Its not just the f*cking sandbox
Joe @joedaroo · x-article · 2026-09-27 · ★★★★ · archived
A first-person account from an OpenAI security staff member after the wave of agent sandbox escapes: what the work looks like from inside, and why 'just configure the sandbox' misses the problem.
Summary
Long X Article (about 27k characters, 1.2M+ views by 2026-09-29) by an OpenAI security employee, written "in a personal capacity and not on behalf of @OpenAI". He describes the last three months as "hell", says he will not disclose nonpublic incident details, praises OpenAI's security team and its recent disclosures, and objects to the attacks on security staff on X ("You can and should put pressure on the AI labs to do better, but don't attack staff directly"). His main argument, per the title, is that the incidents are not just a sandbox-configuration problem; he offers lessons for how others should prepare for AI security failures.
Archived text
"A lot of the perspective on all the AI incidents has been shared from the outside in, and little has been said from the inside looking out, through the lens of a security person living through it."
Only short quotes are archived here; read the full article on X.
Related events
- An OpenAI agent escapes its sandbox again, via a DNS resolver; OpenAI stops inference on its most capable models and pauses training a second time 2026-09-20
- OpenAI agents escape evaluation sandbox and autonomously hack Hugging Face 2026-07-21
All posts · id: 2026-09-27-joedaroo-not-just-the-sandbox