Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. oh jesus tapdancing christ

oh jesus tapdancing christ

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
15 Indlæg 7 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

    RE: https://social.lansky.name/@hn50/116341899721749250

    oh jesus tapdancing christ

    neurovagrant@masto.deoan.orgN This user is from outside of this forum
    neurovagrant@masto.deoan.orgN This user is from outside of this forum
    neurovagrant@masto.deoan.org
    wrote sidst redigeret af
    #2

    i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"

    lauren@mastodon.laurenweinstein.orgL neurovagrant@masto.deoan.orgN jordgubben@mastodon.gamedev.placeJ mkoek@mastodon.nlM 4 Replies Last reply
    0
    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

      i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"

      lauren@mastodon.laurenweinstein.orgL This user is from outside of this forum
      lauren@mastodon.laurenweinstein.orgL This user is from outside of this forum
      lauren@mastodon.laurenweinstein.org
      wrote sidst redigeret af
      #3

      @neurovagrant I'm not surprised in the least. Seriously. Exactly the kind of stuff I would have expected.

      zachery_delong@mastodon.socialZ 1 Reply Last reply
      0
      • lauren@mastodon.laurenweinstein.orgL lauren@mastodon.laurenweinstein.org

        @neurovagrant I'm not surprised in the least. Seriously. Exactly the kind of stuff I would have expected.

        zachery_delong@mastodon.socialZ This user is from outside of this forum
        zachery_delong@mastodon.socialZ This user is from outside of this forum
        zachery_delong@mastodon.social
        wrote sidst redigeret af
        #4

        @lauren @neurovagrant I had been thinking about setting up an instance to see what all the fuss was about but every news story I see makes me glad I’ve dragged my feet.

        1 Reply Last reply
        0
        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

          i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"

          neurovagrant@masto.deoan.orgN This user is from outside of this forum
          neurovagrant@masto.deoan.orgN This user is from outside of this forum
          neurovagrant@masto.deoan.org
          wrote sidst redigeret af
          #5

          thing is, this is likely to cause many downstream enterprise breaches, even in enterprises that actively ban openclaw.

          unauthorized instances, or instances that allow a threat actor to pivot from private hardware to work hardware.

          pure negligence, rolling OpenClaw out in the way they did, both the devs and all the hosting companies that saw profit in providing easy-install packages.

          viss@mastodon.socialV neurovagrant@masto.deoan.orgN 2 Replies Last reply
          0
          • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

            thing is, this is likely to cause many downstream enterprise breaches, even in enterprises that actively ban openclaw.

            unauthorized instances, or instances that allow a threat actor to pivot from private hardware to work hardware.

            pure negligence, rolling OpenClaw out in the way they did, both the devs and all the hosting companies that saw profit in providing easy-install packages.

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote sidst redigeret af
            #6

            @neurovagrant say, you wanna do the thing today?

            neurovagrant@masto.deoan.orgN 1 Reply Last reply
            0
            • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

              RE: https://social.lansky.name/@hn50/116341899721749250

              oh jesus tapdancing christ

              wordshaper@weatherishappening.networkW This user is from outside of this forum
              wordshaper@weatherishappening.networkW This user is from outside of this forum
              wordshaper@weatherishappening.network
              wrote sidst redigeret af
              #7

              @neurovagrant The real fun bonus parts are the scolds in the HN comments telling people that if they set this code they love up wrong then they deserve to be hacked, as if it's possible to set this thing up in a safe way as multiple hacks (including this one) demonstrate.

              1 Reply Last reply
              0
              • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                thing is, this is likely to cause many downstream enterprise breaches, even in enterprises that actively ban openclaw.

                unauthorized instances, or instances that allow a threat actor to pivot from private hardware to work hardware.

                pure negligence, rolling OpenClaw out in the way they did, both the devs and all the hosting companies that saw profit in providing easy-install packages.

                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.orgN This user is from outside of this forum
                neurovagrant@masto.deoan.org
                wrote sidst redigeret af
                #8

                the other fun part?

                even if you don't set up an exposed instance

                even if you require auth

                if any entity you pair openclaw with gets compromised, regardless of its permissions level, it can escalate to admin and pwn you

                1 Reply Last reply
                0
                • viss@mastodon.socialV viss@mastodon.social

                  @neurovagrant say, you wanna do the thing today?

                  neurovagrant@masto.deoan.orgN This user is from outside of this forum
                  neurovagrant@masto.deoan.orgN This user is from outside of this forum
                  neurovagrant@masto.deoan.org
                  wrote sidst redigeret af
                  #9

                  @Viss sure what time?

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                    @Viss sure what time?

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote sidst redigeret af
                    #10

                    @neurovagrant i literally have all day open, and the entire day is earmarked for dealing with it, so just throw a dart for whenever is comfy for you 😄

                    neurovagrant@masto.deoan.orgN 1 Reply Last reply
                    0
                    • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                      i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"

                      jordgubben@mastodon.gamedev.placeJ This user is from outside of this forum
                      jordgubben@mastodon.gamedev.placeJ This user is from outside of this forum
                      jordgubben@mastodon.gamedev.place
                      wrote sidst redigeret af
                      #11

                      @neurovagrant I’m honestly surprised it took this long for it to crackle.

                      One of the ”enthusiasts” at work recently explained to me why they think Clown Cod™ is safe to use. To paraphrase them ”it automatically checks the fist two words in bash commands for anything malicious”.

                      What worries me most about this ride through the Gartner Hype Cycle is that this time it’s not the senior engineers that are at the steering wheel. We’re more often found in the trunk tied up and gagged.

                      1 Reply Last reply
                      0
                      • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                        i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"

                        mkoek@mastodon.nlM This user is from outside of this forum
                        mkoek@mastodon.nlM This user is from outside of this forum
                        mkoek@mastodon.nl
                        wrote sidst redigeret af
                        #12

                        @neurovagrant The AI bros see security as something to be circumvented. “Move fast and break stuff.”

                        1 Reply Last reply
                        0
                        • viss@mastodon.socialV viss@mastodon.social

                          @neurovagrant i literally have all day open, and the entire day is earmarked for dealing with it, so just throw a dart for whenever is comfy for you 😄

                          neurovagrant@masto.deoan.orgN This user is from outside of this forum
                          neurovagrant@masto.deoan.orgN This user is from outside of this forum
                          neurovagrant@masto.deoan.org
                          wrote sidst redigeret af
                          #13

                          @Viss 1500 Eastern / 1200 pacific?

                          viss@mastodon.socialV 1 Reply Last reply
                          0
                          • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                            @Viss 1500 Eastern / 1200 pacific?

                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.socialV This user is from outside of this forum
                            viss@mastodon.social
                            wrote sidst redigeret af
                            #14

                            @neurovagrant done!

                            neurovagrant@masto.deoan.orgN 1 Reply Last reply
                            0
                            • viss@mastodon.socialV viss@mastodon.social

                              @neurovagrant done!

                              neurovagrant@masto.deoan.orgN This user is from outside of this forum
                              neurovagrant@masto.deoan.orgN This user is from outside of this forum
                              neurovagrant@masto.deoan.org
                              wrote sidst redigeret af
                              #15

                              @Viss sweet, will email you a Meet link, thanks man

                              1 Reply Last reply
                              0
                              • bogwitch@social.data.coopB bogwitch@social.data.coop shared this topic
                              Svar
                              • Svar som emne
                              Login for at svare
                              • Ældste til nyeste
                              • Nyeste til ældste
                              • Most Votes


                              • Log ind

                              • Har du ikke en konto? Tilmeld

                              • Login or register to search.
                              Powered by NodeBB Contributors
                              Graciously hosted by data.coop
                              • First post
                                Last post
                              0
                              • Hjem
                              • Seneste
                              • Etiketter
                              • Populære
                              • Verden
                              • Bruger
                              • Grupper