Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
41 Indlæg 25 Posters 20 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • endorama@hachyderm.ioE endorama@hachyderm.io

    @mhoye could you share the source? Thanks in advance

    mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.ca
    wrote sidst redigeret af
    #12

    @endorama

    https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

    1 Reply Last reply
    0
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

      cdamian@rls.socialC This user is from outside of this forum
      cdamian@rls.socialC This user is from outside of this forum
      cdamian@rls.social
      wrote sidst redigeret af
      #13

      @mhoye
      Could you provide a source URL to this?

      cdamian@rls.socialC 1 Reply Last reply
      0
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

        pseudonym@mastodon.onlineP This user is from outside of this forum
        pseudonym@mastodon.onlineP This user is from outside of this forum
        pseudonym@mastodon.online
        wrote sidst redigeret af
        #14

        @mhoye

        #infosec

        Install attack surface as a service.

        IASaaS

        No, swap that...

        Attack Interface Surface as a Service

        AISaaS

        1 Reply Last reply
        0
        • cdamian@rls.socialC cdamian@rls.social

          @mhoye
          Could you provide a source URL to this?

          cdamian@rls.socialC This user is from outside of this forum
          cdamian@rls.socialC This user is from outside of this forum
          cdamian@rls.social
          wrote sidst redigeret af
          #15

          @mhoye
          Found it
          https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another

          1 Reply Last reply
          0
          • pmc@mastodon.ffcentral.netP pmc@mastodon.ffcentral.net

            @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

            kayohtie@blimps.xyzK This user is from outside of this forum
            kayohtie@blimps.xyzK This user is from outside of this forum
            kayohtie@blimps.xyz
            wrote sidst redigeret af
            #16

            @pmc @mhoye @cwebber People granting tokens way too much access because it's easier to check a box for 'all' than it is to drill down and consider specifics needed, frequently.

            1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

              401matthall@mastodon.xyz4 This user is from outside of this forum
              401matthall@mastodon.xyz4 This user is from outside of this forum
              401matthall@mastodon.xyz
              wrote sidst redigeret af
              #17

              @mhoye

              FFS. 👀

              1 Reply Last reply
              0
              • mhoye@cosocial.caM mhoye@cosocial.ca

                Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                feld@friedcheese.usF This user is from outside of this forum
                feld@friedcheese.usF This user is from outside of this forum
                feld@friedcheese.us
                wrote sidst redigeret af
                #18
                @mhoye

                > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                they deserve it
                mhoye@cosocial.caM mischievoustomato@tsundere.loveM khleedril@cyberplace.socialK 3 Replies Last reply
                0
                • mhoye@cosocial.caM mhoye@cosocial.ca

                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                  tanepiper@tane.codesT This user is from outside of this forum
                  tanepiper@tane.codesT This user is from outside of this forum
                  tanepiper@tane.codes
                  wrote sidst redigeret af
                  #19

                  @mhoye postinstall was probably the worst thing added to npm - it's been there since the start with absolutely no effort to secure it or remove it

                  mhoye@cosocial.caM 1 Reply Last reply
                  0
                  • feld@friedcheese.usF feld@friedcheese.us
                    @mhoye

                    > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                    they deserve it
                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.ca
                    wrote sidst redigeret af
                    #20

                    @feld "they deserved it" is a childish, bullshit response to systemic problems.

                    1 Reply Last reply
                    0
                    • feld@friedcheese.usF This user is from outside of this forum
                      feld@friedcheese.usF This user is from outside of this forum
                      feld@friedcheese.us
                      wrote sidst redigeret af
                      #21
                      @joe @mhoye well we used to tell people not to run .exe and .scr etc files on Windows or they'd get a trojan/virus.

                      A lot of what people do these days on MacOS/Linux is pretty damn close to running untrusted code/binaries
                      sun@shitposter.worldS 1 Reply Last reply
                      0
                      • feld@friedcheese.usF feld@friedcheese.us
                        @joe @mhoye well we used to tell people not to run .exe and .scr etc files on Windows or they'd get a trojan/virus.

                        A lot of what people do these days on MacOS/Linux is pretty damn close to running untrusted code/binaries
                        sun@shitposter.worldS This user is from outside of this forum
                        sun@shitposter.worldS This user is from outside of this forum
                        sun@shitposter.world
                        wrote sidst redigeret af
                        #22
                        @feld @joe @mhoye have you actually set it up, it's not easy to get a working but reasonably convenient dev system. I've been trying for a while now
                        1 Reply Last reply
                        0
                        • tanepiper@tane.codesT tanepiper@tane.codes

                          @mhoye postinstall was probably the worst thing added to npm - it's been there since the start with absolutely no effort to secure it or remove it

                          mhoye@cosocial.caM This user is from outside of this forum
                          mhoye@cosocial.caM This user is from outside of this forum
                          mhoye@cosocial.ca
                          wrote sidst redigeret af
                          #23

                          @tanepiper It's been around in the Debian dpkg system for ages, and it's got a lot of utility in that context and definitely works system-wide. But the Debian community doesn't have the NPM "let anyone do anything whatever" ethos, and the versioning systems in that part of the world are much slower and more methodical. You pretty much need to be on Sid and updating every day to get bitten by this in that part of the ecosystem.

                          tanepiper@tane.codesT 1 Reply Last reply
                          0
                          • feld@friedcheese.usF This user is from outside of this forum
                            feld@friedcheese.usF This user is from outside of this forum
                            feld@friedcheese.us
                            wrote sidst redigeret af
                            #24
                            @joe @mhoye you can trust what you get from your OS package manager and not much more.

                            npm, pip, cargo, hex, gem, etc are the wild west
                            1 Reply Last reply
                            0
                            • mhoye@cosocial.caM mhoye@cosocial.ca

                              @tanepiper It's been around in the Debian dpkg system for ages, and it's got a lot of utility in that context and definitely works system-wide. But the Debian community doesn't have the NPM "let anyone do anything whatever" ethos, and the versioning systems in that part of the world are much slower and more methodical. You pretty much need to be on Sid and updating every day to get bitten by this in that part of the ecosystem.

                              tanepiper@tane.codesT This user is from outside of this forum
                              tanepiper@tane.codesT This user is from outside of this forum
                              tanepiper@tane.codes
                              wrote sidst redigeret af
                              #25

                              @mhoye yes, that's the parallel part to it - being responsibility enough to have that level of utility - sadly npm is a wildwest of some of the poorest software development practices out there.

                              1 Reply Last reply
                              0
                              • tiotasram@kolektiva.socialT tiotasram@kolektiva.social

                                @hennell @mhoye openclaw is effectively a vulnerability/exploit payload itself, which to AI boosters doesn't seem like one.

                                hennell@phpc.socialH This user is from outside of this forum
                                hennell@phpc.socialH This user is from outside of this forum
                                hennell@phpc.social
                                wrote sidst redigeret af
                                #26

                                @tiotasram @mhoye yeah not sure I'd want it installed, but I assume it doesn't do anything just on install, like you'd need to set-up keys or features or something? But then I wouldn't assume packages could global install so who knows anymore.

                                1 Reply Last reply
                                0
                                • mhoye@cosocial.caM mhoye@cosocial.ca

                                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                  vfig@mastodon.gamedev.placeV This user is from outside of this forum
                                  vfig@mastodon.gamedev.placeV This user is from outside of this forum
                                  vfig@mastodon.gamedev.place
                                  wrote sidst redigeret af
                                  #27

                                  @mhoye the "S" in "AI" stands for "Security"

                                  1 Reply Last reply
                                  0
                                  • mhoye@cosocial.caM mhoye@cosocial.ca

                                    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                    rick_d_card@mastodon.socialR This user is from outside of this forum
                                    rick_d_card@mastodon.socialR This user is from outside of this forum
                                    rick_d_card@mastodon.social
                                    wrote sidst redigeret af
                                    #28

                                    @mhoye Yikes!

                                    1 Reply Last reply
                                    0
                                    • mhoye@cosocial.caM mhoye@cosocial.ca

                                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                      nobody@mastodon.acm.orgN This user is from outside of this forum
                                      nobody@mastodon.acm.orgN This user is from outside of this forum
                                      nobody@mastodon.acm.org
                                      wrote sidst redigeret af
                                      #29

                                      @mhoye
                                      Gotta love ai

                                      1 Reply Last reply
                                      0
                                      • mhoye@cosocial.caM mhoye@cosocial.ca

                                        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in systems and communities entirely, foundationally built on mutual trust and trustworthiness.

                                        dalias@hachyderm.ioD This user is from outside of this forum
                                        dalias@hachyderm.ioD This user is from outside of this forum
                                        dalias@hachyderm.io
                                        wrote sidst redigeret af
                                        #30

                                        @mhoye How tf does "npm install openclaw" result in openclaw being given backdoor privileges? As opposed to just some files appearing that only do anything if you execute them.

                                        1 Reply Last reply
                                        0
                                        • feld@friedcheese.usF feld@friedcheese.us
                                          @mhoye

                                          > developers not working in an isolated environment (zone, vm, jail, etc) and letting their devtools access their whole laptop

                                          they deserve it
                                          mischievoustomato@tsundere.loveM This user is from outside of this forum
                                          mischievoustomato@tsundere.loveM This user is from outside of this forum
                                          mischievoustomato@tsundere.love
                                          wrote sidst redigeret af
                                          #31
                                          @feld @mhoye i wonder what this applies to, I've done baremetal rust dev (personal project) with cargo, but it was a thing I made from scratch.
                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper