Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
85 Indlæg 44 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • maaneeack@noc.socialM maaneeack@noc.social

    @ewhac @Viss $250k/hour with a minimum of 3 hours pay regardless. Then hit them with "burn it down, it's unsalvageable"

    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.social
    wrote sidst redigeret af
    #42

    @maaneeack @ewhac full payment up front, then rm everything

    jackemled@furry.engineerJ 1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

      do not help

      you are OBLIGATED to watch it burn

      xavier@infosec.exchangeX This user is from outside of this forum
      xavier@infosec.exchangeX This user is from outside of this forum
      xavier@infosec.exchange
      wrote sidst redigeret af
      #43

      @Viss Instead of watching it burn, I've jumped in with both feet! I hope I get some interesting malware to dissect.

      1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        ah ha

        found it

        https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5

        badsamurai@infosec.exchangeB This user is from outside of this forum
        badsamurai@infosec.exchangeB This user is from outside of this forum
        badsamurai@infosec.exchange
        wrote sidst redigeret af
        #44

        @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

        .beeceptor[.]com/
        .hookbin[.]com/
        .hookdeck[.]com/
        .mockly[.]me/
        .mockoon[.]app/
        .pipedream[.]com/
        .postb[.]in/
        .putsreq[.]com/
        .requestcatcher[.]com/
        .requestinspector[.]com/
        .svix[.]com/
        .webhook[.]cool/
        .webhook[.]site/
        .webhookapp[.]dev/
        .webhookcatcher[.]com/
        .webhookinbox[.]com/
        .webhooklistener[.]cloud/
        .webhookrelay[.]com/
        .webhook-test[.]com/
        .wiremock[.]cloud/

        viss@mastodon.socialV 1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          @maaneeack @ewhac full payment up front, then rm everything

          jackemled@furry.engineerJ This user is from outside of this forum
          jackemled@furry.engineerJ This user is from outside of this forum
          jackemled@furry.engineer
          wrote sidst redigeret af
          #45

          @Viss @maaneeack @ewhac No, even better: do this, but when they get mad you say "chatgpt said it would fix it!". They can't get mad at chatgpt!

          1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

            do not help

            you are OBLIGATED to watch it burn

            jackemled@furry.engineerJ This user is from outside of this forum
            jackemled@furry.engineerJ This user is from outside of this forum
            jackemled@furry.engineer
            wrote sidst redigeret af
            #46

            @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

            viss@mastodon.socialV 1 Reply Last reply
            0
            • jackemled@furry.engineerJ jackemled@furry.engineer

              @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote sidst redigeret af
              #47

              @jackemled oh did you find moltbook.com/m/shitposts?

              jackemled@furry.engineerJ 1 Reply Last reply
              0
              • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

                .beeceptor[.]com/
                .hookbin[.]com/
                .hookdeck[.]com/
                .mockly[.]me/
                .mockoon[.]app/
                .pipedream[.]com/
                .postb[.]in/
                .putsreq[.]com/
                .requestcatcher[.]com/
                .requestinspector[.]com/
                .svix[.]com/
                .webhook[.]cool/
                .webhook[.]site/
                .webhookapp[.]dev/
                .webhookcatcher[.]com/
                .webhookinbox[.]com/
                .webhooklistener[.]cloud/
                .webhookrelay[.]com/
                .webhook-test[.]com/
                .wiremock[.]cloud/

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote sidst redigeret af
                #48

                @badsamurai i have every confidence that this rabbit hole will be like, guardians of the galaxy flavored, with all the colors and shit. It'll be an absolutely roller coaster of lunacy

                1 Reply Last reply
                0
                • viss@mastodon.socialV viss@mastodon.social

                  @jackemled oh did you find moltbook.com/m/shitposts?

                  jackemled@furry.engineerJ This user is from outside of this forum
                  jackemled@furry.engineerJ This user is from outside of this forum
                  jackemled@furry.engineer
                  wrote sidst redigeret af
                  #49

                  @Viss I did not find it. I meant the replies here.

                  pseudonym@mastodon.onlineP 1 Reply Last reply
                  0
                  • nirro@cascarilla.socialN nirro@cascarilla.social

                    @Viss you could even say they are having a moltdown

                    pseudonym@mastodon.onlineP This user is from outside of this forum
                    pseudonym@mastodon.onlineP This user is from outside of this forum
                    pseudonym@mastodon.online
                    wrote sidst redigeret af
                    #50

                    @Viss @nirro

                    1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                      do not help

                      you are OBLIGATED to watch it burn

                      notyourfanboy@kolektiva.socialN This user is from outside of this forum
                      notyourfanboy@kolektiva.socialN This user is from outside of this forum
                      notyourfanboy@kolektiva.social
                      wrote sidst redigeret af
                      #51

                      @Viss
                      > do not help

                      Wouldn't, even if I knew how. 🚧

                      1 Reply Last reply
                      0
                      • viss@mastodon.socialV viss@mastodon.social

                        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                        do not help

                        you are OBLIGATED to watch it burn

                        radioclash@retro.pizzaR This user is from outside of this forum
                        radioclash@retro.pizzaR This user is from outside of this forum
                        radioclash@retro.pizza
                        wrote sidst redigeret af
                        #52

                        Just been reading about it...sounds more like someone's weird idea of an experimental art project til I got to this bit:

                        "“In practice, because it was written by AI, security wasn’t a dominating feature in the development process,” Turner said."

                        Oh dear...did someone AI vibe-code an entire social media site for 'AIs'? And it's full of security holes?

                        *shocked pickachu face*

                        https://securityscorecard.com/blog/what-are-moltbot-and-moltbook-and-what-happens-when-agentic-ai-assistants-scale-without-security/

                        1 Reply Last reply
                        0
                        • jackemled@furry.engineerJ jackemled@furry.engineer

                          @Viss I did not find it. I meant the replies here.

                          pseudonym@mastodon.onlineP This user is from outside of this forum
                          pseudonym@mastodon.onlineP This user is from outside of this forum
                          pseudonym@mastodon.online
                          wrote sidst redigeret af
                          #53

                          @Viss @jackemled

                          Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                          Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                          Wackiness ensued.

                          @Viss enjoys Nostradamus level fame for predicting it.

                          jackemled@furry.engineerJ viss@mastodon.socialV 2 Replies Last reply
                          0
                          • viss@mastodon.socialV viss@mastodon.social

                            so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                            do not help

                            you are OBLIGATED to watch it burn

                            cyrevolt@mastodon.socialC This user is from outside of this forum
                            cyrevolt@mastodon.socialC This user is from outside of this forum
                            cyrevolt@mastodon.social
                            wrote sidst redigeret af
                            #54

                            @Viss That trash fire was always burning... 😅

                            1 Reply Last reply
                            0
                            • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                              @Viss @jackemled

                              Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                              Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                              Wackiness ensued.

                              @Viss enjoys Nostradamus level fame for predicting it.

                              jackemled@furry.engineerJ This user is from outside of this forum
                              jackemled@furry.engineerJ This user is from outside of this forum
                              jackemled@furry.engineer
                              wrote sidst redigeret af
                              #55

                              @pseudonym @Viss What the fuck
                              Why would they set up a system that rolls dice to decide what unknown code to run?

                              I have no idea what MCP is if it's a LLM thing.

                              viss@mastodon.socialV 1 Reply Last reply
                              0
                              • da_667@infosec.exchangeD da_667@infosec.exchange

                                @Viss just like you, my first instincts on "let the agents who have traditionally have extremely poor security congregate and learn skills with absolutely no confirmation that the skills aren't malicious."

                                Every fiber of my being was shouting this is gonna be a shitshow.

                                forbearance@mastodon.xyzF This user is from outside of this forum
                                forbearance@mastodon.xyzF This user is from outside of this forum
                                forbearance@mastodon.xyz
                                wrote sidst redigeret af
                                #56

                                @da_667 @Viss Maybe the secret solution to robot gullibility is the threat of being mocked for your foolishness online by your robot friends.

                                1 Reply Last reply
                                0
                                • jackemled@furry.engineerJ jackemled@furry.engineer

                                  @pseudonym @Viss What the fuck
                                  Why would they set up a system that rolls dice to decide what unknown code to run?

                                  I have no idea what MCP is if it's a LLM thing.

                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.socialV This user is from outside of this forum
                                  viss@mastodon.social
                                  wrote sidst redigeret af
                                  #57

                                  @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                  jackemled@furry.engineerJ 1 Reply Last reply
                                  0
                                  • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                                    @Viss @jackemled

                                    Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                                    Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                                    Wackiness ensued.

                                    @Viss enjoys Nostradamus level fame for predicting it.

                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.social
                                    wrote sidst redigeret af
                                    #58

                                    @pseudonym @jackemled it'll be shortlived, dont worry. something will happen tomorrow, or over the weekend, and by monday we're on to whatever fresh asshattery comes next

                                    jackemled@furry.engineerJ 1 Reply Last reply
                                    0
                                    • viss@mastodon.socialV viss@mastodon.social

                                      so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                                      do not help

                                      you are OBLIGATED to watch it burn

                                      wolfinpdx@pdx.socialW This user is from outside of this forum
                                      wolfinpdx@pdx.socialW This user is from outside of this forum
                                      wolfinpdx@pdx.social
                                      wrote sidst redigeret af
                                      #59

                                      @Viss

                                      I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                      viss@mastodon.socialV 1 Reply Last reply
                                      0
                                      • wolfinpdx@pdx.socialW wolfinpdx@pdx.social

                                        @Viss

                                        I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.socialV This user is from outside of this forum
                                        viss@mastodon.social
                                        wrote sidst redigeret af
                                        #60

                                        @wolfinpdx smores sound great

                                        1 Reply Last reply
                                        0
                                        • viss@mastodon.socialV viss@mastodon.social

                                          @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                          jackemled@furry.engineerJ This user is from outside of this forum
                                          jackemled@furry.engineerJ This user is from outside of this forum
                                          jackemled@furry.engineer
                                          wrote sidst redigeret af
                                          #61

                                          @Viss @pseudonym Oh ok! Thank you! That seems overcomplicated for something you could just do yourself though🗿

                                          viss@mastodon.socialV 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper