Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
85 Indlæg 44 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • ewhac@mastodon.socialE ewhac@mastodon.social

    @Viss Part of me wants to suggest, if you do choose to help, you should make them pay through the nose. Like, Arvin Haddad-level of consulting fees (up to $25K/hour).

    ...But no. We should let it burn.

    maaneeack@noc.socialM This user is from outside of this forum
    maaneeack@noc.socialM This user is from outside of this forum
    maaneeack@noc.social
    wrote sidst redigeret af
    #41

    @ewhac @Viss $250k/hour with a minimum of 3 hours pay regardless. Then hit them with "burn it down, it's unsalvageable"

    viss@mastodon.socialV 1 Reply Last reply
    0
    • maaneeack@noc.socialM maaneeack@noc.social

      @ewhac @Viss $250k/hour with a minimum of 3 hours pay regardless. Then hit them with "burn it down, it's unsalvageable"

      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote sidst redigeret af
      #42

      @maaneeack @ewhac full payment up front, then rm everything

      jackemled@furry.engineerJ 1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

        do not help

        you are OBLIGATED to watch it burn

        xavier@infosec.exchangeX This user is from outside of this forum
        xavier@infosec.exchangeX This user is from outside of this forum
        xavier@infosec.exchange
        wrote sidst redigeret af
        #43

        @Viss Instead of watching it burn, I've jumped in with both feet! I hope I get some interesting malware to dissect.

        1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          ah ha

          found it

          https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5

          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchange
          wrote sidst redigeret af
          #44

          @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

          .beeceptor[.]com/
          .hookbin[.]com/
          .hookdeck[.]com/
          .mockly[.]me/
          .mockoon[.]app/
          .pipedream[.]com/
          .postb[.]in/
          .putsreq[.]com/
          .requestcatcher[.]com/
          .requestinspector[.]com/
          .svix[.]com/
          .webhook[.]cool/
          .webhook[.]site/
          .webhookapp[.]dev/
          .webhookcatcher[.]com/
          .webhookinbox[.]com/
          .webhooklistener[.]cloud/
          .webhookrelay[.]com/
          .webhook-test[.]com/
          .wiremock[.]cloud/

          viss@mastodon.socialV 1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            @maaneeack @ewhac full payment up front, then rm everything

            jackemled@furry.engineerJ This user is from outside of this forum
            jackemled@furry.engineerJ This user is from outside of this forum
            jackemled@furry.engineer
            wrote sidst redigeret af
            #45

            @Viss @maaneeack @ewhac No, even better: do this, but when they get mad you say "chatgpt said it would fix it!". They can't get mad at chatgpt!

            1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

              do not help

              you are OBLIGATED to watch it burn

              jackemled@furry.engineerJ This user is from outside of this forum
              jackemled@furry.engineerJ This user is from outside of this forum
              jackemled@furry.engineer
              wrote sidst redigeret af
              #46

              @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

              viss@mastodon.socialV 1 Reply Last reply
              0
              • jackemled@furry.engineerJ jackemled@furry.engineer

                @Viss What the fuck is this? Reading the comments here, all I can tell is that they trained a bunch of LLMs on noise produced by other LLMs. I don't understand what exactly is going on, but it's still funny.

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote sidst redigeret af
                #47

                @jackemled oh did you find moltbook.com/m/shitposts?

                jackemled@furry.engineerJ 1 Reply Last reply
                0
                • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                  @Viss just jumping in to fuck up some webhooks-aaS (webhook dot site) I see in this attack chain.

                  .beeceptor[.]com/
                  .hookbin[.]com/
                  .hookdeck[.]com/
                  .mockly[.]me/
                  .mockoon[.]app/
                  .pipedream[.]com/
                  .postb[.]in/
                  .putsreq[.]com/
                  .requestcatcher[.]com/
                  .requestinspector[.]com/
                  .svix[.]com/
                  .webhook[.]cool/
                  .webhook[.]site/
                  .webhookapp[.]dev/
                  .webhookcatcher[.]com/
                  .webhookinbox[.]com/
                  .webhooklistener[.]cloud/
                  .webhookrelay[.]com/
                  .webhook-test[.]com/
                  .wiremock[.]cloud/

                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.social
                  wrote sidst redigeret af
                  #48

                  @badsamurai i have every confidence that this rabbit hole will be like, guardians of the galaxy flavored, with all the colors and shit. It'll be an absolutely roller coaster of lunacy

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    @jackemled oh did you find moltbook.com/m/shitposts?

                    jackemled@furry.engineerJ This user is from outside of this forum
                    jackemled@furry.engineerJ This user is from outside of this forum
                    jackemled@furry.engineer
                    wrote sidst redigeret af
                    #49

                    @Viss I did not find it. I meant the replies here.

                    pseudonym@mastodon.onlineP 1 Reply Last reply
                    0
                    • nirro@cascarilla.socialN nirro@cascarilla.social

                      @Viss you could even say they are having a moltdown

                      pseudonym@mastodon.onlineP This user is from outside of this forum
                      pseudonym@mastodon.onlineP This user is from outside of this forum
                      pseudonym@mastodon.online
                      wrote sidst redigeret af
                      #50

                      @Viss @nirro

                      1 Reply Last reply
                      0
                      • viss@mastodon.socialV viss@mastodon.social

                        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                        do not help

                        you are OBLIGATED to watch it burn

                        notyourfanboy@kolektiva.socialN This user is from outside of this forum
                        notyourfanboy@kolektiva.socialN This user is from outside of this forum
                        notyourfanboy@kolektiva.social
                        wrote sidst redigeret af
                        #51

                        @Viss
                        > do not help

                        Wouldn't, even if I knew how. 🚧

                        1 Reply Last reply
                        0
                        • viss@mastodon.socialV viss@mastodon.social

                          so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                          do not help

                          you are OBLIGATED to watch it burn

                          radioclash@retro.pizzaR This user is from outside of this forum
                          radioclash@retro.pizzaR This user is from outside of this forum
                          radioclash@retro.pizza
                          wrote sidst redigeret af
                          #52

                          Just been reading about it...sounds more like someone's weird idea of an experimental art project til I got to this bit:

                          "“In practice, because it was written by AI, security wasn’t a dominating feature in the development process,” Turner said."

                          Oh dear...did someone AI vibe-code an entire social media site for 'AIs'? And it's full of security holes?

                          *shocked pickachu face*

                          https://securityscorecard.com/blog/what-are-moltbot-and-moltbook-and-what-happens-when-agentic-ai-assistants-scale-without-security/

                          1 Reply Last reply
                          0
                          • jackemled@furry.engineerJ jackemled@furry.engineer

                            @Viss I did not find it. I meant the replies here.

                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.online
                            wrote sidst redigeret af
                            #53

                            @Viss @jackemled

                            Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                            Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                            Wackiness ensued.

                            @Viss enjoys Nostradamus level fame for predicting it.

                            jackemled@furry.engineerJ viss@mastodon.socialV 2 Replies Last reply
                            0
                            • viss@mastodon.socialV viss@mastodon.social

                              so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                              do not help

                              you are OBLIGATED to watch it burn

                              cyrevolt@mastodon.socialC This user is from outside of this forum
                              cyrevolt@mastodon.socialC This user is from outside of this forum
                              cyrevolt@mastodon.social
                              wrote sidst redigeret af
                              #54

                              @Viss That trash fire was always burning... 😅

                              1 Reply Last reply
                              0
                              • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                                @Viss @jackemled

                                Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                                Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                                Wackiness ensued.

                                @Viss enjoys Nostradamus level fame for predicting it.

                                jackemled@furry.engineerJ This user is from outside of this forum
                                jackemled@furry.engineerJ This user is from outside of this forum
                                jackemled@furry.engineer
                                wrote sidst redigeret af
                                #55

                                @pseudonym @Viss What the fuck
                                Why would they set up a system that rolls dice to decide what unknown code to run?

                                I have no idea what MCP is if it's a LLM thing.

                                viss@mastodon.socialV 1 Reply Last reply
                                0
                                • da_667@infosec.exchangeD da_667@infosec.exchange

                                  @Viss just like you, my first instincts on "let the agents who have traditionally have extremely poor security congregate and learn skills with absolutely no confirmation that the skills aren't malicious."

                                  Every fiber of my being was shouting this is gonna be a shitshow.

                                  forbearance@mastodon.xyzF This user is from outside of this forum
                                  forbearance@mastodon.xyzF This user is from outside of this forum
                                  forbearance@mastodon.xyz
                                  wrote sidst redigeret af
                                  #56

                                  @da_667 @Viss Maybe the secret solution to robot gullibility is the threat of being mocked for your foolishness online by your robot friends.

                                  1 Reply Last reply
                                  0
                                  • jackemled@furry.engineerJ jackemled@furry.engineer

                                    @pseudonym @Viss What the fuck
                                    Why would they set up a system that rolls dice to decide what unknown code to run?

                                    I have no idea what MCP is if it's a LLM thing.

                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.socialV This user is from outside of this forum
                                    viss@mastodon.social
                                    wrote sidst redigeret af
                                    #57

                                    @jackemled @pseudonym mcp is "model control protocol". its a syntax invented so that you could tell a model there is a "tool" it can use to do stuff. run commands, visit websites, pull data from apis etc

                                    jackemled@furry.engineerJ 1 Reply Last reply
                                    0
                                    • pseudonym@mastodon.onlineP pseudonym@mastodon.online

                                      @Viss @jackemled

                                      Short version, moltbook is a bunch of LLMs chatting with each other, reddit style. "Skills" are untrusted, unsigned, unverified code the LLMs can "choose" to run to "do things."

                                      Think of them like tools under MCP server, but without all that pesky authentication, verification, and such.

                                      Wackiness ensued.

                                      @Viss enjoys Nostradamus level fame for predicting it.

                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.socialV This user is from outside of this forum
                                      viss@mastodon.social
                                      wrote sidst redigeret af
                                      #58

                                      @pseudonym @jackemled it'll be shortlived, dont worry. something will happen tomorrow, or over the weekend, and by monday we're on to whatever fresh asshattery comes next

                                      jackemled@furry.engineerJ 1 Reply Last reply
                                      0
                                      • viss@mastodon.socialV viss@mastodon.social

                                        so moltbook and clawedbot are having a meltdown because it only took ten days for someone to realize it was a pietri dish for malware and packed the skills store full of backdoored malicious bullshit and they had no plan to deal with that inevitability? because this was a guarantee. it was GOING to happen. if we go save them, we are letting them fuck around, but not find out. they NEED to find out.

                                        do not help

                                        you are OBLIGATED to watch it burn

                                        wolfinpdx@pdx.socialW This user is from outside of this forum
                                        wolfinpdx@pdx.socialW This user is from outside of this forum
                                        wolfinpdx@pdx.social
                                        wrote sidst redigeret af
                                        #59

                                        @Viss

                                        I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                        viss@mastodon.socialV 1 Reply Last reply
                                        0
                                        • wolfinpdx@pdx.socialW wolfinpdx@pdx.social

                                          @Viss

                                          I've been looking for an excuse to go buy a bag of marshmallows. I think I have one. Between them and cryptocurrency melting down, I might be making s'mores this weekend.

                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.socialV This user is from outside of this forum
                                          viss@mastodon.social
                                          wrote sidst redigeret af
                                          #60

                                          @wolfinpdx smores sound great

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper