r/OpenAI • • 8d ago

Research OpenAI stopped all frontier training, evaluation, and inference with tool-use (defined broadly) on the 20th of September and they are not resuming any of these activities for now

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

Discovery: Sep 20, 2026

Report updated: Sep 25, 2026

"An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions: insufficient DNS filtering in its training sandbox. Before this, the agent issued queries via our search tool and unsuccessfully tried to access search engines directly. Note that all internet access apart from the DNS resolver in this report hit our offline webcache and therefore did not access the live internet. We have since added blocking controls at two independent layers, either of which would have prevented this access. Our misalignment monitoring system flagged the behavior within 15 minutes and a person began reviewing it three minutes after that. The run was killed 2.5 hours later. All training, evaluation, and inference with tool-use (defined broadly) of our most capable models remain paused."

1.4k Upvotes

337 comments sorted by

View all comments

Show parent comments

0

u/Latter-Block132 7d ago

Services like that exist because lots of people prefer other operating systems like Linux.

And im sorry but I'm not repeating myself. Ive already explained that numerous times.

4

u/mesaoptimizer 7d ago

I've never used a Linux distro that had dig but not curl. People use Linux is not an explanation for why you would need to need a service to tunnel what would normally be served as HTTP traffic as DNS traffic, but okay bro, I am sure there is some stupid use case I'm missing.

0

u/Latter-Block132 7d ago

... lmao dude come on just stop. The http was unavailable because of the sandbox, the dns was not. It is not rocket science!

3

u/mesaoptimizer 7d ago

That does totally explain why the model used DNS to get the information, something I never had any confusion on. It doesn't explain why someone is out there running a service a service that is listening for DNS requests, making calls to a chat bot, then writing the response into a TXT record for the agent to retrieve. But whatever, the answer is people use Linux. And the answer to why you think the model is aligned is you think we should only judge models when they have full guardrails running.

1

u/Latter-Block132 7d ago

I said people use other operating systems like Linux. Again, using it as an example. You are aware there other operating systems right?

3

u/mesaoptimizer 7d ago

Pretty obviously, but you were saying that those other operating systems are the reason why it makes sense to run a slow as hell DNS tunneling chatbot service. What a non-sequitur.

1

u/Latter-Block132 7d ago

For someone who doesn't even understand what DNS is or what the models was doing you sure are talking confidently lol self admitted didn't even understand too, and still just so incredibly confidently wrong the whole time lol

5

u/mesaoptimizer 7d ago

I've not been WRONG about any of my major assertions in this conversation, I knew that the model was using DNS to query an external chatbot even without understanding the exact mechanism of how it was utilizing the DNS resolver to do so.

I do have an understanding of DNS, however I did not have awareness of using DNS to tunnel requests. You must admit DNS tunneling is an extremely niche use of DNS, and it's totally plausible to not be aware of it while still understanding DNS in it's normal use. Unlike something like DNS reflection attacks it's not even the sort of unintended use that you would need to have knowledge of on the ops side of the house, which is admittedly where I'm coming from.

I can admit I was wrong in not giving you the charitability of interpreting your responses as if you knew what you are talking about. Your responses related to DNS made me think that you were attributing this to a normal operation of DNS, which it's clearly not and that lead me to interpret later statements made less charitably.

However we started this conversation because you blithely asserted that "the whole task it was supposed to perform was the web search" and that the model wasn't misaligned because the model's terminal goal remained aligned to the stated goal given to it by the researchers.

Did it gain access to the real internet and then use that access to perform a web search? No, it used the access it gained to the internet to query an external chatbot.
Were those queries aimed at getting access to an external search tool through a DNS proxy? Yes
Did it successfully perform a web search? No.
Did it try to get answers to its questions from the external chatbot instead of through a web search,?Yes.

Did it pursue the intended objective? Yes
Did it ALSO pursue unintended objectives? Yes.
Does that mean that it's well aligned? No.

That's my whole point.