Live data from Hacker News

Ghrc.io appears to be malicious

bmitch.net

61–70 of 78 posts

Re: Ghrc.io appears to be malicious

#61
post #30

Earlier quoted context omitted.

Yep this is the sort of typo error I make probably 10 times a day.

What it's funny it's that because tokenization there is a non zero chance a LLM audit may not see anything wrong here, similar to the strawberry problem.

Nah, cr and rc are different tokens and LLMs would have no issues telling them apart. An older model might have trouble explaining that cr and rc are similar and can thus get easily mixed up, but the characters are probably more different to the LLM than they are to us.

Re: Ghrc.io appears to be malicious

#62
post #34

One reason why you should never think or say ghcr, but always github container register, even if that is longer. You should have enough time for not getting trapped. Root cause a stupid FLA of course. For several months I thought it means Google whatever register.

One reason why you should never think or say [or write] FLA, but always Four Letter Acronym (probably?), even if that is longer.

Re: Ghrc.io appears to be malicious

#63
post #38
post #11

Earlier quoted context omitted.

Someone near a computer that is feeling generous should buy up all the typo'd domain names and hand them over to Microsoft. Microsoft should rename the registry. This is a horrible name. I know I've typo'd it before.

Good luck with that. People over in this github-actions issue are struggling to get github's attention for a 1-line fix to stop hanging jobs forever https://github.com/actions/runner/issues/3792#issuecomment-3... That bug is incredibly dumb and obvious. There's been a PR to fix it for over a year with no attention. I bet there's not a dedicated "github domain names" team, it's probably part of some overworked platfor…

Apparently fixed five days ago: https://github.com/actions/runner/pull/3157

But yes a joke of a situation.

Re: Ghrc.io appears to be malicious

#65
post #60

Earlier quoted context omitted.

It may be easier to register a new domain than to get people to make a subdomain for you.

Isn't that an official MS service for github?

Yeah, and what I'm saying is that it may be hard to get people within your org to do something for you.

Re: Ghrc.io appears to be malicious

#67
post #30

Earlier quoted context omitted.

What it's funny it's that because tokenization there is a non zero chance a LLM audit may not see anything wrong here, similar to the strawberry problem.

Nah, cr and rc are different tokens and LLMs would have no issues telling them apart. An older model might have trouble explaining that cr and rc are similar and can thus get easily mixed up, but the characters are probably more different to the LLM than they are to us.

What about all that GitHub training data using the wrong domain? Even being a different token it’s still being trained as a correct value.

Re: Ghrc.io appears to be malicious

#69
post #12

Earlier quoted context omitted.

Microsoft is paying top dollar for MarkMonitor, aren't they supposed to proactively register obvious typos so this kind of thing doesn't happen to their clients?

My guess is that MarkMonitor is mainly used for their brand-relevant domains (microsoft, office 365, github (main site), etc), as opposed to one that a small subset of a small subset of their users of one service will use - I would imagine that microsoft likely owns hundreds of domain names and doesn't pay MarkMonitor to monitor every single one

ghcr.io is registered by markmonitor.
Post reply on HN