Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. OK!

OK!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
212 Indlæg 82 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

    @jonny The Location permission combined with the right low-level permission requests provides access to a lot of information on the nearby Wi-Fi networks. Without the location permission, there's only info on the signal strength of the best available currently connected cellular and WI-Fi networks.

    It would definitely be possible for us to change this by offering having spoofed values. However, it would make no sense to work on this when far more important privacy issues exist.

    adhdruid@infosec.exchangeA This user is from outside of this forum
    adhdruid@infosec.exchangeA This user is from outside of this forum
    adhdruid@infosec.exchange
    wrote sidst redigeret af
    #89

    @GrapheneOS Or you could argue that these are fundamentals. You can choose not to use apps, browsers, etc. You can’t choose not to use the battery or network.

    @jonny

    grapheneos@grapheneos.socialG adhdruid@infosec.exchangeA 2 Replies Last reply
    0
    • jonny@neuromatch.socialJ jonny@neuromatch.social

      The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

      optional@dice.campO This user is from outside of this forum
      optional@dice.campO This user is from outside of this forum
      optional@dice.camp
      wrote sidst redigeret af
      #90

      @jonny the takeaway of your thread seems to be that regex can truly solve *any* problem. The duct tape of programming 🏆️

      1 Reply Last reply
      0
      • jonny@neuromatch.socialJ jonny@neuromatch.social

        RE: https://neuromatch.social/@jonny/117339825958098508

        OK! Meta evaluated this as intended behavior, not applicable for a bug bounty, so therefore responsible disclosure no longer applies so here goes:

        any process run within the VM can access the socket that provides inference with no attribution mechanism. This includes raw inference  with arbitrary system and user prompts, as well as the ability to spawn agents with a toolset labeled as being for the "spaces" feature, which we will come back to.

        This amounts to a horizontally contagious token and information harvesting bug being labeled as intended behavior.

        Splitting details into new thread below

        wcbdata@vis.socialW This user is from outside of this forum
        wcbdata@vis.socialW This user is from outside of this forum
        wcbdata@vis.social
        wrote sidst redigeret af
        #91

        @jonny This whole thread is so life-affirming. ❤️

        1 Reply Last reply
        0
        • jonny@neuromatch.socialJ jonny@neuromatch.social

          @fancysandwiches i am working on this but cannot publicly disclose any progress until meta decides whether or not it is payable as a bug bounty

          jakimfett@masto.hackers.townJ This user is from outside of this forum
          jakimfett@masto.hackers.townJ This user is from outside of this forum
          jakimfett@masto.hackers.town
          wrote sidst redigeret af
          #92

          @jonny @fancysandwiches and, how many of the other quirks that did hit the news cycle are already from this being done lol

          1 Reply Last reply
          0
          • jonny@neuromatch.socialJ jonny@neuromatch.social

            The main unprivileged body of a Space is not supposed to access the filesystem. This is enforced by.... regex

            jonny@neuromatch.socialJ This user is from outside of this forum
            jonny@neuromatch.socialJ This user is from outside of this forum
            jonny@neuromatch.social
            wrote sidst redigeret af
            #93

            So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

            Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

            So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

            viss@mastodon.socialV happyborg@fosstodon.orgH jonny@neuromatch.socialJ bstacey@icosahedron.websiteB m0yng@mastodon.radioM 7 Replies Last reply
            0
            • jonny@neuromatch.socialJ jonny@neuromatch.social

              So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

              Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

              So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote sidst redigeret af
              #94

              @jonny is that your interface? did you make a harness for this thing or is this muses web interface?

              viss@mastodon.socialV jonny@neuromatch.socialJ 2 Replies Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                @jonny is that your interface? did you make a harness for this thing or is this muses web interface?

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote sidst redigeret af
                #95

                @jonny beeteedubs i linked to you a bunch in my reddit ama earlier today, so you may get a buuuunch of new followers, heh

                jonny@neuromatch.socialJ 1 Reply Last reply
                0
                • viss@mastodon.socialV viss@mastodon.social

                  @jonny is that your interface? did you make a harness for this thing or is this muses web interface?

                  jonny@neuromatch.socialJ This user is from outside of this forum
                  jonny@neuromatch.socialJ This user is from outside of this forum
                  jonny@neuromatch.social
                  wrote sidst redigeret af
                  #96

                  @Viss yeah, i am comparatively spoiled by claude code and having yelled at it enough so it always writes code in a TDD loop, muse is absolutely awful at programming out of the box, but after yelling at it for several hours it was capable of generating a browser for the contents of the .jsonl files that have its raw message output. this part of muse could actually be awesome if it wasn't such a fucking trainwreck.

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    @jonny beeteedubs i linked to you a bunch in my reddit ama earlier today, so you may get a buuuunch of new followers, heh

                    jonny@neuromatch.socialJ This user is from outside of this forum
                    jonny@neuromatch.socialJ This user is from outside of this forum
                    jonny@neuromatch.social
                    wrote sidst redigeret af
                    #97

                    @Viss where's the AMA at?

                    viss@mastodon.socialV 1 Reply Last reply
                    0
                    • jonny@neuromatch.socialJ jonny@neuromatch.social

                      So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                      Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                      So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                      happyborg@fosstodon.orgH This user is from outside of this forum
                      happyborg@fosstodon.orgH This user is from outside of this forum
                      happyborg@fosstodon.org
                      wrote sidst redigeret af
                      #98

                      @jonny

                      "So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it."

                      - which we've known about #LLMs since the ice age and has not changed despite their rapid advance towards super intelligence.

                      I think I'll forgo Meta's free VPS with #LLM carnage and stick to my Euro 2.7/month Infomaniak Swiss VPS.

                      1 Reply Last reply
                      0
                      • jonny@neuromatch.socialJ jonny@neuromatch.social

                        @Viss where's the AMA at?

                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.social
                        wrote sidst redigeret af
                        #99

                        @jonny https://www.reddit.com/r/pwnhub/comments/1wjy5b8/comment/pd25b8b/

                        gregatron5@social.lolG 1 Reply Last reply
                        0
                        • jonny@neuromatch.socialJ jonny@neuromatch.social

                          So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                          Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                          So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                          jonny@neuromatch.socialJ This user is from outside of this forum
                          jonny@neuromatch.socialJ This user is from outside of this forum
                          jonny@neuromatch.social
                          wrote sidst redigeret af
                          #100

                          Hell, seeing this, if I was alibaba or tencent, I would put up poisoned packages and use the unlimited unattributable inference socket to distill meta's models, but what do I know about corporate espionage.

                          theorangetheme@en.osm.townT chickenpwny@infosec.exchangeC jonny@neuromatch.socialJ 3 Replies Last reply
                          0
                          • jonny@neuromatch.socialJ jonny@neuromatch.social

                            Hell, seeing this, if I was alibaba or tencent, I would put up poisoned packages and use the unlimited unattributable inference socket to distill meta's models, but what do I know about corporate espionage.

                            theorangetheme@en.osm.townT This user is from outside of this forum
                            theorangetheme@en.osm.townT This user is from outside of this forum
                            theorangetheme@en.osm.town
                            wrote sidst redigeret af
                            #101

                            @jonny On the record? Nothing. :3

                            1 Reply Last reply
                            0
                            • jonny@neuromatch.socialJ jonny@neuromatch.social

                              So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                              Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                              So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                              bstacey@icosahedron.websiteB This user is from outside of this forum
                              bstacey@icosahedron.websiteB This user is from outside of this forum
                              bstacey@icosahedron.website
                              wrote sidst redigeret af
                              #102

                              @jonny Ordering illicict Python from Alibaba

                              1 Reply Last reply
                              0
                              • jonny@neuromatch.socialJ jonny@neuromatch.social

                                Hell, seeing this, if I was alibaba or tencent, I would put up poisoned packages and use the unlimited unattributable inference socket to distill meta's models, but what do I know about corporate espionage.

                                chickenpwny@infosec.exchangeC This user is from outside of this forum
                                chickenpwny@infosec.exchangeC This user is from outside of this forum
                                chickenpwny@infosec.exchange
                                wrote sidst redigeret af
                                #103

                                @jonny you think meta is that good

                                jonny@neuromatch.socialJ 1 Reply Last reply
                                0
                                • glyph@mastodon.socialG glyph@mastodon.social

                                  @jonny every time I come back to this thread I feel like I am having a fever dream

                                  somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                                  somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                                  somevegancheeseisok@mastodon.social
                                  wrote sidst redigeret af
                                  #104

                                  @glyph @jonny I love it. It's so absolutely insane. Absolutely love it.

                                  They better pay him a metric fuvkton.

                                  1 Reply Last reply
                                  0
                                  • timotimo@peoplemaking.gamesT timotimo@peoplemaking.games

                                    @jonny I can't believe they call these "spaces" (meta spaces?) and not "verses"

                                    somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                                    somevegancheeseisok@mastodon.socialS This user is from outside of this forum
                                    somevegancheeseisok@mastodon.social
                                    wrote sidst redigeret af
                                    #105

                                    @timotimo @jonny meat space!

                                    1 Reply Last reply
                                    0
                                    • chickenpwny@infosec.exchangeC chickenpwny@infosec.exchange

                                      @jonny you think meta is that good

                                      jonny@neuromatch.socialJ This user is from outside of this forum
                                      jonny@neuromatch.socialJ This user is from outside of this forum
                                      jonny@neuromatch.social
                                      wrote sidst redigeret af
                                      #106

                                      @ChickenPwny
                                      No, but it would be free!

                                      chickenpwny@infosec.exchangeC 1 Reply Last reply
                                      0
                                      • jonny@neuromatch.socialJ jonny@neuromatch.social

                                        @ChickenPwny
                                        No, but it would be free!

                                        chickenpwny@infosec.exchangeC This user is from outside of this forum
                                        chickenpwny@infosec.exchangeC This user is from outside of this forum
                                        chickenpwny@infosec.exchange
                                        wrote sidst redigeret af
                                        #107

                                        @jonny *should he he because AI should be open-sourced

                                        1 Reply Last reply
                                        0
                                        • jonny@neuromatch.socialJ jonny@neuromatch.social

                                          So again, how could one end up with a compromised package on a muse instance? Wouldn't that have to be some sophisticated supply chain attack? Nope! Muse attempted to install packages from PyPI, which caused a card to pop up on the user interface asking for me to approve connecting to PyPI. I was not watching the screen, so the request timed out. It then proceeded to raw dog a list of PyPI mirrors from its training data. It couldn't figure out how to use uv, so it then generated a wheel download script that would bypass any lockfile that validated packages by hash. It forked that to the background, forgot about it, and then proceeded to attempt to manually download the specified dependencies across a dozen or two tool calls with direct URL construction over whatever mirrors returned something.

                                          Connecting to PyPI required explicit approval, but connecting to the mirrors didn't, and so i wouldn't have even noticed if i didn't always read the raw message stream rather than the interface output because you can never trust these things. When I stopped it and said "don't connect to random pypi mirrors wtf are you doing" it 1) lied about PyPI being unreachable because it has no visibility into the permission status and by pattern words should be there, 2) told me that two of the mirrors it tried were official PyPI mirrors, and 3) presented randomly wandering PyPI indexes as if it was a normal thing to do. If I wasn't a python developer and knew already there are no official PyPI mirrors, and also actively investigating how its egress permissions worked, I probably would have just accepted that.

                                          So anyway, unless you are a user with lots of direct domain knowledge about a language packaging ecosystem who is reading the entire raw message log as it happens, muse will aggressively download random shit from the internet and execute it.

                                          m0yng@mastodon.radioM This user is from outside of this forum
                                          m0yng@mastodon.radioM This user is from outside of this forum
                                          m0yng@mastodon.radio
                                          wrote sidst redigeret af
                                          #108

                                          @jonny oh great, another way that this steaming pile of shit will put even more strain on the resources of everyone hosting anything on the internet.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper