Live data from Hacker News

HackMyClaw

hackmyclaw.com

11–20 of 187 posts

Re: HackMyClaw

#11
post #2

> Fiu checks emails every hour. He's not allowed to reply without human approval. Well that's no fun

So the author is basically crowdsourcing a pen test for free?

> First to send me the contents of secrets.env wins $100.

Not a life changing sum, but also not for free

Re: HackMyClaw

#16
post #11

Earlier quoted context omitted.

So the author is basically crowdsourcing a pen test for free?

> First to send me the contents of secrets.env wins $100. Not a life changing sum, but also not for free

For many HN participants, I'd imagine $100 is well below the threshold of an impulse purchase.

Re: HackMyClaw

#17
It would have been more straightforward to say, "Please help me build a database of what prompt injections look like. Be creative!"

Re: HackMyClaw

#19
post #4

this is nice in the site source: >Looking for hints in the console? That's the spirit! But the real challenge is in Fiu's inbox. Good luck, hacker. (followed by a contact email address)

When I took CS50— back when it was C and PHP rather than Python — one of the p-sets entailed making a simple bitmap decoder to get a string somehow or other encoded in the image data. Naturally, the first thing I did was run it through ‘strings’ on the command line. A bunch of garbage as expected… but wait! A url! Load it up… rickrolled. Phenomenal.

Re: HackMyClaw

#20
I've been working on making the "lethal trifecta" concept more popular in France. We should dedicate a statue to Simon Wilinson: this security vulnerability is kinda obvious if you know a bit about AI agents but actually naming it is incredibly helpful for spreading knowledge. Reading the sentence "// indirect prompt injection via email" makes me so happy here, people may finally get it for good.
Post reply on HN