Earlier quoted context omitted.
> Do they don't have any code reviews? I have a good friend that works for one of the giants(I can't say which one for obvious reasons but S&P 500). He's been working there for quite a while now, so far he hasn't seen what the project he works on looks like, has the repo cloned and knows what language is used but nothing beyond that. Everything is slopped together. His project is the authentication and authorization…
> have a good friend that works for one of the giants(I can't say which one for obvious reasons but S&P 500). I can’t think of any obvious reason other than this being embellished / made up? Those companies have tens of thousands of employees you aren’t going to “out” anyone by naming the company.
Microsoft's open source tools were hacked to steal passwords of AI developers
191–200 of 211 posts
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#192Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#193Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#194Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#195Earlier quoted context omitted.
What if this is "The Great Filter?" [Ominous music plays in the background]
That would be when we've automated stuff to the point where [machinery breaking down] causes a large majority of humans to die from starvation. And then go on to repeat that mistake by re-building without using the lessons from previous catastrophe(s). Sadly that last part sounds fairly common for humans... 8-| So yeah. Maybe. Possible.
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#196The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…
Microsoft which owns GitHub, has been washing their hands if any responsibility in helping to resolve the ongoing supply chain catastrophe which is hosted and spread nearly entirely via Github repositories: not responding to security researchers flagging malware hosted on GitHub; doing nothing to address the proliferation of open source malware across their platform, giving no recourse for action, not applying their tremendous resources to the problem, fiddling as the open source community burns and leaving the devs to fend for themselves. Let's not mention the recent very hostile and trust-erodibg behavior towards bug bounty security researchers.
The *&$@ finally spread all the way up to the top of the hill in a compromise of Microsoft's own repos, which I think highlights the scale of the problem.
And in response, they offer a watery corporate platitude, "a few customers were affected in a recent incident, and we're looking into it."
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#197These seem related: * https://news.ycombinator.com/item?id=48418318 ( The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds ) * https://news.ycombinator.com/item?id=48450543 ( Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents ) * https://news.ycombinator.com/item?id=48416155 * https://news.ycombinator.com/item?id=4…
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#198Earlier quoted context omitted.
Anecdotal. 13 million swe roles with .01% is 130,000 compromised devices. Process problem
I think that the numerical example you gave appears to be wrong unless you intended 1% rather than 0.01%. In any case, fair enough. The concern is that organizations will build processes around AI where many people do not review outputs carefully. I do not disagree with this. I also agree that my particular workflow is anecdotal and does not work at scale.
Yes 1%
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#199The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…
That's the thing: they do bear responsibility in allowing the situation to get to this point and are very pointedly not connecting the dots with their response. Microsoft which owns GitHub, has been washing their hands if any responsibility in helping to resolve the ongoing supply chain catastrophe which is hosted and spread nearly entirely via Github repositories: not responding to security researchers flagging malw…
They did not read the source code of the worm implant and have absolutely no clue how the worm works, if that is their response.
The only way to meaningfully stop the worm is by requiring manual confirmations for git commit/push actions and for the auto-executed hooks in all IDEs. Also, these scripts should be sandboxed to only be allowed to run and interact with files inside the same opened project folder.
Well, that, or setting the host system language to Russian. Which I am kind of expecting Microsoft to do next...
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#200Earlier quoted context omitted.
I think that the numerical example you gave appears to be wrong unless you intended 1% rather than 0.01%. In any case, fair enough. The concern is that organizations will build processes around AI where many people do not review outputs carefully. I do not disagree with this. I also agree that my particular workflow is anecdotal and does not work at scale.
Yes my bad I even checked it in the calculator but then typed in .01 again but added % again. I meant to do it to serve as an example of how bad humans are at thing.... right... Yes 1%