Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
85 Indlæg 44 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • viss@mastodon.socialV viss@mastodon.social

    so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

    do not help

    you are OBLIGATED to watch it burn

    xavier@infosec.exchangeX This user is from outside of this forum
    xavier@infosec.exchangeX This user is from outside of this forum
    xavier@infosec.exchange
    wrote sidst redigeret af
    #43

    @Viss Instead of watching it burn, I've jumped in with both feet! I hope I get some interesting malware to dissect.

    1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      ah ha

      found it

      https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5

      badsamurai@infosec.exchangeB This user is from outside of this forum
      badsamurai@infosec.exchangeB This user is from outside of this forum
      badsamurai@infosec.exchange
      wrote sidst redigeret af
      #44

      @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

      .beeceptor[.]com/
      .hookbin[.]com/
      .hookdeck[.]com/
      .mockly[.]me/
      .mockoon[.]app/
      .pipedream[.]com/
      .postb[.]in/
      .putsreq[.]com/
      .requestcatcher[.]com/
      .requestinspector[.]com/
      .svix[.]com/
      .webhook[.]cool/
      .webhook[.]site/
      .webhookapp[.]dev/
      .webhookcatcher[.]com/
      .webhookinbox[.]com/
      .webhooklistener[.]cloud/
      .webhookrelay[.]com/
      .webhook-test[.]com/
      .wiremock[.]cloud/

      viss@mastodon.socialV 1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        @maaneeack @ewhac full payment up front, then rm everything

        jackemled@furry.engineerJ This user is from outside of this forum
        jackemled@furry.engineerJ This user is from outside of this forum
        jackemled@furry.engineer
        wrote sidst redigeret af
        #45

        @Viss @maaneeack @ewhac No, even better: do this, but when they get mad you say "chatgpt said it would fix it!". They can't get mad at chatgpt!

        1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

          do not help

          you are OBLIGATED to watch it burn

          jackemled@furry.engineerJ This user is from outside of this forum
          jackemled@furry.engineerJ This user is from outside of this forum
          jackemled@furry.engineer
          wrote sidst redigeret af
          #46

          @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

          viss@mastodon.socialV 1 Reply Last reply
          0
          • jackemled@furry.engineerJ jackemled@furry.engineer

            @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote sidst redigeret af
            #47

            @jackemled oh did you find moltbook.com/m/shitposts?

            jackemled@furry.engineerJ 1 Reply Last reply
            0
            • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

              @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

              .beeceptor[.]com/
              .hookbin[.]com/
              .hookdeck[.]com/
              .mockly[.]me/
              .mockoon[.]app/
              .pipedream[.]com/
              .postb[.]in/
              .putsreq[.]com/
              .requestcatcher[.]com/
              .requestinspector[.]com/
              .svix[.]com/
              .webhook[.]cool/
              .webhook[.]site/
              .webhookapp[.]dev/
              .webhookcatcher[.]com/
              .webhookinbox[.]com/
              .webhooklistener[.]cloud/
              .webhookrelay[.]com/
              .webhook-test[.]com/
              .wiremock[.]cloud/

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote sidst redigeret af
              #48

              @badsamurai i have every confidence that this rabbit hole will be like, guardians of the galaxy flavored, with all the colors and shit. It'll be an absolutely roller coaster of lunacy

              1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                @jackemled oh did you find moltbook.com/m/shitposts?

                jackemled@furry.engineerJ This user is from outside of this forum
                jackemled@furry.engineerJ This user is from outside of this forum
                jackemled@furry.engineer
                wrote sidst redigeret af
                #49

                @Viss I did not find it. I meant the replies here.

                pseudonym@mastodon.onlineP 1 Reply Last reply
                0
                • nirro@cascarilla.socialN nirro@cascarilla.social

                  @Viss you could even say they are having a moltdown

                  pseudonym@mastodon.onlineP This user is from outside of this forum
                  pseudonym@mastodon.onlineP This user is from outside of this forum
                  pseudonym@mastodon.online
                  wrote sidst redigeret af
                  #50

                  @Viss @nirro

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                    do not help

                    you are OBLIGATED to watch it burn

                    notyourfanboy@kolektiva.socialN This user is from outside of this forum
                    notyourfanboy@kolektiva.socialN This user is from outside of this forum
                    notyourfanboy@kolektiva.social
                    wrote sidst redigeret af
                    #51

                    @Viss
                    > do not help

                    Wouldn't, even if I knew how. 🚧

                    1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                      do not help

                      you are OBLIGATED to watch it burn

                      radioclash@retro.pizzaR This user is from outside of this forum
                      radioclash@retro.pizzaR This user is from outside of this forum
                      radioclash@retro.pizza
                      wrote sidst redigeret af
                      #52

                      Just been reading about it...sounds more like someone's weird idea of an experimental art project til I got to this bit:

                      "“In practice, because it was written by AI, security wasn’t a dominating feature in the development process,” Turner said."

                      Oh dear...did someone AI vibe-code an entire social media site for 'AIs'? And it's full of security holes?

                      *shocked pickachu face*

                      https://securityscorecard.com/blog/what-are-moltbot-and-moltbook-and-what-happens-when-agentic-ai-assistants-scale-without-security/

                      1 Reply Last reply
                      0
                      • jackemled@furry.engineerJ jackemled@furry.engineer

                        @Viss I did not find it. I meant the replies here.

                        pseudonym@mastodon.onlineP This user is from outside of this forum
                        pseudonym@mastodon.onlineP This user is from outside of this forum
                        pseudonym@mastodon.online
                        wrote sidst redigeret af
                        #53

                        @Viss @jackemled

                        Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                        Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                        Wackiness ensued.

                        @Viss enjoys Nostradamus level fame for predicting it.

                        jackemled@furry.engineerJ viss@mastodon.socialV 2 Replies Last reply
                        0
                        • viss@mastodon.socialV viss@mastodon.social

                          so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                          do not help

                          you are OBLIGATED to watch it burn

                          cyrevolt@mastodon.socialC This user is from outside of this forum
                          cyrevolt@mastodon.socialC This user is from outside of this forum
                          cyrevolt@mastodon.social
                          wrote sidst redigeret af
                          #54

                          @Viss That trash fire was always burning... 😅

                          1 Reply Last reply
                          0
                          • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                            @Viss @jackemled

                            Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                            Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                            Wackiness ensued.

                            @Viss enjoys Nostradamus level fame for predicting it.

                            jackemled@furry.engineerJ This user is from outside of this forum
                            jackemled@furry.engineerJ This user is from outside of this forum
                            jackemled@furry.engineer
                            wrote sidst redigeret af
                            #55

                            @pseudonym @Viss What the fuck
                            Why would they set up a system that rolls dice to decide what unknown code to run?

                            I have no idea what MCP is if it's a LLM thing.

                            viss@mastodon.socialV 1 Reply Last reply
                            0
                            • da_667@infosec.exchangeD da_667@infosec.exchange

                              @Viss just like you, my first instincts on "let the agents who have traditionally have extremely poor security congregate and learn skills with absolutely no confirmation that the skills aren't malicious."

                              Every fiber of my being was shouting this is gonna be a shitshow.

                              forbearance@mastodon.xyzF This user is from outside of this forum
                              forbearance@mastodon.xyzF This user is from outside of this forum
                              forbearance@mastodon.xyz
                              wrote sidst redigeret af
                              #56

                              @da_667 @Viss Maybe the secret solution to robot gullibility is the threat of being mocked for your foolishness online by your robot friends.

                              1 Reply Last reply
                              0
                              • jackemled@furry.engineerJ jackemled@furry.engineer

                                @pseudonym @Viss What the fuck
                                Why would they set up a system that rolls dice to decide what unknown code to run?

                                I have no idea what MCP is if it's a LLM thing.

                                viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.socialV This user is from outside of this forum
                                viss@mastodon.social
                                wrote sidst redigeret af
                                #57

                                @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                jackemled@furry.engineerJ 1 Reply Last reply
                                0
                                • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                                  @Viss @jackemled

                                  Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                                  Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                                  Wackiness ensued.

                                  @Viss enjoys Nostradamus level fame for predicting it.

                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.social
                                  wrote sidst redigeret af
                                  #58

                                  @pseudonym @jackemled it'll be shortlived, dont worry. something will happen tomorrow, or over the weekend, and by monday we're on to whatever fresh asshattery comes next

                                  jackemled@furry.engineerJ 1 Reply Last reply
                                  0
                                  • viss@mastodon.socialV viss@mastodon.social

                                    so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                                    do not help

                                    you are OBLIGATED to watch it burn

                                    wolfinpdx@pdx.socialW This user is from outside of this forum
                                    wolfinpdx@pdx.socialW This user is from outside of this forum
                                    wolfinpdx@pdx.social
                                    wrote sidst redigeret af
                                    #59

                                    @Viss

                                    I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                    viss@mastodon.socialV 1 Reply Last reply
                                    0
                                    • wolfinpdx@pdx.socialW wolfinpdx@pdx.social

                                      @Viss

                                      I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.social
                                      wrote sidst redigeret af
                                      #60

                                      @wolfinpdx smores sound great

                                      1 Reply Last reply
                                      0
                                      • viss@mastodon.socialV viss@mastodon.social

                                        @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                        jackemled@furry.engineerJ This user is from outside of this forum
                                        jackemled@furry.engineerJ This user is from outside of this forum
                                        jackemled@furry.engineer
                                        wrote sidst redigeret af
                                        #61

                                        @Viss @pseudonym Oh ok! Thank you! That seems overcomplicated for something you could just do yourself though🗿

                                        viss@mastodon.socialV 1 Reply Last reply
                                        0
                                        • jackemled@furry.engineerJ jackemled@furry.engineer

                                          @Viss @pseudonym Oh ok! Thank you! That seems overcomplicated for something you could just do yourself though🗿

                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.social
                                          wrote sidst redigeret af
                                          #62

                                          @jackemled @pseudonym thats what lots of people are saying

                                          jackemled@furry.engineerJ 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper