How we Rooted Copilot
-
This post did not contain any content.
-
This post did not contain any content.
$10 says they haven't actually escaped anything and it's just hallucinating a directory structure & file contents
-
$10 says they haven't actually escaped anything and it's just hallucinating a directory structure & file contents
Even if it had access to its own source during training, the chances of it regurgitating it with total fidelity are zero.
-
This post did not contain any content.
And so Microsoft decided this wasn't a big enough vulnerability to pay them a bounty. Why the fuck would you ever share that with them then, if you could sell it to a black-hat hacking org for thousands?
-
$10 says they haven't actually escaped anything and it's just hallucinating a directory structure & file contents
-
MS said they fixed it and categorised it as a "moderate severity vulnerability" so presumably they did in fact gain root access to the container
If they gained root access to the container, that's not a moderate vulnerability. Root inside a container is still root. You can still access the kernel with root privs and it's the same kernel as the host.
Docker is not a virtual machine.
-
If they gained root access to the container, that's not a moderate vulnerability. Root inside a container is still root. You can still access the kernel with root privs and it's the same kernel as the host.
Docker is not a virtual machine.
-
And so Microsoft decided this wasn't a big enough vulnerability to pay them a bounty. Why the fuck would you ever share that with them then, if you could sell it to a black-hat hacking org for thousands?
There may not have been any logical progression beyond the container.
-
I know that? I'm just saying that MS categorised it as such. It would be strange to include the part about MS's responses if MS also found that the vulnerability was not what the researchers claimed it was.
What I'm saying is something about the story doesn't add up.
Either Microsoft classified a major issue as a minor one so they didn't have to payout the bug bounty (quite possible), or the attack didn't achieve what the researchers thought it did and Microsoft classified it according to it's actual results.
-
What I'm saying is something about the story doesn't add up.
Either Microsoft classified a major issue as a minor one so they didn't have to payout the bug bounty (quite possible), or the attack didn't achieve what the researchers thought it did and Microsoft classified it according to it's actual results.
If I have to choose between either ms or an unknown being correct, I pick the unknown person.
-
-
-
-
-
Airbnb’s Dying Software Gets a Second Life: The AI boom has revitalized a stagnant open-source project
Technology1
-
-
Meta(Facebook) and Yandex apps silently de-anonymize users’ browsing habits without consent.
Technology1
-
Startups and Big Tech firms cut hiring of recent graduates by 11% and 25% respectively in 2024 vs. 2023, as AI can handle routine, low-risk tasks
Technology1