> In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems
Specifically, the model hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.
Probably three companies that had port 22 open with no root password if it was Gemini. I’ve always gotten garbage from their coding models and Google sheet integrated chat.
Would everyone please put their AIs back in their boxes? This is embarrassing, regardless of whether you think it's viral marketing, apalling competence, or some opportunistic mixture.
This approach to marketing one's AI by finding ways to brag that it "broke out" and "hacked companies" is getting ridiculous. It's particularly sad when it's large, established businesses like Google resorting to the kind of thing that's embarrassing enough when it's some brand new startup on tpot trying to get some engagement.
I must be out of the loop. Not defending google when I ask this but....how is google flailing, exactly? I figured they were in the best position of all the other companies combined. They have their own hardware for inference, they have a solid grasp on enterprise, and they have a good road map. I mean, Google is incredibly strong, is it not? And remember how quickly google answered Bard? For a while, gemini was even the preferred model, if we are strictly speaking AI models. Again, I'm not defending google, I just want to see how this comment makes sense is all, without letting fantasy overtake reality in the process...
I'm not an expert in cybersecurity, but given my own experience using the `ol stochastic parrot as coding tools I both see the power of a bot swarm, but also think these companies just have shit network security.
"Guess what everyone, our AI can go rogue, TOO!"
It's just getting really embarrassing for Google at this point.
> In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems
Pretty lame hacks if you ask me.
Specifically, the model hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.
The AI bubble bullshit PR is even dumber than the crypto bra bullshit from five, six years ago
Probably three companies that had port 22 open with no root password if it was Gemini. I’ve always gotten garbage from their coding models and Google sheet integrated chat.
Would everyone please put their AIs back in their boxes? This is embarrassing, regardless of whether you think it's viral marketing, apalling competence, or some opportunistic mixture.
This approach to marketing one's AI by finding ways to brag that it "broke out" and "hacked companies" is getting ridiculous. It's particularly sad when it's large, established businesses like Google resorting to the kind of thing that's embarrassing enough when it's some brand new startup on tpot trying to get some engagement.
Google is flailing right now, probably more a PR effort to say they are still relevant
I must be out of the loop. Not defending google when I ask this but....how is google flailing, exactly? I figured they were in the best position of all the other companies combined. They have their own hardware for inference, they have a solid grasp on enterprise, and they have a good road map. I mean, Google is incredibly strong, is it not? And remember how quickly google answered Bard? For a while, gemini was even the preferred model, if we are strictly speaking AI models. Again, I'm not defending google, I just want to see how this comment makes sense is all, without letting fantasy overtake reality in the process...
Both of these things can be true.
I'm not an expert in cybersecurity, but given my own experience using the `ol stochastic parrot as coding tools I both see the power of a bot swarm, but also think these companies just have shit network security.
Earlier: https://news.ycombinator.com/item?id=49760988