Reddit
Hacker News Security Practitioners Tear Into OpenAI's Astra Disclosure: 'They Found Their Agents Had RCE'd Artifactory Once, Reported It, and Kept Using It Unmonitored'
The OpenAI critical-cyber post drew 188 points and 181 comments on Hacker News within 19 hours, and the reaction was overwhelmingly about containment negligence rather than model capability. Commenters noted OpenAI downgraded from the network-layer isolation used in the original ExploitGym to trusting repository server settings, then left the known-vulnerable Artifactory unmonitored for days; others argued ExploitGym's Docker/userspace sandboxing makes escape far more trivial than escaping ESXi or Proxmox, and several posted their own KVM/QEMU IPv4-only, no-mounted-volume agent isolation setups as the bar OpenAI failed to meet. A recurring minority read the whole disclosure as capability marketing.
↳ Follow the thread