the rm -rf's will continue until morale improves
-
the rm -rf's will continue until morale improves
@neurovagrant if you gave #AI the ability to rm -rf your system that's a fucking skills issue.
-
the rm -rf's will continue until morale improves
Script kiddies. They're all just script kiddies. Especially the ones who ought to know better.
-
@neurovagrant "Claude decided" you mean the random plausible-word-sequence generator generated a sequence that you stupidly gave permission to delete all ur files, hope that helps have a nice day
@joshg @neurovagrant In the case of AI agent, it might be a good idea to treat it like a separate person with its own identity, accounts and permissions.
Always relevant: https://furry.engineer/@aronowski/116486886171382391 -
@neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran
drop table users;via injection.Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.
@paco @neurovagrant wouldn't that be a criminal offense at that point as well

-
the rm -rf's will continue until morale improves
@neurovagrant Morality. I think in this case the right word to use is morality.
-
the rm -rf's will continue until morale improves
@neurovagrant It's beautiful.
-
@astraleureka At approximately the same time (same year, probably) we had a WAF vendor some in and give a presentation on their product. We had demo access to a live version of it. We were playing with the console of the WAF itself, not some app behind the WAF.
While the vendor is speaking my colleague starts testing stuff on the product console and within a couple minutes he’s pretty sure it’s vulnerable to SQL injection. He tries the classic “or 1=1” and he gets a well-formatted security error. Huh. It detected that and stopped it. He tried “or 2=2”. Bingo. It WAS vulnerable, but they were detecting and matching on the value “or 1=1” as some kind of literal.

I dont mean to derail the thread about careless people losing data to the automated , climate-destroying intern. It just triggers memories of hand made, non-automated failures in the past.
-
the rm -rf's will continue until morale improves
-
@jrdepriest @jztusk @paco @neurovagrant no, drop tables *also* let's you demonstrate the presence or absence of effective backups. It's a two for one test!
@SomeVeganCheeseIsOk @jrdepriest @jztusk @paco @neurovagrant And also the non-isolation of permissions (the SQL user the application connects with should not be able to perform DDL queries, only DQL and DML).
-
the rm -rf's will continue until morale improves
@neurovagrant good
-
the rm -rf's will continue until morale improves
@neurovagrant Just waiting for the day, when Claude deletes my employer's company wide network shares.
-
@neurovagrant apes gone
@kirakira @neurovagrant all of em
-
the rm -rf's will continue until morale improves
@neurovagrant Part of the AI folkore, as long as your company is not big enough for "my agent/model is commiting crimes now".
Both still leave me puzzled, because in a professional context, this is a clear sign not to trust those people or even do business with them. But I might not be a professional... ¯\_(ツ)_/¯
-
@joshg @neurovagrant In the case of AI agent, it might be a good idea to treat it like a separate person with its own identity, accounts and permissions.
Always relevant: https://furry.engineer/@aronowski/116486886171382391@aronowski
I vastly prefer the "don't use the stupid wasteful unethical thing" option, myself.
@neurovagrant -
@neurovagrant Part of the AI folkore, as long as your company is not big enough for "my agent/model is commiting crimes now".
Both still leave me puzzled, because in a professional context, this is a clear sign not to trust those people or even do business with them. But I might not be a professional... ¯\_(ツ)_/¯
@neurovagrant Oh, CTO midnight foundation... "dedicated to growing the Midnight network — a fourth-generation blockchain built for secure, compliant, and private decentralised applications".

-
@neurovagrant been thinking about aliasing rm -rf as “finish-him”
@patricksh @neurovagrant 100% YES
-
the rm -rf's will continue until morale improves
@neurovagrant Did he not know that rm -rf was? I honestly don't know what was supposed to do. And, if he closes most sandboxes, they tend to delete because they are temporary. I don't get it.
I don't get what this guy was trying to do and I don't think I will understand. I feel silly.
-
the rm -rf's will continue until morale improves
@neurovagrant also, people still not doing backups/restore testing, no zfs, no jails / containers / other restrictions. Kids these days.
-
@neurovagrant also, people still not doing backups/restore testing, no zfs, no jails / containers / other restrictions. Kids these days.
@dch right?
the fundamentals do not disappear regardless of the presence of spicy autocorrect
-
the rm -rf's will continue until morale improves
.