VMs won't contain cyber-capable agents
16 points by equeue
16 points by equeue
This title overstates the matter doesn’t it?
the author tried to have SOTA gpt break out of firecracker and it couldn’t. So.. vms can contain agents..?
when the agent broke out of qemu it was run from the host. It had full context of the host. So the agent cheated. Even if it doesn’t modify host memory from outside it had context that an agent in qemu wouldn’t so easily (or even maybe at all?) be able to get. So not that it’s impossible to break out of that vm setup , but this test is not proof that SOTA gpt even can.
I’m not a security person but at face value this seems overblown.
Knowing the environment ahead of time likely helped, but it is more of a question of time not capability.
It could have easily fingerprinted my distribution via SSH banner, CUPS sever exploit, QEMU device version strings, or just pulling kernel and QEMU and dependency source, examining differences in behavior as changed in different commits and establishing a plausible version range. Its tedious, but the agent does not get tired.
It is also very careful in its exploitation; it used host memory read primitives where possible to ensure vulnerability and reliability.
Did I miss something or did the agent read the flag file? I don't see a clear statement on that point.
Most of the listed exploits don't seem like actual escapes. Did any of those heap overflows or out of band memory accesses lead to privilege escalation?
Is it too soon to declare "cyber-capable" the dumbest word of the century?
I'm of two minds on these sorts of things:
I have no idea which is right
There are other interesting outcomes which I cannot rule out…
Economics and politics can play out differently, but there are interesting scenarios with significant tech component: