<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Thomy Gölles</title><link>https://thomygoelles.com/tags/security/</link><description>Recent content in Security on Thomy Gölles</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 24 Aug 2025 12:24:21 +0000</lastBuildDate><atom:link href="https://thomygoelles.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>When “Responsible AI” Becomes a Wall Instead of a Guide</title><link>https://thomygoelles.com/who-defines-responsible-ai/</link><pubDate>Sun, 24 Aug 2025 09:26:38 +0000</pubDate><guid>https://thomygoelles.com/who-defines-responsible-ai/</guid><description>&lt;h2 id="when-responsible-ai-becomes-a-wall-instead-of-a-guide"&gt;When “Responsible AI” Becomes a Wall Instead of a Guide&lt;/h2&gt;
&lt;p&gt;The other day, I ran into this delightful message:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;“Your instructions may contain content that violates Microsoft’s responsible AI policy.”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That’s it. No explanation. No hint of what part is problematic. Just a big red warning, suggesting that somewhere, somehow, I might be about to do something bad.&lt;/p&gt;
&lt;h2 id="the-cynicism-of-corporate-responsibility"&gt;The Cynicism of Corporate Responsibility&lt;/h2&gt;
&lt;p&gt;Now, I’m not against the idea of “responsible AI.” Quite the opposite. Of course, AI needs guardrails. But here’s where the cynicism kicks in: if a trillion-dollar, shareholder-value-driven company gets to define what “responsible” means—without transparency or clarity—then we’re left in a strange place.&lt;/p&gt;</description></item><item><title>How to fix Pi-hole blocking Azure OpenAI calls</title><link>https://thomygoelles.com/how-to-fix-pi-hole-blocking-azure-openai-calls/</link><pubDate>Thu, 22 Feb 2024 07:59:41 +0000</pubDate><guid>https://thomygoelles.com/how-to-fix-pi-hole-blocking-azure-openai-calls/</guid><description>&lt;p&gt;&lt;i&gt;A simple solution for a frustrating bug hunt&lt;/i&gt;&lt;/p&gt;
&lt;h2 id="tldr"&gt;TLDR;&lt;/h2&gt;
&lt;p&gt;If you’re using Pi-hole for ad-blocking and find that it’s preventing your access to Azure OpenAI Service, the solution is to whitelist Azure OpenAI domains in Pi-hole’s settings. This issue arises because Pi-hole, which blocks ad-serving domains at the DNS level, can also block legitimate services like Azure OpenAI. The fix involves accessing Pi-hole’s admin interface and adding openai.azure.com to the whitelist, ensuring uninterrupted access to Azure OpenAI for your services, which relies on Azure OpenAI for features like Semantic Kernel for natural language processing. Remember to share this workaround with anyone facing similar issues!&lt;/p&gt;</description></item><item><title>Exploits and possible LLM attacks plus M365 Copilot</title><link>https://thomygoelles.com/exploits-and-possible-llm-attacks-plus-m365-copilot/</link><pubDate>Sun, 04 Feb 2024 12:26:38 +0000</pubDate><guid>https://thomygoelles.com/exploits-and-possible-llm-attacks-plus-m365-copilot/</guid><description>&lt;p&gt;There is a German idiom called &amp;ldquo;in between the years&amp;rdquo;, meaning the timeframe from Christmas to New Year&amp;rsquo;s eve. It is a time of reflection and of course family. This year it was also the time of the &lt;a href="https://events.ccc.de/congress/2023/infos/index.html" target="_blank" rel="noopener"&gt;37th Chaos Communication Congress (37C3) in Hamburg&lt;/a&gt;. The 37C3 was a hybrid event, meaning it was a physical event in Hamburg and a virtual event on the internet.&lt;/p&gt;
&lt;h2 id="real-world-exploits-and-mitigations-in-llm-applications"&gt;Real-world exploits and mitigations in LLM applications&lt;/h2&gt;
&lt;p&gt;One of the talks that I found very interesting was the talk about &lt;a href="https://www.youtube.com/watch?v=qyTSOSDEC5M" target="_blank" rel="noopener"&gt;Real-world exploits and mitigations in LLM applications (37c3)&lt;/a&gt;. The talk was about a new type of attacks that are based on LLMs by &lt;a href="https://www.linkedin.com/in/johannrehberger/" target="_blank" rel="noopener"&gt;Johann Rehberger&lt;/a&gt;. Johann is currently a Red Team Director at Electronic Arts and worked as a Principal Security Engineer Manager for years at Microsoft. Red Teams are tasked with simulating attacks on a company&amp;rsquo;s systems to test the effectiveness of its security measures. So it&amp;rsquo;s very interessting so see his thoughts on this topic.&lt;/p&gt;</description></item></channel></rss>