Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Uh, is that what they did? I didn't read their blog posting like that. But let's put that aside and focus on something else. How was it a failure of internal practice, what did they do wrong?

AIUI they used a proxy with a bug, which they reported as soon as they discovered it. Right? What should they have done, and what's the difference?



Monitoring that didn't take days to notice unauthorized external traffic would probably be a good start


I see.

I had the impression that "days" is already good as these things go, "months" being more common.


Months to recognize traffic escaping a sandbox you set up yourself?


No, unauthorised traffic across a firewall in general.

This involved some lateral movement, ie. traffic didn't just cross the intended sandbox border. Is that kind of thing simpler to detect than an intrusion?


The lateral movement was outside OAI's network. The security sandbox should have had an offline package cache and a strict internet whitelist. Detecting unauthorized traffic seems like one of the highest priorities of designing a security sandbox.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: