Earlier quoted context omitted.
Yep this is the sort of typo error I make probably 10 times a day.
What it's funny it's that because tokenization there is a non zero chance a LLM audit may not see anything wrong here, similar to the strawberry problem.
Ghrc.io appears to be malicious
61–70 of 78 posts
Re: Ghrc.io appears to be malicious
#62One reason why you should never think or say ghcr, but always github container register, even if that is longer. You should have enough time for not getting trapped. Root cause a stupid FLA of course. For several months I thought it means Google whatever register.
Re: Ghrc.io appears to be malicious
#63Earlier quoted context omitted.
Someone near a computer that is feeling generous should buy up all the typo'd domain names and hand them over to Microsoft. Microsoft should rename the registry. This is a horrible name. I know I've typo'd it before.
Good luck with that. People over in this github-actions issue are struggling to get github's attention for a 1-line fix to stop hanging jobs forever https://github.com/actions/runner/issues/3792#issuecomment-3... That bug is incredibly dumb and obvious. There's been a PR to fix it for over a year with no attention. I bet there's not a dedicated "github domain names" team, it's probably part of some overworked platfor…
But yes a joke of a situation.
Re: Ghrc.io appears to be malicious
#64Re: Ghrc.io appears to be malicious
#65Re: Ghrc.io appears to be malicious
#66Wouldn't DNSSEC solve stuff like this?
Re: Ghrc.io appears to be malicious
#67Earlier quoted context omitted.
What it's funny it's that because tokenization there is a non zero chance a LLM audit may not see anything wrong here, similar to the strawberry problem.
Nah, cr and rc are different tokens and LLMs would have no issues telling them apart. An older model might have trouble explaining that cr and rc are similar and can thus get easily mixed up, but the characters are probably more different to the LLM than they are to us.
Re: Ghrc.io appears to be malicious
#68Re: Ghrc.io appears to be malicious
#69Earlier quoted context omitted.
Microsoft is paying top dollar for MarkMonitor, aren't they supposed to proactively register obvious typos so this kind of thing doesn't happen to their clients?
My guess is that MarkMonitor is mainly used for their brand-relevant domains (microsoft, office 365, github (main site), etc), as opposed to one that a small subset of a small subset of their users of one service will use - I would imagine that microsoft likely owns hundreds of domain names and doesn't pay MarkMonitor to monitor every single one