Replit从2016年就在跑沙箱,被各路黑客盯过,他们总结的防御思路比空谈AI威胁实在多了。
Replit CEO Amjad Masad在推文中指出,多数AI公司和沙箱供应商在安全上犯了基本错误。Replit自2016年起运行沙箱,长期应对黑客与国家行为体的攻击。他建议安全团队必须假设零日漏洞存在,并基于零信任框架设计多层防护。相关防御策略细节发布在Replit官方博客上。
Sandboxes are hard. With all the “AI escaping sandbox” it’s easy to think “wow AI so scary,” but m...
Sandboxes are hard. With all the “AI escaping sandbox” it’s easy to think “wow AI so scary,” but most AI companies, and recent “sandbox providers” are making very basic mistakes. At Replit we’ve been running sandboxes since 2016 and targeted by every hacker and state actor under the sun. So we learned a thing or two. Main advice: Assume zero-days exist — because they do — and think in layers of protection in a zero-trust framework. More here: replit.com/blog/defense-i… 💬 11 🔄 4 ❤️ 93 👀 5936 📊 23 ⚡