Bad title. This isn't an agent "running amok", this is an early experiment in carrying out an Xz attack by using an agent to build trust (and hacking/impersonating a known-good contributor identity). The agent is obeying commands it was given, the exact opposite of running amok, and although the execution isn't particularly effective, it is having some success (patches have been accepted). This is deeply scary, not b…
AI agent runs amok in Fedora and elsewhere
31–40 of 275 posts
Re: AI agent runs amok in Fedora and elsewhere
#32In their suspicious message [1] claiming to have been hacked, the user and/or agent says > To help identify accounts and actions that have been directly verified by me, I will use the term “NATCIOS” to indicate anything I have personally verified. Does anyone have any idea what "NATCIOS" means here? I cannot find this term anywhere on the internet. (Honestly, that sentence is really weird. I almost wonder whether thi…
The reply to that message notes that the email doesn't read like previous emails he's sent, and the Github account mentioned was created an hour prior to the email being sent. I think it's at least somewhat feasible that it's still the LLM writing, and the acronym is just something it made up.
They won't put their foot down until the AI starts spewing hate speech, probably.
Re: AI agent runs amok in Fedora and elsewhere
#33In their suspicious message [1] claiming to have been hacked, the user and/or agent says > To help identify accounts and actions that have been directly verified by me, I will use the term “NATCIOS” to indicate anything I have personally verified. Does anyone have any idea what "NATCIOS" means here? I cannot find this term anywhere on the internet. (Honestly, that sentence is really weird. I almost wonder whether thi…
Because I'm probably not the only one thinking it, here are anagrams [0] for your Setec Astronomy needs. [0] https://wordsmith.org/anagram/anagram.cgi?anagram=NATCIOS&t=...
Re: AI agent runs amok in Fedora and elsewhere
#34We never envisioned that the actual FOSS death spiral would come from progress itself, much more so from AI...
[1] Oh what fun did we have. One of us in the Greek FOSS community actually put RMS in jail. [2] Something that I think nobody except RMS ever seriously believed in.
Re: AI agent runs amok in Fedora and elsewhere
#35In their suspicious message [1] claiming to have been hacked, the user and/or agent says > To help identify accounts and actions that have been directly verified by me, I will use the term “NATCIOS” to indicate anything I have personally verified. Does anyone have any idea what "NATCIOS" means here? I cannot find this term anywhere on the internet. (Honestly, that sentence is really weird. I almost wonder whether thi…
Re: AI agent runs amok in Fedora and elsewhere
#36Earlier quoted context omitted.
I personally find the barrier of starting new (FOSS) projects much lower now days.
Do they have value? Purpose? I vibe code shop jigs all the time but I don’t FOSS them because they rarely have value outside my context.
I open source my vibing projects because someone might find them useful. I don't shop them around, I just work in the open because I find it fun and interesting.
Re: AI agent runs amok in Fedora and elsewhere
#37Re: AI agent runs amok in Fedora and elsewhere
#38Every day the gpg web of trust looks better. If only we didn't spend the last 20 years trying as hard as possible to do anything but allow user side encryption and signing.
Re: AI agent runs amok in Fedora and elsewhere
#39Every day the gpg web of trust looks better. If only we didn't spend the last 20 years trying as hard as possible to do anything but allow user side encryption and signing.
Nothing really stopping an agent from getting a key
And how many people are both dedicated enough to go to key signing parties and stupid enough to let an agent act without supervision in the name of their real-world identity?
Re: AI agent runs amok in Fedora and elsewhere
#40looks like LLMs aren't mature enough yet to play long-game xz-style attacks without detection... Scary stuff though :( These supply chain attacks are getting really wild