Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
41 Indlæg 25 Posters 16 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.ca
    wrote sidst redigeret af
    #1

    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

    oxyhyxo@mastodon.bsd.cafeO lerxst@az.socialL pmc@mastodon.ffcentral.netP delta_vee@mstdn.caD hennell@phpc.socialH 18 Replies Last reply
    1
    0
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

      oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
      oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
      oxyhyxo@mastodon.bsd.cafe
      wrote sidst redigeret af
      #2

      @mhoye 😔

      1 Reply Last reply
      0
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

        lerxst@az.socialL This user is from outside of this forum
        lerxst@az.socialL This user is from outside of this forum
        lerxst@az.social
        wrote sidst redigeret af
        #3

        @mhoye If we didn't learn from the left pad incident, we never will. This is just a new payload for an existing threat vector.

        1 Reply Last reply
        0
        • mhoye@cosocial.caM mhoye@cosocial.ca

          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

          pmc@mastodon.ffcentral.netP This user is from outside of this forum
          pmc@mastodon.ffcentral.netP This user is from outside of this forum
          pmc@mastodon.ffcentral.net
          wrote sidst redigeret af
          #4

          @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

          kayohtie@blimps.xyzK 1 Reply Last reply
          0
          • mhoye@cosocial.caM mhoye@cosocial.ca

            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

            delta_vee@mstdn.caD This user is from outside of this forum
            delta_vee@mstdn.caD This user is from outside of this forum
            delta_vee@mstdn.ca
            wrote sidst redigeret af
            #5

            @mhoye This is the real "we're cooked"

            1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

              hennell@phpc.socialH This user is from outside of this forum
              hennell@phpc.socialH This user is from outside of this forum
              hennell@phpc.social
              wrote sidst redigeret af
              #6

              @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

              tiotasram@kolektiva.socialT 1 Reply Last reply
              0
              • mhoye@cosocial.caM mhoye@cosocial.ca

                Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                endorama@hachyderm.ioE This user is from outside of this forum
                endorama@hachyderm.ioE This user is from outside of this forum
                endorama@hachyderm.io
                wrote sidst redigeret af
                #7

                @mhoye could you share the source? Thanks in advance

                mhoye@cosocial.caM 1 Reply Last reply
                0
                • mhoye@cosocial.caM mhoye@cosocial.ca

                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.social
                  wrote sidst redigeret af
                  #8

                  @mhoye

                  “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                  A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                  https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                  stepheneb@ruby.socialS 1 Reply Last reply
                  0
                  • stepheneb@ruby.socialS stepheneb@ruby.social

                    @mhoye

                    “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                    A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                    https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                    stepheneb@ruby.socialS This user is from outside of this forum
                    stepheneb@ruby.socialS This user is from outside of this forum
                    stepheneb@ruby.social
                    wrote sidst redigeret af
                    #9

                    @mhoye

                    I didn’t know about using “OpenID Connect (OIDC) to authenticate GitHub Actions” and wonder how many surfaces it closes and whether it opens new surfaces?

                    https://docs.github.com/en/actions/reference/security/oidc

                    1 Reply Last reply
                    0
                    • hennell@phpc.socialH hennell@phpc.social

                      @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

                      tiotasram@kolektiva.socialT This user is from outside of this forum
                      tiotasram@kolektiva.socialT This user is from outside of this forum
                      tiotasram@kolektiva.social
                      wrote sidst redigeret af
                      #10

                      @hennell @mhoye openclaw is effectively a vulnerability/exploit payload itself, which to AI boosters doesn't seem like one.

                      hennell@phpc.socialH 1 Reply Last reply
                      0
                      • mhoye@cosocial.caM mhoye@cosocial.ca

                        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.ca
                        wrote sidst redigeret af
                        #11

                        Links:

                        https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                        https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                        dancast@wandering.shopD 1 Reply Last reply
                        0
                        • endorama@hachyderm.ioE endorama@hachyderm.io

                          @mhoye could you share the source? Thanks in advance

                          mhoye@cosocial.caM This user is from outside of this forum
                          mhoye@cosocial.caM This user is from outside of this forum
                          mhoye@cosocial.ca
                          wrote sidst redigeret af
                          #12

                          @endorama

                          https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                          1 Reply Last reply
                          0
                          • mhoye@cosocial.caM mhoye@cosocial.ca

                            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                            cdamian@rls.socialC This user is from outside of this forum
                            cdamian@rls.socialC This user is from outside of this forum
                            cdamian@rls.social
                            wrote sidst redigeret af
                            #13

                            @mhoye
                            Could you provide a source URL to this?

                            cdamian@rls.socialC 1 Reply Last reply
                            0
                            • mhoye@cosocial.caM mhoye@cosocial.ca

                              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                              pseudonym@mastodon.onlineP This user is from outside of this forum
                              pseudonym@mastodon.onlineP This user is from outside of this forum
                              pseudonym@mastodon.online
                              wrote sidst redigeret af
                              #14

                              @mhoye

                              #infosec

                              Install attack surface as a service.

                              IASaaS

                              No, swap that...

                              Attack Interface Surface as a Service

                              AISaaS

                              1 Reply Last reply
                              0
                              • cdamian@rls.socialC cdamian@rls.social

                                @mhoye
                                Could you provide a source URL to this?

                                cdamian@rls.socialC This user is from outside of this forum
                                cdamian@rls.socialC This user is from outside of this forum
                                cdamian@rls.social
                                wrote sidst redigeret af
                                #15

                                @mhoye
                                Found it
                                https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                                1 Reply Last reply
                                0
                                • pmc@mastodon.ffcentral.netP pmc@mastodon.ffcentral.net

                                  @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

                                  kayohtie@blimps.xyzK This user is from outside of this forum
                                  kayohtie@blimps.xyzK This user is from outside of this forum
                                  kayohtie@blimps.xyz
                                  wrote sidst redigeret af
                                  #16

                                  @pmc @mhoye @cwebber People granting tokens way too much access because it's easier to check a box for 'all' than it is to drill down and consider specifics needed, frequently.

                                  1 Reply Last reply
                                  0
                                  • mhoye@cosocial.caM mhoye@cosocial.ca

                                    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                    401matthall@mastodon.xyz4 This user is from outside of this forum
                                    401matthall@mastodon.xyz4 This user is from outside of this forum
                                    401matthall@mastodon.xyz
                                    wrote sidst redigeret af
                                    #17

                                    @mhoye

                                    FFS. 👀

                                    1 Reply Last reply
                                    0
                                    • mhoye@cosocial.caM mhoye@cosocial.ca

                                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                      feld@friedcheese.usF This user is from outside of this forum
                                      feld@friedcheese.usF This user is from outside of this forum
                                      feld@friedcheese.us
                                      wrote sidst redigeret af
                                      #18
                                      @mhoye

                                      > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                                      they deserve it
                                      mhoye@cosocial.caM mischievoustomato@tsundere.loveM khleedril@cyberplace.socialK 3 Replies Last reply
                                      0
                                      • mhoye@cosocial.caM mhoye@cosocial.ca

                                        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                        tanepiper@tane.codesT This user is from outside of this forum
                                        tanepiper@tane.codesT This user is from outside of this forum
                                        tanepiper@tane.codes
                                        wrote sidst redigeret af
                                        #19

                                        @mhoye postinstall was probably the worst thing added to npm - it's been there since the start with absolutely no effort to secure it or remove it

                                        mhoye@cosocial.caM 1 Reply Last reply
                                        0
                                        • feld@friedcheese.usF feld@friedcheese.us
                                          @mhoye

                                          > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                                          they deserve it
                                          mhoye@cosocial.caM This user is from outside of this forum
                                          mhoye@cosocial.caM This user is from outside of this forum
                                          mhoye@cosocial.ca
                                          wrote sidst redigeret af
                                          #20

                                          @feld "they deserved it" is a childish, bullshit response to systemic problems.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper