惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
K
Kaspersky official blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Latest
Security Latest
P
Privacy & Cybersecurity Law Blog
Google DeepMind News
Google DeepMind News
Simon Willison's Weblog
Simon Willison's Weblog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
人人都是产品经理
人人都是产品经理
O
OpenAI News
Help Net Security
Help Net Security
N
News and Events Feed by Topic
博客园 - 司徒正美
U
Unit 42
Security Archives - TechRepublic
Security Archives - TechRepublic
The Cloudflare Blog
D
DataBreaches.Net
Y
Y Combinator Blog
AI
AI
L
LINUX DO - 最新话题
C
CXSECURITY Database RSS Feed - CXSecurity.com
H
Heimdal Security Blog
宝玉的分享
宝玉的分享
C
CERT Recently Published Vulnerability Notes
博客园 - 聂微东
TaoSecurity Blog
TaoSecurity Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Jina AI
Jina AI
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Attack and Defense Labs
Attack and Defense Labs
V
V2EX
博客园 - 【当耐特】
S
SegmentFault 最新的问题
小众软件
小众软件
L
LangChain Blog
N
Netflix TechBlog - Medium
V
Vulnerabilities – Threatpost
T
Tor Project blog
AWS News Blog
AWS News Blog
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
G
GRAHAM CLULEY
Know Your Adversary
Know Your Adversary
S
Securelist
T
Troy Hunt's Blog

Replicate's blog

How to make remarkable videos with Seedance 2.0 – Replicate blog How to prompt Seedream 5.0 – Replicate blog Recraft V4: image generation with design taste – Replicate blog Run Isaac 0.1 on Replicate – Replicate blog Run FLUX.2 on Replicate – Replicate blog How to prompt Nano Banana Pro – Replicate blog Retro Diffusion's pixel art models are now on Replicate – Replicate blog Replicate is joining Cloudflare – Replicate blog Extract text from documents and images with Datalab Marker and OCR – Replicate blog How to prompt Veo 3.1 – Replicate blog IBM's Granite 4.0 is now on Replicate – Replicate blog Which image editing model should I use? – Replicate blog Introducing our new search API – Replicate blog Torch compile caching for inference speed – Replicate blog Announcing Replicate's remote MCP server – Replicate blog How to prompt Veo 3 with images – Replicate blog Open source video is back – Replicate blog Generate consistent characters – Replicate blog Bria is now on Replicate – Replicate blog How we optimized FLUX.1 Kontext [dev] – Replicate blog Compare AI video models – Replicate blog The FLUX.1 Kontext hackathon – Replicate blog How to prompt Veo 3 for the best results – Replicate blog Get the most from Google Veo 3 – Replicate blog FLUX.1 Kontext from the community – Replicate blog Use FLUX.1 Kontext to edit images with words – Replicate blog Generate incredible images with Google's Imagen 4 – Replicate blog Run OpenAI’s latest models on Replicate – Replicate blog NVIDIA H100 GPUs are here – Replicate blog Run 30,000+ LoRAs on Hugging Face with Replicate – Replicate blog Ideogram 3.0 on Replicate – Replicate blog Run MiniMax Speech-02 models with an API – Replicate blog Easel AI is now on Replicate – Replicate blog Stylized video with Wan2.1 – Replicate blog Creative roundup: avatars, lightsabers, and LoRA tricks – Replicate blog Wan2.1: generate videos with an API – Replicate blog Wan2.1 parameter sweep – Replicate blog You can now fine-tune open-source video models – Replicate blog Generate short videos with the Replicate playground – Replicate blog AI video is having its Stable Diffusion moment – Replicate blog FLUX fine-tunes are now fast – Replicate blog FLUX.1 Tools – Control and steerability for FLUX – Replicate blog NVIDIA L40S GPUs are here – Replicate blog Ideogram v2 is an outstanding new inpainting model – Replicate blog Stable Diffusion 3.5 is here – Replicate blog FLUX is fast and it's open source – Replicate blog FLUX1.1 [pro] is here – Replicate blog Using synthetic training data to improve Flux finetunes – Replicate blog Fine-tune FLUX.1 with an API – Replicate blog Fine-tune FLUX.1 to create images of yourself – Replicate blog Replicate Intelligence #12 – Replicate blog Replicate Intelligence #11 – Replicate blog Fine-tune FLUX.1 with your own images – Replicate blog Replicate Intelligence #10 – Replicate blog FLUX.1: First Impressions – Replicate blog Replicate Intelligence #9 – Replicate blog Run FLUX with an API – Replicate blog Replicate Intelligence #8 – Replicate blog Run Meta Llama 3.1 405B with an API – Replicate blog Replicate Intelligence #7 – Replicate blog Replicate Intelligence #6 – Replicate blog Replicate Intelligence #5 – Replicate blog How to get the best results from Stable Diffusion 3 – Replicate blog Run Stable Diffusion 3 on your Apple Silicon Mac – Replicate blog Push a custom version of Stable Diffusion 3 – Replicate blog Replicate Intelligence #4 – Replicate blog Run Stable Diffusion 3 on your own machine with ComfyUI – Replicate blog H100s are coming to Replicate – Replicate blog Run Stable Diffusion 3 with an API – Replicate blog Replicate Intelligence #3 – Replicate blog Replicate Intelligence #2 – Replicate blog Replicate Intelligence #1 – Replicate blog Run Snowflake Arctic with an API – Replicate blog Run Meta Llama 3 with an API – Replicate blog Run Code Llama 70B with an API – Replicate blog How to create an AI narrator for your life – Replicate blog Clone your voice using open-source models – Replicate blog Businesses are building on open-source AI – Replicate blog How to run Yi chat models with an API – Replicate blog Scaffold Replicate apps with one command – Replicate blog Using open-source models for faster and cheaper text embeddings – Replicate blog Generate music from chord progressions and text prompts with MusicGen-Chord – Replicate blog Generate images in one second on your Mac using a latent consistency model – Replicate blog How to use retrieval augmented generation with ChromaDB and Mistral – Replicate blog Fine-tune MusicGen to generate music in any style – Replicate blog Jet-setting with Llama 2 + Grammars – Replicate blog How to run Mistral 7B with an API – Replicate blog Make smooth AI generated videos with AnimateDiff and an interpolator – Replicate blog Fine-tuned models now boot in less than one second – Replicate blog Painting with words: a history of text-to-image AI – Replicate blog We're cutting our prices in half – Replicate blog A guide to prompting Llama 2 – Replicate blog Streaming output for language models – Replicate blog Fine-tune SDXL with your own images – Replicate blog Run Llama 2 with an API – Replicate blog Run SDXL with an API – Replicate blog A comprehensive guide to running Llama 2 locally – Replicate blog Fine-tune Llama 2 on Replicate – Replicate blog What happened with Llama 2 in the last 24 hours? 🦙 – Replicate blog Make any large language model a better poet – Replicate blog
Shared network vulnerability disclosure – Replicate blog
2024-05-23 · via Replicate's blog

This post shares details of a security vulnerability disclosed to us in January 2024 by our friends at Wiz, a cloud security company.

Their findings revealed that our infrastructure could have allowed a malicious model to access sensitive data. We took their report seriously, and deployed a full mitigation within 24 hours of speaking with Wiz (just over two weeks after their initial disclosure). We have since deployed additional mitigations for the issue and are now encrypting all internal traffic and restricting privileged network access for all model containers. During our investigation and mitigation, we found no evidence that this vulnerability was exploited.

Read on to learn more about the details of the vulnerability and the steps we are taking to keep Replicate secure.

Running models safely in production

At Replicate, our job is to make it easy for you to build amazing things with machine learning models. We work hard to make sure your models are reliable, fast, and scale automatically when you need them to. Equally important but less visible is our commitment to making Replicate a secure and trusted platform for you to run your workloads.

A big part of our business boils down to taking code from users (that’s you!) and running it in our production environment. When we do that, it’s important for that code to only have permission to do things we expect (like ML inference) and not other things (like poking around our network, other users’ models, etc.). We use several layers of defenses to ensure that this is the case, including but not limited to:

  • Containerization. Cog models are built into Open Container (OCI) images, and that provides us with some protections against the code within the containers “escaping” from the containers and running in places it shouldn’t.
  • Network isolation. Model code running in our infrastructure isn’t allowed to inspect our entire network. It can only talk to the services it needs to to function.
  • Inversion of control. When a model runs in our infrastructure, it takes explicit instructions from a service that runs alongside it. That service, which we call “director,” is trusted to communicate with the rest of Replicate, but the model itself is not.

The vulnerability

The vulnerability that Wiz disclosed to us showed that while some of these controls were working as expected, others were not. While the model processes and the “director” processes were isolated from one another, they shared a network (technically, they shared a network namespace).

A carefully constructed model container could eavesdrop on the traffic between director and the rest of Replicate. Because the director process was trusted, it used secrets (API tokens, etc.) to communicate with systems within Replicate that the model should never have access to.

For this vulnerability to be exploitable, two things needed to be true:

  1. The model needed to be able to gain raw access to the network namespace shared with director.
  2. The communications between director and the rest of Replicate’s systems needed to be unencrypted.

At the time Wiz made a report to us, both of these were indeed true within Replicate. We knew that traffic between director and the rest of Replicate needed to be encrypted, but we thought that the network isolation of the containers gave us more time to do that work. We had missed that the model and director containers shared a network namespace.

For more technical details on the vulnerability, we recommend reading Wiz’s blog post on this disclosure.

Our response

We took the disclosure from Wiz seriously as soon as we received it. We first decided to address the unencrypted internal network traffic to address issue. We already encrypted all Replicate traffic transiting the public internet, and we started work on encrypting all traffic on our internal networks.

When we consulted with Wiz early in the process, they advised us that if possible we should remove raw network access from model containers. Less than 24 hours later, on February 2nd, we were able to drop the NET_ADMIN and NET_RAW capabilities from all model containers to block privileged access to the network namespace.

Dropping the networking capabilities was enough to mitigate the vulnerability Wiz disclosed, but we took the opportunity to develop our defenses and further improve our overall security story. Since February 20th, all internal traffic from model pods is encrypted using TLS.

During our investigation and mitigation, we found no evidence that this vulnerability was known to anyone other than the Wiz researchers who discovered it, and no evidence that it was exploited.

Looking ahead

Wiz has a research team who are constantly on the lookout for new risks and threats in the world of cloud computing. We are immensely grateful to Wiz for their coordinated disclosure of this vulnerability and for their partnership that helped us to fix the issue quickly and effectively.

We will continue to prioritize the security of Replicate. We are committed to learning from incidents like this one to improve our systems and practices. We will also continue to collaborate with partners like Wiz to identify and address potential vulnerabilities. We understand that maintaining trust with you, our users, depends on us being vigilant about security. We appreciate your confidence in us and will continue to work hard to keep Replicate secure.