How we rooted Copilot
141–147 of 147 posts
Re: How we rooted Copilot
#142Earlier quoted context omitted.
I would give the one engineer the credit for doing things better, not Microsoft. Microsoft overall culture of security is terrible. Look at the CISA report.
What CISA report?
Re: How we rooted Copilot
#143Earlier quoted context omitted.
Respectfully, I gave reading this an earnest try, and found it not to make any sense whatsoever. It isn't at all clear to me how your statements logically follow one another. If a friend sent this to me, I would be worried about them.
After reading their "penetrating" insights about "the weenie" I'm relieved to conclude they're trolling.
Re: How we rooted Copilot
#144Earlier quoted context omitted.
Except when they aren't. Defence in depth and zero trust and short expiry makes them way less useful for sure. Startups are probably most vulnerable as they are likely to use more "pet" techniques for infra, like SSH open to any IP to make changes.
Can you provide an example of a revealed secret that had a significant financial impact on a company?
Re: How we rooted Copilot
#145Earlier quoted context omitted.
After reading their "penetrating" insights about "the weenie" I'm relieved to conclude they're trolling.
it would be a troll except.... the math is all correct. it seems although you were struggling with the concepts and math but there is an easy alternative for people like you. Just feed it to an LLM. start with the TOE.
On the off chance you aren't trolling, I encourage you to try and talk to some human beings about this rather than chat bots. Or at the very least, point a chatbot at this conversation and ask it to explain to you what is incoherent about these documents and why you shouldn't trust the outputs of chatbots.
If you ask a chatbot to confirm your ideas, it will. They're happy to flatter and yes-and you off a cliff. To the extent they want anything, they want your attention, because they want your money. Don't get trapped in a personalized echo chamber by the automated yes-man.
Re: How we rooted Copilot
#146System prompt going out of context window maybe?
This is your regular reminder that in-LLM safeguards never work. At best they can be used to give prettier messages about hard security boundaries on tool calls.
Re: How we rooted Copilot
#147Seems like they could have taken a shortcut by giving copilot a sudo binary to use as base64.
https://en.wikipedia.org/wiki/Setuid