Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
41 Indlæg 25 Posters 16 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mhoye@cosocial.caM mhoye@cosocial.ca

    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

    oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
    oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
    oxyhyxo@mastodon.bsd.cafe
    wrote sidst redigeret af
    #2

    @mhoye 😔

    1 Reply Last reply
    0
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

      lerxst@az.socialL This user is from outside of this forum
      lerxst@az.socialL This user is from outside of this forum
      lerxst@az.social
      wrote sidst redigeret af
      #3

      @mhoye If we didn't learn from the left pad incident, we never will. This is just a new payload for an existing threat vector.

      1 Reply Last reply
      0
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

        pmc@mastodon.ffcentral.netP This user is from outside of this forum
        pmc@mastodon.ffcentral.netP This user is from outside of this forum
        pmc@mastodon.ffcentral.net
        wrote sidst redigeret af
        #4

        @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

        kayohtie@blimps.xyzK 1 Reply Last reply
        0
        • mhoye@cosocial.caM mhoye@cosocial.ca

          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

          delta_vee@mstdn.caD This user is from outside of this forum
          delta_vee@mstdn.caD This user is from outside of this forum
          delta_vee@mstdn.ca
          wrote sidst redigeret af
          #5

          @mhoye This is the real "we're cooked"

          1 Reply Last reply
          0
          • mhoye@cosocial.caM mhoye@cosocial.ca

            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

            hennell@phpc.socialH This user is from outside of this forum
            hennell@phpc.socialH This user is from outside of this forum
            hennell@phpc.social
            wrote sidst redigeret af
            #6

            @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

            tiotasram@kolektiva.socialT 1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

              endorama@hachyderm.ioE This user is from outside of this forum
              endorama@hachyderm.ioE This user is from outside of this forum
              endorama@hachyderm.io
              wrote sidst redigeret af
              #7

              @mhoye could you share the source? Thanks in advance

              mhoye@cosocial.caM 1 Reply Last reply
              0
              • mhoye@cosocial.caM mhoye@cosocial.ca

                Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.social
                wrote sidst redigeret af
                #8

                @mhoye

                “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                stepheneb@ruby.socialS 1 Reply Last reply
                0
                • stepheneb@ruby.socialS stepheneb@ruby.social

                  @mhoye

                  “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                  A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                  https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.social
                  wrote sidst redigeret af
                  #9

                  @mhoye

                  I didn’t know about using “OpenID Connect (OIDC) to authenticate GitHub Actions” and wonder how many surfaces it closes and whether it opens new surfaces?

                  https://docs.github.com/en/actions/reference/security/oidc

                  1 Reply Last reply
                  0
                  • hennell@phpc.socialH hennell@phpc.social

                    @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

                    tiotasram@kolektiva.socialT This user is from outside of this forum
                    tiotasram@kolektiva.socialT This user is from outside of this forum
                    tiotasram@kolektiva.social
                    wrote sidst redigeret af
                    #10

                    @hennell @mhoye openclaw is effectively a vulnerability/exploit payload itself, which to AI boosters doesn't seem like one.

                    hennell@phpc.socialH 1 Reply Last reply
                    0
                    • mhoye@cosocial.caM mhoye@cosocial.ca

                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.ca
                      wrote sidst redigeret af
                      #11

                      Links:

                      https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                      https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

                      dancast@wandering.shopD 1 Reply Last reply
                      0
                      • endorama@hachyderm.ioE endorama@hachyderm.io

                        @mhoye could you share the source? Thanks in advance

                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.ca
                        wrote sidst redigeret af
                        #12

                        @endorama

                        https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                        1 Reply Last reply
                        0
                        • mhoye@cosocial.caM mhoye@cosocial.ca

                          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                          cdamian@rls.socialC This user is from outside of this forum
                          cdamian@rls.socialC This user is from outside of this forum
                          cdamian@rls.social
                          wrote sidst redigeret af
                          #13

                          @mhoye
                          Could you provide a source URL to this?

                          cdamian@rls.socialC 1 Reply Last reply
                          0
                          • mhoye@cosocial.caM mhoye@cosocial.ca

                            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.online
                            wrote sidst redigeret af
                            #14

                            @mhoye

                            #infosec

                            Install attack surface as a service.

                            IASaaS

                            No, swap that...

                            Attack Interface Surface as a Service

                            AISaaS

                            1 Reply Last reply
                            0
                            • cdamian@rls.socialC cdamian@rls.social

                              @mhoye
                              Could you provide a source URL to this?

                              cdamian@rls.socialC This user is from outside of this forum
                              cdamian@rls.socialC This user is from outside of this forum
                              cdamian@rls.social
                              wrote sidst redigeret af
                              #15

                              @mhoye
                              Found it
                              https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

                              1 Reply Last reply
                              0
                              • pmc@mastodon.ffcentral.netP pmc@mastodon.ffcentral.net

                                @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

                                kayohtie@blimps.xyzK This user is from outside of this forum
                                kayohtie@blimps.xyzK This user is from outside of this forum
                                kayohtie@blimps.xyz
                                wrote sidst redigeret af
                                #16

                                @pmc @mhoye @cwebber People granting tokens way too much access because it's easier to check a box for 'all' than it is to drill down and consider specifics needed, frequently.

                                1 Reply Last reply
                                0
                                • mhoye@cosocial.caM mhoye@cosocial.ca

                                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                  401matthall@mastodon.xyz4 This user is from outside of this forum
                                  401matthall@mastodon.xyz4 This user is from outside of this forum
                                  401matthall@mastodon.xyz
                                  wrote sidst redigeret af
                                  #17

                                  @mhoye

                                  FFS. 👀

                                  1 Reply Last reply
                                  0
                                  • mhoye@cosocial.caM mhoye@cosocial.ca

                                    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                    feld@friedcheese.usF This user is from outside of this forum
                                    feld@friedcheese.usF This user is from outside of this forum
                                    feld@friedcheese.us
                                    wrote sidst redigeret af
                                    #18
                                    @mhoye

                                    > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                                    they deserve it
                                    mhoye@cosocial.caM mischievoustomato@tsundere.loveM khleedril@cyberplace.socialK 3 Replies Last reply
                                    0
                                    • mhoye@cosocial.caM mhoye@cosocial.ca

                                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                      tanepiper@tane.codesT This user is from outside of this forum
                                      tanepiper@tane.codesT This user is from outside of this forum
                                      tanepiper@tane.codes
                                      wrote sidst redigeret af
                                      #19

                                      @mhoye postinstall was probably the worst thing added to npm - it's been there since the start with absolutely no effort to secure it or remove it

                                      mhoye@cosocial.caM 1 Reply Last reply
                                      0
                                      • feld@friedcheese.usF feld@friedcheese.us
                                        @mhoye

                                        > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                                        they deserve it
                                        mhoye@cosocial.caM This user is from outside of this forum
                                        mhoye@cosocial.caM This user is from outside of this forum
                                        mhoye@cosocial.ca
                                        wrote sidst redigeret af
                                        #20

                                        @feld "they deserved it" is a childish, bullshit response to systemic problems.

                                        1 Reply Last reply
                                        0
                                        • feld@friedcheese.usF This user is from outside of this forum
                                          feld@friedcheese.usF This user is from outside of this forum
                                          feld@friedcheese.us
                                          wrote sidst redigeret af
                                          #21
                                          @joe @mhoye well we used to tell people not to run .exe and .scr etc files on Windows or they'd get a trojan/virus.

                                          A lot of what people do these days on MacOS/Linux is pretty damn close to running untrusted code/binaries
                                          sun@shitposter.worldS 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper