Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
84 Indlæg 64 Posters 18 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

    @GossiTheDog
    So just make a bot that goes around behind claude and files a vuln bug and lists the revert as the fix.

    fritzadalis@infosec.exchangeF This user is from outside of this forum
    fritzadalis@infosec.exchangeF This user is from outside of this forum
    fritzadalis@infosec.exchange
    wrote sidst redigeret af
    #52

    @GossiTheDog
    Nvm these are commits, not prs.

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Today in InfoSec Job Security News:

      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

      seism0saurus@infosec.exchangeS This user is from outside of this forum
      seism0saurus@infosec.exchangeS This user is from outside of this forum
      seism0saurus@infosec.exchange
      wrote sidst redigeret af
      #53

      @GossiTheDog

      Is there a cwe (common weakness enumeration) for AI slop usage already?

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Today in InfoSec Job Security News:

        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

        sassinake@mastodon.socialS This user is from outside of this forum
        sassinake@mastodon.socialS This user is from outside of this forum
        sassinake@mastodon.social
        wrote sidst redigeret af
        #54

        @GossiTheDog

        fuck.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Today in InfoSec Job Security News:

          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

          apples_and_pears@mastodon.worldA This user is from outside of this forum
          apples_and_pears@mastodon.worldA This user is from outside of this forum
          apples_and_pears@mastodon.world
          wrote sidst redigeret af
          #55

          @GossiTheDog I'm anti-AI. I used program generators long ago - they didn't work. They aren't maintainable. Major updates required complete rewrites.

          Now there's AI. It's a manager's wet dream...until it isn't.

          ...but look how productive AI is. It can whip out code as fast as a gossip can spread noise. Sure, there will be glitches, but they'll be fixed when found.

          What about the $$$$$ liability of glitches that are not found?

          1 Reply Last reply
          0
          • carpetbomberz@mastodon.onlineC This user is from outside of this forum
            carpetbomberz@mastodon.onlineC This user is from outside of this forum
            carpetbomberz@mastodon.online
            wrote sidst redigeret af
            #56

            @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

            We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

            carpetbomberz@mastodon.onlineC 1 Reply Last reply
            0
            • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

              @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

              We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

              carpetbomberz@mastodon.onlineC This user is from outside of this forum
              carpetbomberz@mastodon.onlineC This user is from outside of this forum
              carpetbomberz@mastodon.online
              wrote sidst redigeret af
              #57

              @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

              sassinake@mastodon.socialS 1 Reply Last reply
              0
              • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

                @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

                sassinake@mastodon.socialS This user is from outside of this forum
                sassinake@mastodon.socialS This user is from outside of this forum
                sassinake@mastodon.social
                wrote sidst redigeret af
                #58

                @carpetbomberz @funnymonkey @GossiTheDog

                this. Exactly this.

                1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Today in InfoSec Job Security News:

                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                  gerhardd@olching.socialG This user is from outside of this forum
                  gerhardd@olching.socialG This user is from outside of this forum
                  gerhardd@olching.social
                  wrote sidst redigeret af
                  #59

                  @GossiTheDog That #claude #AI has been created to solve the „we have too much electricity“ problem.

                  1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Today in InfoSec Job Security News:

                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                    jab01701mid@mastodon.socialJ This user is from outside of this forum
                    jab01701mid@mastodon.socialJ This user is from outside of this forum
                    jab01701mid@mastodon.social
                    wrote sidst redigeret af
                    #60

                    @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                    jab01701mid@mastodon.socialJ 1 Reply Last reply
                    0
                    • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                      @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                      jab01701mid@mastodon.socialJ This user is from outside of this forum
                      jab01701mid@mastodon.socialJ This user is from outside of this forum
                      jab01701mid@mastodon.social
                      wrote sidst redigeret af
                      #61

                      @GossiTheDog "AI" is the cryptocurrency of IT.

                      1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Today in InfoSec Job Security News:

                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                        vlkr@social.tchncs.deV This user is from outside of this forum
                        vlkr@social.tchncs.deV This user is from outside of this forum
                        vlkr@social.tchncs.de
                        wrote sidst redigeret af
                        #62

                        @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

                        crazyeddie@mastodon.socialC 1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Today in InfoSec Job Security News:

                          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                          vv@solarpunk.moeV This user is from outside of this forum
                          vv@solarpunk.moeV This user is from outside of this forum
                          vv@solarpunk.moe
                          wrote sidst redigeret af
                          #63

                          @GossiTheDog i keep waiting for a scandal to break out about this, but it never comes

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Today in InfoSec Job Security News:

                            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                            c64whiz@oldbytes.spaceC This user is from outside of this forum
                            c64whiz@oldbytes.spaceC This user is from outside of this forum
                            c64whiz@oldbytes.space
                            wrote sidst redigeret af
                            #64

                            @GossiTheDog

                            Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                            kiernian@infosec.exchangeK 1 Reply Last reply
                            0
                            • draeath@infosec.exchangeD draeath@infosec.exchange

                              @nihkeys @DJGummikuh @GossiTheDog I don't think that phrase allows for incompetency in design. The purpose is what was intended, not what actually results. There is a distinction.

                              azuaron@cyberpunk.lolA This user is from outside of this forum
                              azuaron@cyberpunk.lolA This user is from outside of this forum
                              azuaron@cyberpunk.lol
                              wrote sidst redigeret af
                              #65

                              @draeath @nihkeys @DJGummikuh @GossiTheDog If it was an accident, or incompetence, then it would be rapidly corrected.

                              If it's not rapidly corrected, then it is the purpose.

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Today in InfoSec Job Security News:

                                I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                perigee@rage.loveP This user is from outside of this forum
                                perigee@rage.loveP This user is from outside of this forum
                                perigee@rage.love
                                wrote sidst redigeret af
                                #66

                                @GossiTheDog @deliberately_me oh goodie. Our global repository has been compromised by a worm.

                                1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  Today in InfoSec Job Security News:

                                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                  synlogic4242@social.vivaldi.netS This user is from outside of this forum
                                  synlogic4242@social.vivaldi.netS This user is from outside of this forum
                                  synlogic4242@social.vivaldi.net
                                  wrote sidst redigeret af
                                  #67

                                  @GossiTheDog loltears. ie. fools suffer consequences of being fools, but at scale

                                  1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    Today in InfoSec Job Security News:

                                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                    el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                    el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                    el0j@mastodon.gamedev.place
                                    wrote sidst redigeret af
                                    #68

                                    @GossiTheDog Fortunately, I can choose to not engage.

                                    1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      Today in InfoSec Job Security News:

                                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                      tknarr@mstdn.socialT This user is from outside of this forum
                                      tknarr@mstdn.socialT This user is from outside of this forum
                                      tknarr@mstdn.social
                                      wrote sidst redigeret af
                                      #69

                                      @GossiTheDog I think @timbray might be interested in that too.

                                      1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Today in InfoSec Job Security News:

                                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                        G This user is from outside of this forum
                                        G This user is from outside of this forum
                                        geoglyphentropy@mstdn.social
                                        wrote sidst redigeret af
                                        #70

                                        @GossiTheDog Not just bad vibes, but the *same* bad vibes repeated endlessly!

                                        1 Reply Last reply
                                        0
                                        • c64whiz@oldbytes.spaceC c64whiz@oldbytes.space

                                          @GossiTheDog

                                          Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                                          kiernian@infosec.exchangeK This user is from outside of this forum
                                          kiernian@infosec.exchangeK This user is from outside of this forum
                                          kiernian@infosec.exchange
                                          wrote sidst redigeret af
                                          #71

                                          @c64whiz @GossiTheDog
                                          This was honestly my first thought.

                                          The vast majority of the tv-news-watching public barely understands computers as it is through no real fault of their own as they have been spoonfed "magic and mystery" since the dialup days.

                                          The distinction of "open source = MORE dangerous than big company software" would be very easy for a front of united major media outlets owned by a handful rich folks to spread and most people will not be equipped to tell facts from misinformation.

                                          How well have those open source legal protections been working against the "smart TV" industry? I'd bet every TV holding shelf I hit at Wal-Mart will be stocked with misappropriated GPL code and no source distribution.

                                          This is the same tactic major corps use to obtain IP for themselves.

                                          Lock up the originator in tedious, costly busywork (typically legal, claiming infringement to start a costly time-consuming trial, for most corps) and then when the originator can't handle it and collapse under the weight of it all, the corps take the product as their own.

                                          Tying up repos with vulnerabilities that might not get noticed just might work out well for the major software outfits in the long run.

                                          It's reprehensible and a little more haphazard, but it sure looks awfully familiar.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper