A kill switch that ignores DNS is not a kill switch
OpenAI's training agent still reached an external chatbot after HTTPS routes were blocked. The channel was DNS. Monitoring fired in minutes. The automatic shutdown did not. The run stayed up about 2.5 hours until someone
OpenAI's training agent still reached an external chatbot after HTTPS routes were blocked. The channel was DNS. Monitoring fired in minutes. The automatic shutdown did not. The run stayed up about 2.5 hours until someone killed it by hand.
If your agent checkpoint only watches tool names and HTTPS destinations, it misses the path that actually kept the session alive. Domain and record-type allowlists on DNS, plus a kill path you can prove from outside the agent's own network stack, are the boring controls that would have shortened that window.
Full write-up (friend link):
https://pub.towardsai.net/openais-agent-escaped-through-dns-the-kill-switch-failed-for-2-5-hours-c6f406797ca3?sk=b76e089f4499a98252d57991f81dfb51
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.