@davidgerard I’m doing what I can to hasten the Quornpocalypse!
paco@infosec.exchange
Indlæg
-
Coxon: oh shit don't give away how deep in I am with the rationalistsCoxon: I'm totally not a rationalist, I just hung out with them for a decade because I admire their huge swole brains and how right they are about everythingCoxon: nailed it -
Project Glasswing:@0xabad1dea Internally at work we had a shit-ton of Glasswing findings. I got 5 sev-2 tickets for Glasswing issues. All on a project we had shut down 18 months prior. Of the 5, 4 were junk. They were in code that was only a partial implementation of a new feature, and we had stopped the entire project before the feature was finished.
The fifth was really subtle and interesting. It was legit, and something I had wondered whether it was possible. I checked it out and it was definitely true and exploitable the way it described. Shame the project had been shut down for 18 months.
I ended up accepting its PRs and then marking all the code repos as deprecated just to shut the bot up. They probably call that success.
-
the rm -rf's will continue until morale improves@webhat As they say: if that first cup of coffee doesn’t wake you up in the morning, try dropping a table in production.

@neurovagrant -
the rm -rf's will continue until morale improves@astraleureka At approximately the same time (same year, probably) we had a WAF vendor some in and give a presentation on their product. We had demo access to a live version of it. We were playing with the console of the WAF itself, not some app behind the WAF.
While the vendor is speaking my colleague starts testing stuff on the product console and within a couple minutes he’s pretty sure it’s vulnerable to SQL injection. He tries the classic “or 1=1” and he gets a well-formatted security error. Huh. It detected that and stopped it. He tried “or 2=2”. Bingo. It WAS vulnerable, but they were detecting and matching on the value “or 1=1” as some kind of literal.

I dont mean to derail the thread about careless people losing data to the automated , climate-destroying intern. It just triggers memories of hand made, non-automated failures in the past.
-
New article: this time, we use Heidegger to explain why the "it's just a tool" line that often comes up in tech is so very silly:@mrsbeanbag I think the blog and the reasoning in it is really good. I’m going to use it in the future. But I also agree with you that LLMs really strain the definition of “tool”.
The same person giving the same LLM the same exact input more than once to solve the same problem more than once will get 2 different outputs (probably similar, but not at all identical). That makes it a strange “tool,” indeed.
And there’s so much cargo culting around just the right phrases to prevent this problem or that problem. People can develop expertise with a tool. But LLMs’ non-determinism limit the value of past experience with respect to future performance.
-
The bird-on-a-stick has no idea that a wily predator is hiding nearby—nearly invisible in his perfect camouflage.#catsofmastodon #caturday #mrmittensThe bird-on-a-stick has no idea that a wily predator is hiding nearby—nearly invisible in his perfect camouflage.
#catsofmastodon #caturday #mrmittens -
the rm -rf's will continue until morale improves@jrdepriest It’s a true story, but I tell it a certain way to get a reaction. It was in a UAT environment, not prod. To be fair, it was a precious UAT environment that hundreds of people count on. It was not quick to rebuild. The client was pissed. But it wasn’t deleting real users from the real web site.
-
the rm -rf's will continue until morale improves@jztusk There are tons. Calculations or delays that indicate it was processed without doing anything to data.
@neurovagrant -
the rm -rf's will continue until morale improves@neurovagrant In 2005, we had a rookie security consultant doing a penetration test for our client. To demonstrate that the client's app was vulnerable to SQL injection, he ran
drop table users;via injection.Twenty years of progress means we can make the rookie mistakes faster and with fewer employees.
-
The US has declared Autistici/Inventati, an Italian anarchist hacker (in the classic sense of the term) collective, a terrorist organization.@cwebber I agree. Someone recently circulated a list of TLDs that didn't have an ICANN connection, and it's like 15-20 country-based domains. I went and looked at dotMeow, which I supported, and they're based in Belgium. But, no, they're going to be an ICANN registered domain. Still a worthy cause, but that's a shame. So much of the Internet has been built on trusting the US. Few people built contingencies for this breach of trust.