the rm -rf's will continue until morale improves
-
Nobody writes a CLAUDE.md to raise their pass rate on code issues. They write it so the agent follows the project's conventions. The study scored the first and got quoted as debunking the second.
There is a token overhead on compliance (about 20%?), it works for me, though I never run a project without it.
Edit: Though its the weakest counterpoint, AGENTS.md =\= CLAUDE.md and the fact the author doesn't seem to know that, irks me more than it should.
-
@neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity
-
@neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity
@Viss @neurovagrant Letsss goooooo
-
@jrdepriest @jztusk @paco @neurovagrant "oh, it's only data exfil, that's not so bad" Some people have very limited imaginations, and need an unequivocal demonstration.
@womble @jrdepriest @paco @neurovagrant
Exactly. "Well that's only showing they can read", whereas having an unrequested calculator sitting there on your desktop is very undeniable.
-
@womble @jrdepriest @paco @neurovagrant
Exactly. "Well that's only showing they can read", whereas having an unrequested calculator sitting there on your desktop is very undeniable.
@jztusk @womble @paco @neurovagrant
Mission accomplished with the table drop, then?
-
@Viss @neurovagrant Letsss goooooo
@quinn @neurovagrant someone rm'ing themselves because they gave claude too much access, who self-identifies as a cto, strikes me as one of those "php ceo" types, who does a lot of talking but never really produces stuff or makes anything interesting or worthwhile.
-
the rm -rf's will continue until morale improves
@neurovagrant apes gone
-
I've always liked how the default demonstration of vulnerability on Windows was is opening calc.exe. isn't there a similar sensible SQL default?
@jztusk There are tons. Calculations or delays that indicate it was processed without doing anything to data.
@neurovagrant -
@jztusk @womble @paco @neurovagrant
Mission accomplished with the table drop, then?
@jrdepriest @womble @paco @neurovagrant
Well, you *can* then just close the calculator, though you can't deny that it was there.
I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.
-
@neurovagrant @quinn cool now we get to see how well he handles disaster recovery and business continuity
@Viss @neurovagrant @quinn rizaster decovery and business kindakablooey?
-
@jrdepriest @womble @paco @neurovagrant
Well, you *can* then just close the calculator, though you can't deny that it was there.
I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.
@jztusk @womble @paco @neurovagrant
Like leaving an empty file called
pwnedon/. -
@jztusk @womble @paco @neurovagrant
Mission accomplished with the table drop, then?
@jrdepriest It’s a true story, but I tell it a certain way to get a reaction. It was in a UAT environment, not prod. To be fair, it was a precious UAT environment that hundreds of people count on. It was not quick to rebuild. The client was pissed. But it wasn’t deleting real users from the real web site.
-
@jrdepriest @womble @paco @neurovagrant
Well, you *can* then just close the calculator, though you can't deny that it was there.
I was wondering if the was some standard, like you create a table named "tag_youre_it", and insert "boop" in a CHAR(4) field. Reversible, but undeniable.
@jztusk @jrdepriest @paco @neurovagrant CREATE TABLE l33th4x0rs (pwned bool default true); does seem like the least intrusive way to demonstrate the acquisition of significant privileges.
-
@jztusk @womble @paco @neurovagrant
Like leaving an empty file called
pwnedon/. -
the rm -rf's will continue until morale improves
@neurovagrant I love seeing ai bros bitching about shit us older geeks warned would happen, especially those of us who worked on real AI.
They're using LLMs for shit it's not good at then bitching about the broken shit. I'm just going to keep eating my popcorn.
-
@neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran
drop table users;via injection.Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.
@paco @neurovagrant Good ol' Little Bobby Tables.
-
the rm -rf's will continue until morale improves
@neurovagrant I suspect his idea of a dev machine wouldn’t match mine.
-
@neurovagrant I love seeing ai bros bitching about shit us older geeks warned would happen, especially those of us who worked on real AI.
They're using LLMs for shit it's not good at then bitching about the broken shit. I'm just going to keep eating my popcorn.
-
the rm -rf's will continue until morale improves
@neurovagrant @hypebot all my ops, gone
-
the rm -rf's will continue until morale improves
There are things you learn the hard way. "No backup - no merci". Won't trust LLMs farther than I could spit a rat - and so would not let it loose on my system.
