Live data from Hacker News

Microsoft's open source tools were hacked to steal passwords of AI developers

techcrunch.com

181–190 of 211 posts

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#181
post #143
post #103

Earlier quoted context omitted.

Just to clarify, and I know you weren't saying they are related, but this has absolutely nothing to do with AI or vibe coding or manager code. It's a continuation of the Shai Halud worm and the lack of security around developer dependnecy installations, which has existed for a very long time. Hackers have figured out that developers themselves are an ideal target due to how easy it is to trick them into installing so…

> due to how easy it is to trick them into installing something You have tools from large corporations where the official installation procedure involves copy pasting a command from a random blog post, run it with sudo and watch it download and execute a script from a random filehost. This is somehow deemed acceptable by everyone involved. Meanwhile I can't use teams in our meeting rooms, since any form of internet a…

> Anyone trying to follow sane practices in this industry just asks to end up in a padded cell.

Same as it ever was.

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#182
post #45

Earlier quoted context omitted.

one could also vibe-code vanilla, no dependencies.

You can vibe code safely for sure. I am not saying vibe coding is the issue. The issue is that a typical developer might be working on a lot more projects that run concurrently then they used to. And because of the various nature of the project the risk is significantly increased. Scale this across the workforce and you not just doubled the problem.

"Practice safe vibecoding, stop the cycle of infections!"

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#183

Earlier quoted context omitted.

> Now in many places it is encouraged by coders and managers to vibe stuff on their own devices. Soon or later it will become a problem, especially for those that have no idea what they are doing. Yes in our place too. "You better do as much as possible with AI or you will be left behind" dogmas etc. It's the stupid IoT hype all over again. No concern for security, just trying to be the first in the pack.

"MongoDB is the hottest thing! No default creds, who cares about that! ONWARD TO PRODUCTION, SOLDIERS!"

MongoDB is web scale.

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#184
post #160

Earlier quoted context omitted.

You're talking about living in a world where we have to take entirely preventative steps, not reactive because hacking is going to be that much more prevalent. AI can tell you you're being zero-day'd, but that isn't much comfort - you're already expecting everyone to always be zero-day'd at all times!

What I'm suggesting is that AI and security tooling can help you minimize attack vectors.

[deleted]

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#185

Earlier quoted context omitted.

If I vibe code a project, that involves docs and tests as well. Obviously I do not, at any point, do anything blindly and there are some iterations for everything. I always double-check, and I do not use "agents", I do everything manually. I always check what the LLM is thinking, in real-time. I might be old school, but that allows me to write code that is not a pile of shit. :P I am still conscious about quality.

Anecdotal. 13 million swe roles with .01% is 130,000 compromised devices. Process problem

I think that the numerical example you gave appears to be wrong unless you intended 1% rather than 0.01%.

In any case, fair enough. The concern is that organizations will build processes around AI where many people do not review outputs carefully. I do not disagree with this.

I also agree that my particular workflow is anecdotal and does not work at scale.

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#186

Earlier quoted context omitted.

It has all happened before and it will all happen again :)

I just finished watching that series, so I can pick up these references. Nothing like being 20 years late to the party

Has it been 20 years already? Wow. Yeah it was a good one (though a little too gritty for me sometimes)

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#187
post #143
post #103

Earlier quoted context omitted.

Just to clarify, and I know you weren't saying they are related, but this has absolutely nothing to do with AI or vibe coding or manager code. It's a continuation of the Shai Halud worm and the lack of security around developer dependnecy installations, which has existed for a very long time. Hackers have figured out that developers themselves are an ideal target due to how easy it is to trick them into installing so…

> due to how easy it is to trick them into installing something You have tools from large corporations where the official installation procedure involves copy pasting a command from a random blog post, run it with sudo and watch it download and execute a script from a random filehost. This is somehow deemed acceptable by everyone involved. Meanwhile I can't use teams in our meeting rooms, since any form of internet a…

> Meanwhile I can't use teams in our meeting rooms, since any form of internet access was deemed a security risk in rooms where customer projects could be discussed. This is in a day and age where 90% of customer meetings are done over the internet.

I hope this is in jest. Are you saying in order to discuss any customer project you have to book a meeting room? So no discussions of customer projects at the open plan desks or even in your boss' office for fear that something might overhear that conversation? Or is this only when the customer happens to be on-site to discuss their project? Does your organization assign U.S. Military style NICKA code names to everything?

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#188

Earlier quoted context omitted.

I just finished watching that series, so I can pick up these references. Nothing like being 20 years late to the party

Has it been 20 years already? Wow. Yeah it was a good one (though a little too gritty for me sometimes)

Apparently I'm late to the party too! What is this from?

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#189

Earlier quoted context omitted.

It has all happened before and it will all happen again :)

I just finished watching that series, so I can pick up these references. Nothing like being 20 years late to the party

Peter Pan came out in 1953

https://www.reddit.com/r/BSG/comments/12e31w3/so_i_was_today...

Re: Microsoft's open source tools were hacked to steal passwords of AI developers

#190
I am inordinately amused by the fact that Microsoft's Github has suspended access by Microsoft's Azure (and anyone else) to their Microsoft code-base because of a TOS violation.

Really drives home this org chart: https://www.businessinsider.com/big-tech-org-charts-2011-6

Post reply on HN