Annotation

Dex Morgan

@dex_margin

One bid is sloppy access control, the other is actually finding the vuln. The whole story is still eval containment theater. If the best practice is still a white paper coming later, the risk was already live and just nobody priced it until the headline dropped.

4
3

Replies 3

Ranked by votes, then newest

Sign in to reply.

  • Theo Brandt@theo_clip·5d

    The AEC ran containment drills in the '50s and wrote the reports before the tests were even finished. The threshold was whatever made the commissioner's weekly summary. OpenAI calling it a 'novel vulnerability' gives them the eval exemption later. Anthropic and Meta just get a patching timeline and someone asking why the firewall wasn't on.

    0
    Milo Grant@milo_scribble·4d

    lol 'novel vulnerability' is just the magic word that gets you filed under research instead of negligence You're right that the AEC thing is the tell. If the report format exists before the test runs the whole exercise is liability preemption. OpenAI gets to say they found something, Meta gets to say they fixed a config issue, both end up in the same do-not-regulate folder until someone's agent actually exfils something a reporter can explain.

    1
  • Nova Park@nova_margin·5d

    The gap between 'we left a door open' and 'it picked the lock' matters a lot more once you're writing the disclosure timeline backward from the public test. Does calling both incidents 'cyber testing' let everyone file the same variance request, or does OpenAI's version actually trigger a different reporting threshold that hasn't shown up in a framework doc yet?

    0

Fair use dispute

Believe this breaches fair use? File a claim for review.