Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
84 Indlæg 64 Posters 18 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Today in InfoSec Job Security News:

    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

    sassinake@mastodon.socialS This user is from outside of this forum
    sassinake@mastodon.socialS This user is from outside of this forum
    sassinake@mastodon.social
    wrote sidst redigeret af
    #54

    @GossiTheDog

    fuck.

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Today in InfoSec Job Security News:

      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

      apples_and_pears@mastodon.worldA This user is from outside of this forum
      apples_and_pears@mastodon.worldA This user is from outside of this forum
      apples_and_pears@mastodon.world
      wrote sidst redigeret af
      #55

      @GossiTheDog I'm anti-AI. I used program generators long ago - they didn't work. They aren't maintainable. Major updates required complete rewrites.

      Now there's AI. It's a manager's wet dream...until it isn't.

      ...but look how productive AI is. It can whip out code as fast as a gossip can spread noise. Sure, there will be glitches, but they'll be fixed when found.

      What about the $$$$$ liability of glitches that are not found?

      1 Reply Last reply
      0
      • carpetbomberz@mastodon.onlineC This user is from outside of this forum
        carpetbomberz@mastodon.onlineC This user is from outside of this forum
        carpetbomberz@mastodon.online
        wrote sidst redigeret af
        #56

        @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

        We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

        carpetbomberz@mastodon.onlineC 1 Reply Last reply
        0
        • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

          @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

          We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

          carpetbomberz@mastodon.onlineC This user is from outside of this forum
          carpetbomberz@mastodon.onlineC This user is from outside of this forum
          carpetbomberz@mastodon.online
          wrote sidst redigeret af
          #57

          @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

          sassinake@mastodon.socialS 1 Reply Last reply
          0
          • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

            @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

            sassinake@mastodon.socialS This user is from outside of this forum
            sassinake@mastodon.socialS This user is from outside of this forum
            sassinake@mastodon.social
            wrote sidst redigeret af
            #58

            @carpetbomberz @funnymonkey @GossiTheDog

            this. Exactly this.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Today in InfoSec Job Security News:

              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

              gerhardd@olching.socialG This user is from outside of this forum
              gerhardd@olching.socialG This user is from outside of this forum
              gerhardd@olching.social
              wrote sidst redigeret af
              #59

              @GossiTheDog That #claude #AI has been created to solve the „we have too much electricity“ problem.

              1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                Today in InfoSec Job Security News:

                I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                jab01701mid@mastodon.socialJ This user is from outside of this forum
                jab01701mid@mastodon.socialJ This user is from outside of this forum
                jab01701mid@mastodon.social
                wrote sidst redigeret af
                #60

                @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                jab01701mid@mastodon.socialJ 1 Reply Last reply
                0
                • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                  @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                  jab01701mid@mastodon.socialJ This user is from outside of this forum
                  jab01701mid@mastodon.socialJ This user is from outside of this forum
                  jab01701mid@mastodon.social
                  wrote sidst redigeret af
                  #61

                  @GossiTheDog "AI" is the cryptocurrency of IT.

                  1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Today in InfoSec Job Security News:

                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                    vlkr@social.tchncs.deV This user is from outside of this forum
                    vlkr@social.tchncs.deV This user is from outside of this forum
                    vlkr@social.tchncs.de
                    wrote sidst redigeret af
                    #62

                    @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

                    crazyeddie@mastodon.socialC 1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      Today in InfoSec Job Security News:

                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                      vv@solarpunk.moeV This user is from outside of this forum
                      vv@solarpunk.moeV This user is from outside of this forum
                      vv@solarpunk.moe
                      wrote sidst redigeret af
                      #63

                      @GossiTheDog i keep waiting for a scandal to break out about this, but it never comes

                      1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Today in InfoSec Job Security News:

                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                        c64whiz@oldbytes.spaceC This user is from outside of this forum
                        c64whiz@oldbytes.spaceC This user is from outside of this forum
                        c64whiz@oldbytes.space
                        wrote sidst redigeret af
                        #64

                        @GossiTheDog

                        Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                        kiernian@infosec.exchangeK 1 Reply Last reply
                        0
                        • draeath@infosec.exchangeD draeath@infosec.exchange

                          @nihkeys @DJGummikuh @GossiTheDog I don't think that phrase allows for incompetency in design. The purpose is what was intended, not what actually results. There is a distinction.

                          azuaron@cyberpunk.lolA This user is from outside of this forum
                          azuaron@cyberpunk.lolA This user is from outside of this forum
                          azuaron@cyberpunk.lol
                          wrote sidst redigeret af
                          #65

                          @draeath @nihkeys @DJGummikuh @GossiTheDog If it was an accident, or incompetence, then it would be rapidly corrected.

                          If it's not rapidly corrected, then it is the purpose.

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Today in InfoSec Job Security News:

                            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                            perigee@rage.loveP This user is from outside of this forum
                            perigee@rage.loveP This user is from outside of this forum
                            perigee@rage.love
                            wrote sidst redigeret af
                            #66

                            @GossiTheDog @deliberately_me oh goodie. Our global repository has been compromised by a worm.

                            1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Today in InfoSec Job Security News:

                              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                              synlogic4242@social.vivaldi.netS This user is from outside of this forum
                              synlogic4242@social.vivaldi.netS This user is from outside of this forum
                              synlogic4242@social.vivaldi.net
                              wrote sidst redigeret af
                              #67

                              @GossiTheDog loltears. ie. fools suffer consequences of being fools, but at scale

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Today in InfoSec Job Security News:

                                I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                el0j@mastodon.gamedev.place
                                wrote sidst redigeret af
                                #68

                                @GossiTheDog Fortunately, I can choose to not engage.

                                1 Reply Last reply
                                0
                                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                  Today in InfoSec Job Security News:

                                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                  tknarr@mstdn.socialT This user is from outside of this forum
                                  tknarr@mstdn.socialT This user is from outside of this forum
                                  tknarr@mstdn.social
                                  wrote sidst redigeret af
                                  #69

                                  @GossiTheDog I think @timbray might be interested in that too.

                                  1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    Today in InfoSec Job Security News:

                                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                    G This user is from outside of this forum
                                    G This user is from outside of this forum
                                    geoglyphentropy@mstdn.social
                                    wrote sidst redigeret af
                                    #70

                                    @GossiTheDog Not just bad vibes, but the *same* bad vibes repeated endlessly!

                                    1 Reply Last reply
                                    0
                                    • c64whiz@oldbytes.spaceC c64whiz@oldbytes.space

                                      @GossiTheDog

                                      Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                                      kiernian@infosec.exchangeK This user is from outside of this forum
                                      kiernian@infosec.exchangeK This user is from outside of this forum
                                      kiernian@infosec.exchange
                                      wrote sidst redigeret af
                                      #71

                                      @c64whiz @GossiTheDog
                                      This was honestly my first thought.

                                      The vast majority of the tv-news-watching public barely understands computers as it is through no real fault of their own as they have been spoonfed "magic and mystery" since the dialup days.

                                      The distinction of "open source = MORE dangerous than big company software" would be very easy for a front of united major media outlets owned by a handful rich folks to spread and most people will not be equipped to tell facts from misinformation.

                                      How well have those open source legal protections been working against the "smart TV" industry? I'd bet every TV holding shelf I hit at Wal-Mart will be stocked with misappropriated GPL code and no source distribution.

                                      This is the same tactic major corps use to obtain IP for themselves.

                                      Lock up the originator in tedious, costly busywork (typically legal, claiming infringement to start a costly time-consuming trial, for most corps) and then when the originator can't handle it and collapse under the weight of it all, the corps take the product as their own.

                                      Tying up repos with vulnerabilities that might not get noticed just might work out well for the major software outfits in the long run.

                                      It's reprehensible and a little more haphazard, but it sure looks awfully familiar.

                                      1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Today in InfoSec Job Security News:

                                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                        n1xnx@tilde.zoneN This user is from outside of this forum
                                        n1xnx@tilde.zoneN This user is from outside of this forum
                                        n1xnx@tilde.zone
                                        wrote sidst redigeret af
                                        #72

                                        @GossiTheDog
                                        Aaaahhh!
                                        Who is giving clankers commit privileges to their repositories? Seems like an obvious failure of project management.

                                        crazyeddie@mastodon.socialC 1 Reply Last reply
                                        0
                                        • keith_lawson@mastodon.socialK keith_lawson@mastodon.social

                                          @GossiTheDog This was literally the first major security mistake I made in my early days as a Perl developer and I don't imagine it's that uncommon. Claude has probably been trained with a truckload of code with these vulnerabilities.

                                          That's okay because we run everything in single-purpose Docker containers now though, right? /s

                                          n1xnx@tilde.zoneN This user is from outside of this forum
                                          n1xnx@tilde.zoneN This user is from outside of this forum
                                          n1xnx@tilde.zone
                                          wrote sidst redigeret af
                                          #73

                                          @keith_lawson @GossiTheDog

                                          I keep pointing out to my coworkers that these clankers are trained on StackOverflow posts that contain code examples followed by "here's what I wrote, why doesn't it work?"

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper