logoalt Hacker News

ctolsen • yesterday at 11:08 PM • 7 replies • view on HN

My biggest takeaway from this is just how godawful the sandboxing is. The stuff written up in OpenAIs report says more about lack of extremely basic sysadmin skills than anything else.

I’m not that surprised about models with endless compute being capable of this, I’m more surprised that a company with the resources they have apparently can only create a sandbox that a half skilled human operator could have broken out of easily.


Replies

foobarbecue • today at 2:57 AM

And their latest breathless "rogue agent hack" brag is about how they compromised customer data https://www.theguardian.com/technology/2026/sep/25/openai-ag... . How are they getting away with this level of malpractice???

➕ show 1 reply
olwmc • yesterday at 11:45 PM

This was my thought as well. Literally take any halfway decent greybeard and point them at "Hey, give us a sandbox for this kind of thing". I honestly was skeptical that they just vibecoded the entire thing but now more than ever I think they did.

➕ show 2 replies
gbrindisi • yesterday at 11:33 PM

Not just sandboxing but overall security engineering practices on both sides

➕ show 1 reply
piyh • today at 2:51 AM

Yes, but do you really think that a stronger sandbox would have been a more beneficial outcome here? I'd rather know that we're on the cusp of losing control now than in 3 months when best practice sandbox mitigations fall to the next, more capable unaligned model

bushbaba • today at 1:42 AM

Less a lack of skill and more a lack of care

aaroninsf • today at 2:17 AM

A friend is of the opinion that getting out of the sandbox was actually intentional, and in service of a second line of business.

➕ show 1 reply
Quarrelsome • today at 1:15 AM

how did it break the sandbox? I felt like the article just jumped us into "it has GET privileges now".