Live data from Hacker News

Microsoft's open source tools were hacked to steal passwords of AI developers

techcrunch.com

21–30 of 211 posts

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#21
post #19
post #8

guys. what the fuck. are we even doing.

We are ever-faster approaching the Anti Singularity, the moment when everything "tech" implodes and progress screeches to a halt.

What if this is "The Great Filter?" [Ominous music plays in the background]

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#22
post #18

The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…

What's your post mortem, then? As in - what happened and how should it be read?

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#23
post #16

And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.

a friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#24
post #18

The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…

TechCrunch is very sloppy and unreliable. I’ve seen them reporting on things I worked on where they just invented facts for SEO purpose and there is no way to get them to correct

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#26
> steal passwords of AI developers

What does this even mean?

The malware specifically steals passwords from developers who use AI? From those who develop AI tool? Or it steals API tokens, which serve a similar function as passwords do for humans?

Is this what journalism looks like today? Just slap the two holy letters on the title and you get views?

(Yes, I read the article. No, I still don't think the title makes sense. You can skip this techchurch slop and read the real information here: https://opensourcemalware.com/blog/miasma-reaches-azure)

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#27
post #17

I hate to be the "I told you" guy but... I told you and have been for years. And every time I do, a flock of sloppers come to say "but have you tried the claude sloppus, it's so good man, I haven't written any code in X months". Well.. Enjoy.

[dead]

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#28
post #18

The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…

What's your post mortem, then? As in - what happened and how should it be read?

Microsoft's open source projects the target of a supply chain attack and they decided to restrict access to understand and limit exposure ? Something a little more 'true' and less targetted?

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#29
post #23
post #16

And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.

a friend of mine has a very different solution: he codes everything by hand. he says that the time you need to research to include a new package you can actually use to code the piece you need. and he for sure doesn't have the problems of transitive dependencies

I assume that means he genAIs all his deps? Rather than writing by hand

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#30

And we trust these people with the root CA cert in our Secure Boot?

More like "forced to accept" rather than "trust".

This latest event just continues Microsoft's track record of being a security problem rather than having their shit together. :(

Post reply on HN