Even if it had access to its own source during training, the chances of it regurgitating it with total fidelity are zero.
Comment on How we Rooted Copilot
nathan@piefed.alphapuggle.dev 1 week ago
$10 says they haven't actually escaped anything and it's just hallucinating a directory structure & file contents
MagicShel@lemmy.zip 1 week ago
communism@lemmy.ml 1 week ago
MS said they fixed it and categorised it as a “moderate severity vulnerability” so presumably they did in fact gain root access to the container
wewbull@feddit.uk 1 week ago
If they gained root access to the container, that’s not a moderate vulnerability. Root inside a container is still root. You can still access the kernel with root privs and it’s the same kernel as the host.
Docker is not a virtual machine.
communism@lemmy.ml 1 week ago
I know that? I’m just saying that MS categorised it as such. It would be strange to include the part about MS’s responses if MS also found that the vulnerability was not what the researchers claimed it was.
wewbull@feddit.uk 1 week ago
What I’m saying is something about the story doesn’t add up.
Either Microsoft classified a major issue as a minor one so they didn’t have to payout the bug bounty (quite possible), or the attack didn’t achieve what the researchers thought it did and Microsoft classified it according to it’s actual results.
Grappling7155@lemmy.ca 1 week ago
Docker isn’t, but I was under the impression that hyperscalars tended to put all their containers in lightweight VMs (like kata containers) anyways for security purposes
ftbd@feddit.org 1 week ago
That assumes the container itself is run as root, right?
Fizz@lemmy.nz 1 week ago
I think they gained root to the python env which they couldn’t do anything with because it was still running in docker inside a VM.