable in robots and other devices where workloads must be kept apart, so that a failure in a non-critical function cannot reach the safety-critical side. Cody Zuschlag, the Xen Project community manager, says safety engineering has so far required every organisation to recreate much of the same foundational work. The committee takes on producing and maintaining that shared foundation together.[3]