Live data from Hacker News

Mercor says it was hit by cyberattack tied to compromise LiteLLM

techcrunch.com

1–10 of 62 posts

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#4
post #2

[flagged]

[flagged]

What makes you think that?

Your cab see the commit history ~10% of code is written by agents.

Rest was all written by me.

Unlike other criticisms of the project, this one feels personal as it is objectively incorrect.

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#6
post #4

Earlier quoted context omitted.

[flagged]

What makes you think that? Your cab see the commit history ~10% of code is written by agents. Rest was all written by me. Unlike other criticisms of the project, this one feels personal as it is objectively incorrect.

All these commenters just yell AI about every post and comment on here now. They have a worse hit rate than a blind marksman.

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#7
> The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications.

This is pretty funny.

The leaked excel sheet with customers of Delve is basically a shortlist of targets for hackers to try now. Not that they necessarily have bad security, but you can play the odds

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#10
post #5
post #2

[flagged]

Docker is not a strong security boundary and shouldn't be used to sandbox like this https://cloud.google.com/blog/products/gcp/exploring-contain...

Compared to what? Which one is superior?

Running npm on your dev machine? Or running npm inside Docker?

I would always prefer the latter but would love to know what your approach to security is that's better than running npm inside Docker.

Post reply on HN