Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
84 Indlæg 64 Posters 18 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

    @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

    We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

    carpetbomberz@mastodon.onlineC This user is from outside of this forum
    carpetbomberz@mastodon.onlineC This user is from outside of this forum
    carpetbomberz@mastodon.online
    wrote sidst redigeret af
    #57

    @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

    sassinake@mastodon.socialS 1 Reply Last reply
    0
    • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

      @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

      sassinake@mastodon.socialS This user is from outside of this forum
      sassinake@mastodon.socialS This user is from outside of this forum
      sassinake@mastodon.social
      wrote sidst redigeret af
      #58

      @carpetbomberz @funnymonkey @GossiTheDog

      this. Exactly this.

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Today in InfoSec Job Security News:

        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

        gerhardd@olching.socialG This user is from outside of this forum
        gerhardd@olching.socialG This user is from outside of this forum
        gerhardd@olching.social
        wrote sidst redigeret af
        #59

        @GossiTheDog That #claude #AI has been created to solve the „we have too much electricity“ problem.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Today in InfoSec Job Security News:

          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

          jab01701mid@mastodon.socialJ This user is from outside of this forum
          jab01701mid@mastodon.socialJ This user is from outside of this forum
          jab01701mid@mastodon.social
          wrote sidst redigeret af
          #60

          @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

          jab01701mid@mastodon.socialJ 1 Reply Last reply
          0
          • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

            @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

            jab01701mid@mastodon.socialJ This user is from outside of this forum
            jab01701mid@mastodon.socialJ This user is from outside of this forum
            jab01701mid@mastodon.social
            wrote sidst redigeret af
            #61

            @GossiTheDog "AI" is the cryptocurrency of IT.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Today in InfoSec Job Security News:

              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

              vlkr@social.tchncs.deV This user is from outside of this forum
              vlkr@social.tchncs.deV This user is from outside of this forum
              vlkr@social.tchncs.de
              wrote sidst redigeret af
              #62

              @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

              crazyeddie@mastodon.socialC 1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Today in InfoSec Job Security News:

                I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                vv@solarpunk.moeV This user is from outside of this forum
                vv@solarpunk.moeV This user is from outside of this forum
                vv@solarpunk.moe
                wrote sidst redigeret af
                #63

                @GossiTheDog i keep waiting for a scandal to break out about this, but it never comes

                1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Today in InfoSec Job Security News:

                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                  c64whiz@oldbytes.spaceC This user is from outside of this forum
                  c64whiz@oldbytes.spaceC This user is from outside of this forum
                  c64whiz@oldbytes.space
                  wrote sidst redigeret af
                  #64

                  @GossiTheDog

                  Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                  kiernian@infosec.exchangeK 1 Reply Last reply
                  0
                  • draeath@infosec.exchangeD draeath@infosec.exchange

                    @nihkeys @DJGummikuh @GossiTheDog I don't think that phrase allows for incompetency in design. The purpose is what was intended, not what actually results. There is a distinction.

                    azuaron@cyberpunk.lolA This user is from outside of this forum
                    azuaron@cyberpunk.lolA This user is from outside of this forum
                    azuaron@cyberpunk.lol
                    wrote sidst redigeret af
                    #65

                    @draeath @nihkeys @DJGummikuh @GossiTheDog If it was an accident, or incompetence, then it would be rapidly corrected.

                    If it's not rapidly corrected, then it is the purpose.

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      Today in InfoSec Job Security News:

                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                      perigee@rage.loveP This user is from outside of this forum
                      perigee@rage.loveP This user is from outside of this forum
                      perigee@rage.love
                      wrote sidst redigeret af
                      #66

                      @GossiTheDog @deliberately_me oh goodie. Our global repository has been compromised by a worm.

                      1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Today in InfoSec Job Security News:

                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                        synlogic4242@social.vivaldi.netS This user is from outside of this forum
                        synlogic4242@social.vivaldi.netS This user is from outside of this forum
                        synlogic4242@social.vivaldi.net
                        wrote sidst redigeret af
                        #67

                        @GossiTheDog loltears. ie. fools suffer consequences of being fools, but at scale

                        1 Reply Last reply
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Today in InfoSec Job Security News:

                          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                          el0j@mastodon.gamedev.placeE This user is from outside of this forum
                          el0j@mastodon.gamedev.placeE This user is from outside of this forum
                          el0j@mastodon.gamedev.place
                          wrote sidst redigeret af
                          #68

                          @GossiTheDog Fortunately, I can choose to not engage.

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Today in InfoSec Job Security News:

                            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                            tknarr@mstdn.socialT This user is from outside of this forum
                            tknarr@mstdn.socialT This user is from outside of this forum
                            tknarr@mstdn.social
                            wrote sidst redigeret af
                            #69

                            @GossiTheDog I think @timbray might be interested in that too.

                            1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Today in InfoSec Job Security News:

                              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                              G This user is from outside of this forum
                              G This user is from outside of this forum
                              geoglyphentropy@mstdn.social
                              wrote sidst redigeret af
                              #70

                              @GossiTheDog Not just bad vibes, but the *same* bad vibes repeated endlessly!

                              1 Reply Last reply
                              0
                              • c64whiz@oldbytes.spaceC c64whiz@oldbytes.space

                                @GossiTheDog

                                Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                                kiernian@infosec.exchangeK This user is from outside of this forum
                                kiernian@infosec.exchangeK This user is from outside of this forum
                                kiernian@infosec.exchange
                                wrote sidst redigeret af
                                #71

                                @c64whiz @GossiTheDog
                                This was honestly my first thought.

                                The vast majority of the tv-news-watching public barely understands computers as it is through no real fault of their own as they have been spoonfed "magic and mystery" since the dialup days.

                                The distinction of "open source = MORE dangerous than big company software" would be very easy for a front of united major media outlets owned by a handful rich folks to spread and most people will not be equipped to tell facts from misinformation.

                                How well have those open source legal protections been working against the "smart TV" industry? I'd bet every TV holding shelf I hit at Wal-Mart will be stocked with misappropriated GPL code and no source distribution.

                                This is the same tactic major corps use to obtain IP for themselves.

                                Lock up the originator in tedious, costly busywork (typically legal, claiming infringement to start a costly time-consuming trial, for most corps) and then when the originator can't handle it and collapse under the weight of it all, the corps take the product as their own.

                                Tying up repos with vulnerabilities that might not get noticed just might work out well for the major software outfits in the long run.

                                It's reprehensible and a little more haphazard, but it sure looks awfully familiar.

                                1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  Today in InfoSec Job Security News:

                                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                  n1xnx@tilde.zoneN This user is from outside of this forum
                                  n1xnx@tilde.zoneN This user is from outside of this forum
                                  n1xnx@tilde.zone
                                  wrote sidst redigeret af
                                  #72

                                  @GossiTheDog
                                  Aaaahhh!
                                  Who is giving clankers commit privileges to their repositories? Seems like an obvious failure of project management.

                                  crazyeddie@mastodon.socialC 1 Reply Last reply
                                  0
                                  • keith_lawson@mastodon.socialK keith_lawson@mastodon.social

                                    @GossiTheDog This was literally the first major security mistake I made in my early days as a Perl developer and I don't imagine it's that uncommon. Claude has probably been trained with a truckload of code with these vulnerabilities.

                                    That's okay because we run everything in single-purpose Docker containers now though, right? /s

                                    n1xnx@tilde.zoneN This user is from outside of this forum
                                    n1xnx@tilde.zoneN This user is from outside of this forum
                                    n1xnx@tilde.zone
                                    wrote sidst redigeret af
                                    #73

                                    @keith_lawson @GossiTheDog

                                    I keep pointing out to my coworkers that these clankers are trained on StackOverflow posts that contain code examples followed by "here's what I wrote, why doesn't it work?"

                                    1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      Today in InfoSec Job Security News:

                                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                      crypticrainfall@app.wafrn.netC This user is from outside of this forum
                                      crypticrainfall@app.wafrn.netC This user is from outside of this forum
                                      crypticrainfall@app.wafrn.net
                                      wrote sidst redigeret af
                                      #74

                                      This is just starting to sound like a cyber attack.

                                      1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Today in InfoSec Job Security News:

                                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                        gmoore@thepit.socialG This user is from outside of this forum
                                        gmoore@thepit.socialG This user is from outside of this forum
                                        gmoore@thepit.social
                                        wrote sidst redigeret af
                                        #75

                                        @GossiTheDog This kind of basic stuff is easily caught by any free static analysis tool. There's no excuse to not be running one in one's repo, vibe-coded or not.

                                        1 Reply Last reply
                                        0
                                        • drat@infosec.exchangeD drat@infosec.exchange

                                          @da_667 @GossiTheDog I wish that juice actually existed...

                                          crazyeddie@mastodon.socialC This user is from outside of this forum
                                          crazyeddie@mastodon.socialC This user is from outside of this forum
                                          crazyeddie@mastodon.social
                                          wrote sidst redigeret af
                                          #76

                                          @Drat @da_667 @GossiTheDog It does. In the form I was really fond of it's $50 per 750 ml and makes you say stupid shit like, "GASP...that's really smooth...." and then shove your head up your ass.

                                          But I'm actually sick to death of that kind of oblivion. The shit I have to unsee just keeps adding up as does the shame of letting shit pass by unopposed.

                                          benroyce@mastodon.socialB 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper