Live data from Hacker News

Just the rumour of a bug is enough to find an exploit these days

anil.recoil.org

131–140 of 141 posts

Re: Just the rumour of a bug is enough to find an exploit these days

#132
post #86

Earlier quoted context omitted.

I came across rclone at work because "Copy or move data to Azure Storage by using AzCopy v10" is a lie, it literally can't `move` files, only `copy` them. I can't express in polite words how pathetic it is to see the only official blob storage bulk transfer CLI tool from a multi-trillion-dollar company fail to do the simplest, most essential functionality after ten major revisions. Meanwhile, rclone Just Works(tm). T…

Do not try and move the files; that's impossible. Instead, only try to realize the truth... Delete them after you copy.

> Delete them after you copy.

Why is the word “you” in there, as-if that is inherently manual labour for me to carry out?

I know! Move is two operations under the hood.

Rclone automates this trivial two step action.

Azcopy does not.

Re: Just the rumour of a bug is enough to find an exploit these days

#134
post #125

Earlier quoted context omitted.

> It is not "will" it always is money. Bullshit. There are so many ways to make money. And let's be honest, are the levels of wealth these people have money is entirely meaningless. There is nothing Elon can obtain, through money, that Alex Karp can't. That is despite more than an order of magnitude difference in wealth. So it isn't money. You can argue that it is power, that the money is the proxy, but this still wo…

At some point money stops being about what you can buy and turns to a competition. You become addicted to the feeling of getting ahead of your rivals on the Forbes list, watching your companies stock price tick up after a good quarter, coming up with megalomaniac plans and then feeling happy when you can finally afford them even if you never actually wanted to pull them off. Being a billionaire is a conscious decisio…

I buy that but it still leaves many questions. The goal is ultimately arbitrary, is it not?

Why not seek fame instead? Philanthropy? World records? Knowledge? Innovation? Adventure? Or many other things? Money makes all these things easier to achieve. These are less hated by the public. Using capital to seek these pursuits does not risk them losing their heads as the populous revolts. Power can still be had through many of these pursuits. To do the things they claim their companies do...

I don't think you're wrong, but it is far from a complete answer and that's why I ask

Re: Just the rumour of a bug is enough to find an exploit these days

#135
post #125

Earlier quoted context omitted.

At some point money stops being about what you can buy and turns to a competition. You become addicted to the feeling of getting ahead of your rivals on the Forbes list, watching your companies stock price tick up after a good quarter, coming up with megalomaniac plans and then feeling happy when you can finally afford them even if you never actually wanted to pull them off. Being a billionaire is a conscious decisio…

I buy that but it still leaves many questions. The goal is ultimately arbitrary, is it not? Why not seek fame instead? Philanthropy? World records? Knowledge? Innovation? Adventure? Or many other things? Money makes all these things easier to achieve. These are less hated by the public. Using capital to seek these pursuits does not risk them losing their heads as the populous revolts. Power can still be had through m…

Some do. They aren't the ones with the most money.

Re: Just the rumour of a bug is enough to find an exploit these days

#136
post #4

I don't think this is new with LLMs (finding an exploit based on a few words offhand has always been a fun part of exploit development), but it's scaled and democratized to mass exploitation of low value targets. Backing exploit PoCs out of patches, commit messages, and random overheard or over-read sentences is a practice as old as vulnerability research. The difference with LLMs is that an explosion in actors "skil…

> [...] enabled sloppy / low-skill "exploit the whole Internet" actors [...]

Is there a modern equivalent for AI enabled script kiddies?

slop kiddies?

Re: Just the rumour of a bug is enough to find an exploit these days

#137
post #3

This describes my life as an open source maintainer at the moment! In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month! That has taken a huge amount of my time, even using AI tools to triage and come up with fixes for review. The hit rate for those security disclosures is pretty good - about 75% of them have a nugget of so…

> GitHub assigns CVEs for the advisories. Before the AI apocalypse they took 2-3 days for an assignment but now it they are running at 3-4 weeks so I have to send the point releases out with CVE-PENDING in the changelog which isn't ideal. A strange bottleneck; anyone know why that would be so slow?

https://github.blog/security/supply-chain-security/inside-th... goes into it more

As mentioned by another commenter, they intentionally have a human reviewer in the process before a GitHub Security Advisory (GHSA) becomes "official" post-publish

(this is separate to getting CVE ID assigned, if wanted)

Re: Just the rumour of a bug is enough to find an exploit these days

#138
post #3

This describes my life as an open source maintainer at the moment! In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month! That has taken a huge amount of my time, even using AI tools to triage and come up with fixes for review. The hit rate for those security disclosures is pretty good - about 75% of them have a nugget of so…

If it helps, in the Renovate project we don't usually request a full CVE ID, but use the GitHub Security Advisory (GHSA) ID

You can use those numbers in changelogs as soon as they're published

There is some human review, which takes time, before the GHSA is "GitHub-reviewed" which then allows security scanners to pick it up

Then, the CVE ID can be assigned to it after-the-fact if need be, but the GHSA should be a sufficient starting point

Re: Just the rumour of a bug is enough to find an exploit these days

#139

Earlier quoted context omitted.

I buy that but it still leaves many questions. The goal is ultimately arbitrary, is it not? Why not seek fame instead? Philanthropy? World records? Knowledge? Innovation? Adventure? Or many other things? Money makes all these things easier to achieve. These are less hated by the public. Using capital to seek these pursuits does not risk them losing their heads as the populous revolts. Power can still be had through m…

Some do. They aren't the ones with the most money.

Yet our society praises the money people more.

So I'm not just going to accept selection bias as the answer because while that explains why some people have an addition it doesn't explain why society is fixated on those chasing the arbitrary high score.

Re: Just the rumour of a bug is enough to find an exploit these days

#140

Earlier quoted context omitted.

I disagree, a bit. There should always be some contention between manager and developer. It's healthy. But I think many developers just remain silent and are afraid to speak up. They are afraid of losing their jobs, or worse, getting kicked out of the country. It's reasonable, but it is one of many factors that contribute to the negative feedback loop of myopic management. We've all seen developers who game the syste…

>They get rewarded because they appear to move fast, eventually become management, and the whole thing gets worse as time goes on. We've got a winner. Devs respond to the incentives set by management, and the message I have received loud and clear, my entire career, despite protestation, is that I should ship faster and not worry about bugs so much, big or small. That I take pride in what I do is the only reason moti…

  > Devs respond to the incentives set by management
But I still hate these types of explanations. We are not mindless automata.

  > That I take pride in what I do
And I'm glad you do. I'm glad you don't reduce yourself to a mindless automata. I'm glad you set your own objective functions. I'm glad you see beyond the literal metric and the to the intent.

I just hope that more can. That they don't shirk off the part they play, just because it is small. The world is made by all of us, not just those "above" us.

Post reply on HN