Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. the rm -rf's will continue until morale improves

the rm -rf's will continue until morale improves

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
123 Indlæg 85 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • quinn@social.circl.luQ quinn@social.circl.lu

    @drwho @Viss @neurovagrant he probably makes more in a month than i will ever make

    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.town
    wrote sidst redigeret af
    #97

    @quinn @Viss @neurovagrant Same.

    1 Reply Last reply
    0
    • paco@infosec.exchangeP paco@infosec.exchange

      @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

      Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

      me@mastodon.seahousen.euM This user is from outside of this forum
      me@mastodon.seahousen.euM This user is from outside of this forum
      me@mastodon.seahousen.eu
      wrote sidst redigeret af
      #98

      @paco @neurovagrant imho, if LLMs are what make developers finally care about cybersecurity, that's the first thing about them one might consider 'good'

      1 Reply Last reply
      0
      • drwho@masto.hackers.townD drwho@masto.hackers.town

        @rail @paco @neurovagrant Depends on how aggro the client wants to be.

        benaveling@infosec.exchangeB This user is from outside of this forum
        benaveling@infosec.exchangeB This user is from outside of this forum
        benaveling@infosec.exchange
        wrote sidst redigeret af
        #99

        Also depends on how well written your contact with the client is.

        @drwho @rail @paco @neurovagrant

        1 Reply Last reply
        0
        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

          the rm -rf's will continue until morale improves

          catboycody@tech.lgbtC This user is from outside of this forum
          catboycody@tech.lgbtC This user is from outside of this forum
          catboycody@tech.lgbt
          wrote sidst redigeret af
          #100

          @neurovagrant I'm pushed to use claude at work... Three possible takeaways from this:

          1. Don't use auto mode and review the commands.
          2. Sandbox claude so that the fallout of such an oppsie is more limited.
          3. Do nothing and have a claude-free afternoon while I restore my profile.

          1 Reply Last reply
          0
          • jrdepriest@infosec.exchangeJ jrdepriest@infosec.exchange

            @jztusk @paco @neurovagrant

            A simple select * from users would've been fine just to prove the point.

            jackeric@beige.partyJ This user is from outside of this forum
            jackeric@beige.partyJ This user is from outside of this forum
            jackeric@beige.party
            wrote sidst redigeret af
            #101

            @jrdepriest @jztusk @paco @neurovagrant that shows access but not, whatsit, that the injected query has `drop table` privileges, I forget the term for it

            1 Reply Last reply
            0
            • computernut43@nexto.myC computernut43@nexto.my

              @neurovagrant thats why dev machines are VM's for me and before I start to "dev" you make a backup. I think its time we teach about backups now.

              epic_null@infosec.exchangeE This user is from outside of this forum
              epic_null@infosec.exchangeE This user is from outside of this forum
              epic_null@infosec.exchange
              wrote sidst redigeret af
              #102

              @computernut43 @neurovagrant You mean one of the things that AI has just made unreasonably expensive?

              computernut43@nexto.myC 1 Reply Last reply
              0
              • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                the rm -rf's will continue until morale improves

                crowbriarhexe@tech.lgbtC This user is from outside of this forum
                crowbriarhexe@tech.lgbtC This user is from outside of this forum
                crowbriarhexe@tech.lgbt
                wrote sidst redigeret af
                #103

                @neurovagrant still waiting for the bad news

                1 Reply Last reply
                0
                • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                  @paco oh no

                  webhat@infosec.exchangeW This user is from outside of this forum
                  webhat@infosec.exchangeW This user is from outside of this forum
                  webhat@infosec.exchange
                  wrote sidst redigeret af
                  #104

                  @neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production

                  davep@infosec.exchangeD paco@infosec.exchangeP 2 Replies Last reply
                  0
                  • webhat@infosec.exchangeW webhat@infosec.exchange

                    @neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production

                    davep@infosec.exchangeD This user is from outside of this forum
                    davep@infosec.exchangeD This user is from outside of this forum
                    davep@infosec.exchange
                    wrote sidst redigeret af
                    #105

                    @webhat @neurovagrant @paco

                    I once took out Nespresso's factory by DoSing its firewall until it fell over. On a Friday at 5pm. With no one on call. Oops.

                    davep@infosec.exchangeD 1 Reply Last reply
                    0
                    • davep@infosec.exchangeD davep@infosec.exchange

                      @webhat @neurovagrant @paco

                      I once took out Nespresso's factory by DoSing its firewall until it fell over. On a Friday at 5pm. With no one on call. Oops.

                      davep@infosec.exchangeD This user is from outside of this forum
                      davep@infosec.exchangeD This user is from outside of this forum
                      davep@infosec.exchange
                      wrote sidst redigeret af
                      #106

                      @webhat @neurovagrant @paco
                      They lost a couple of tons of roasting beans...

                      To be fair, it was my boss's fault for not allowing me to sniff the network with the systems at rest.

                      davep@infosec.exchangeD 1 Reply Last reply
                      0
                      • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                        @neurovagrant I realize that formal verification is a real pain; but I can't help but get the strong impression that software's experiments with downright belligerent levels of dumb empiricism might be going badly.

                        It's like watching civil engineers overcome with excitement at the velocities achievable under "hold my beer" standards and practices.

                        ireneista@adhd.irenes.spaceI This user is from outside of this forum
                        ireneista@adhd.irenes.spaceI This user is from outside of this forum
                        ireneista@adhd.irenes.space
                        wrote sidst redigeret af
                        #107

                        @fuzzyfuzzyfungus @neurovagrant for whatever it is worth this is our belief as well

                        1 Reply Last reply
                        0
                        • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                          the rm -rf's will continue until morale improves

                          njsg@mementomori.socialN This user is from outside of this forum
                          njsg@mementomori.socialN This user is from outside of this forum
                          njsg@mementomori.social
                          wrote sidst redigeret af
                          #108

                          @neurovagrant In case this hasn't been linked yet in this thread, relevant @davidrevoy comic:
                          https://framapiaf.org/@davidrevoy/116211515986568390

                          1 Reply Last reply
                          0
                          • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                            the rm -rf's will continue until morale improves

                            magnetic_tape@infosec.exchangeM This user is from outside of this forum
                            magnetic_tape@infosec.exchangeM This user is from outside of this forum
                            magnetic_tape@infosec.exchange
                            wrote sidst redigeret af
                            #109

                            @neurovagrant

                            1 Reply Last reply
                            0
                            • benaveling@infosec.exchangeB benaveling@infosec.exchange

                              If you ask a human to explain an action, they think back to what they were thinking at the time. LLMs don't do that, because LLM's don't think.

                              GenAI engines are chatbots. They generate text. They match your prompt against some subset of the billions of rules they have and the combination of rules that trigger most strongly determines the response, one word at a time.

                              The only honest explanation for “why this behaviour and not that behaviour” would be “these rules triggered more strongly than those rules”.

                              @bartholin @neurovagrant

                              tessarakt@mastodon.socialT This user is from outside of this forum
                              tessarakt@mastodon.socialT This user is from outside of this forum
                              tessarakt@mastodon.social
                              wrote sidst redigeret af
                              #110

                              @BenAveling @bartholin @neurovagrant "I was about to switch off the stove, but then the doorbell rang and I forgot."

                              1 Reply Last reply
                              0
                              • davep@infosec.exchangeD davep@infosec.exchange

                                @webhat @neurovagrant @paco
                                They lost a couple of tons of roasting beans...

                                To be fair, it was my boss's fault for not allowing me to sniff the network with the systems at rest.

                                davep@infosec.exchangeD This user is from outside of this forum
                                davep@infosec.exchangeD This user is from outside of this forum
                                davep@infosec.exchange
                                wrote sidst redigeret af
                                #111

                                @webhat @neurovagrant @paco

                                In a meeting with all the bigwigs at a foreign top secret missile manufacturing HQ while I was troubleshooting a problem there I mentioned that I had sniffed their network. One of the network engineers stood up and shouted "Arrest that man!". I replied "If you like, but I found your problem". They invited me back another time for another issue they were having.

                                The lesson here, kids, is don't ask for permission first.

                                1 Reply Last reply
                                0
                                • neurovagrant@masto.deoan.orgN neurovagrant@masto.deoan.org

                                  the rm -rf's will continue until morale improves

                                  isagalaev@mastodon.socialI This user is from outside of this forum
                                  isagalaev@mastodon.socialI This user is from outside of this forum
                                  isagalaev@mastodon.social
                                  wrote sidst redigeret af
                                  #112

                                  @neurovagrant I wonder if there's a correlation between this happening to people who also don't have backups.

                                  1 Reply Last reply
                                  0
                                  • webhat@infosec.exchangeW webhat@infosec.exchange

                                    @neurovagrant @paco I don't think you can get your sysadmin certification without showing the scars where you dropped tables in production

                                    paco@infosec.exchangeP This user is from outside of this forum
                                    paco@infosec.exchangeP This user is from outside of this forum
                                    paco@infosec.exchange
                                    wrote sidst redigeret af
                                    #113

                                    @webhat As they say: if that first cup of coffee doesn’t wake you up in the morning, try dropping a table in production. 😜
                                    @neurovagrant

                                    1 Reply Last reply
                                    0
                                    • viss@mastodon.socialV viss@mastodon.social

                                      @quinn @neurovagrant someone rm'ing themselves because they gave claude too much access, who self-identifies as a cto, strikes me as one of those "php ceo" types, who does a lot of talking but never really produces stuff or makes anything interesting or worthwhile.

                                      richlv@mastodon.socialR This user is from outside of this forum
                                      richlv@mastodon.socialR This user is from outside of this forum
                                      richlv@mastodon.social
                                      wrote sidst redigeret af
                                      #114

                                      @Viss @quinn @neurovagrant Oh, they produce a lot now. So much. Productive bigly. Lots for others to review.

                                      1 Reply Last reply
                                      0
                                      • epic_null@infosec.exchangeE epic_null@infosec.exchange

                                        @computernut43 @neurovagrant You mean one of the things that AI has just made unreasonably expensive?

                                        computernut43@nexto.myC This user is from outside of this forum
                                        computernut43@nexto.myC This user is from outside of this forum
                                        computernut43@nexto.my
                                        wrote sidst redigeret af
                                        #115

                                        @Epic_Null @neurovagrant yes

                                        1 Reply Last reply
                                        0
                                        • paco@infosec.exchangeP paco@infosec.exchange

                                          @neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran drop table users; via injection.

                                          Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.

                                          feld@friedcheese.usF This user is from outside of this forum
                                          feld@friedcheese.usF This user is from outside of this forum
                                          feld@friedcheese.us
                                          wrote sidst redigeret af
                                          #116
                                          @paco @neurovagrant well yeah I'd at least expect the LLM to do it right:

                                          DROP TABLE users CASCADE;
                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper