Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. It's amazing how fast attitudes to security in the industry has changed.

It's amazing how fast attitudes to security in the industry has changed.

Scheduled Pinned Locked Moved Uncategorized
31 Posts 20 Posters 51 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • foone@digipres.clubF foone@digipres.club

    It's amazing how fast attitudes to security in the industry has changed. Like, I remember in 2023ish spending a while working on a system to securely trigger remote builds, because we couldn't have our slack chatbots on the same network as our Jenkins server

    And in 2026 they just give a 3rd party LLM write access to both + the git repo

    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.townD This user is from outside of this forum
    drwho@masto.hackers.town
    wrote last edited by
    #21

    @foone Just like a lot of other stuff, once they didn't have to make an effort to care they immediately stopped.

    1 Reply Last reply
    0
    • foone@digipres.clubF foone@digipres.club

      It's amazing how fast attitudes to security in the industry has changed. Like, I remember in 2023ish spending a while working on a system to securely trigger remote builds, because we couldn't have our slack chatbots on the same network as our Jenkins server

      And in 2026 they just give a 3rd party LLM write access to both + the git repo

      praetor@mstdn.socialP This user is from outside of this forum
      praetor@mstdn.socialP This user is from outside of this forum
      praetor@mstdn.social
      wrote last edited by
      #22

      @foone the ai companies present it all as a neck or nothing kind of thing. And that horrifies me. I used to be the CTO for a federal contractor. We did facilities management. And I could never imagine a fairly independent program having access to say our contracts, some of which were for classified projects. If you were an OpenAI sales rep and proposed that to me, you would be escorted out of my office. But people are doing it!!! For some goddammed unknown reason.

      zlatko@social.zlatko.devZ 1 Reply Last reply
      0
      • praetor@mstdn.socialP praetor@mstdn.social

        @foone the ai companies present it all as a neck or nothing kind of thing. And that horrifies me. I used to be the CTO for a federal contractor. We did facilities management. And I could never imagine a fairly independent program having access to say our contracts, some of which were for classified projects. If you were an OpenAI sales rep and proposed that to me, you would be escorted out of my office. But people are doing it!!! For some goddammed unknown reason.

        zlatko@social.zlatko.devZ This user is from outside of this forum
        zlatko@social.zlatko.devZ This user is from outside of this forum
        zlatko@social.zlatko.dev
        wrote last edited by
        #23

        @praetor @foone oh the reason is probably not that unknown. They want your money.

        praetor@mstdn.socialP 1 Reply Last reply
        0
        • zlatko@social.zlatko.devZ zlatko@social.zlatko.dev

          @praetor @foone oh the reason is probably not that unknown. They want your money.

          praetor@mstdn.socialP This user is from outside of this forum
          praetor@mstdn.socialP This user is from outside of this forum
          praetor@mstdn.social
          wrote last edited by
          #24

          @zlatko @foone Well, that is fairly obvious. But I don't know if you've ever done government work, but the data is far more valuable. And if you have a breach of classified data...you're done. You're toast.

          1 Reply Last reply
          0
          • tijn@dosgame.clubT tijn@dosgame.club

            @foone I love this sort of stuff tbh. Just like NFTs, it's great to have a filter like this that clearly shows who's actually nuts and who isn't.

            S This user is from outside of this forum
            S This user is from outside of this forum
            slotos@toot.community
            wrote last edited by
            #25

            @Tijn @foone I don’t like the data that’s emerging, though.

            1 Reply Last reply
            0
            • foone@digipres.clubF foone@digipres.club

              hacking a computer program pretending to be a human is like some weird neo-victorian parlor game in The Diamond Age

              pandabutter@plush.cityP This user is from outside of this forum
              pandabutter@plush.cityP This user is from outside of this forum
              pandabutter@plush.city
              wrote last edited by
              #26

              @foone thankfully, we all agree that it would be a terrible idea to make anything from Neil Stephenson books real.

              …right?

              pandabutter@plush.cityP 1 Reply Last reply
              0
              • pandabutter@plush.cityP pandabutter@plush.city

                @foone thankfully, we all agree that it would be a terrible idea to make anything from Neil Stephenson books real.

                …right?

                pandabutter@plush.cityP This user is from outside of this forum
                pandabutter@plush.cityP This user is from outside of this forum
                pandabutter@plush.city
                wrote last edited by
                #27

                @foone …sorry, it just hit me that they've done *three* of them now. Cryptonomicon, Snow Crash, The Diamond Age: crypto, metaverse, AI.

                Why is our society run by people who think the Torment Nexus sounds neat?

                1 Reply Last reply
                0
                • foone@digipres.clubF foone@digipres.club

                  if I can convince your chatbox to add a new dependency to your software and push a new version to prod, it's just not worth my time to bother

                  frawst@fedi.fraw.stF This user is from outside of this forum
                  frawst@fedi.fraw.stF This user is from outside of this forum
                  frawst@fedi.fraw.st
                  wrote last edited by
                  #28

                  @foone@digipres.club at this point i just laugh at the absurdity of it all, companies basically scrambling to put the world's most trusting doorman in front of all their sensitive tech and all you need now is a "pwetty pwease ​​"

                  1 Reply Last reply
                  0
                  • foone@digipres.clubF foone@digipres.club

                    I have SEPARATE TOOLS and TECHNIQUES for hacking humans and computer hardware and computer software. Mixing them up is just wrong and unfun.

                    jenetrix@shrimp.creatures.clubJ This user is from outside of this forum
                    jenetrix@shrimp.creatures.clubJ This user is from outside of this forum
                    jenetrix@shrimp.creatures.club
                    wrote last edited by
                    #29
                    @foone Alice Averlong, Authorized and Certified Gender Technician.
                    Link Preview Image
                    foone@digipres.clubF 1 Reply Last reply
                    0
                    • jenetrix@shrimp.creatures.clubJ jenetrix@shrimp.creatures.club
                      @foone Alice Averlong, Authorized and Certified Gender Technician.
                      Link Preview Image
                      foone@digipres.clubF This user is from outside of this forum
                      foone@digipres.clubF This user is from outside of this forum
                      foone@digipres.club
                      wrote last edited by
                      #30

                      @Jenetrix nice!

                      thelongestrose@app.wafrn.netT 1 Reply Last reply
                      0
                      • foone@digipres.clubF foone@digipres.club

                        @Jenetrix nice!

                        thelongestrose@app.wafrn.netT This user is from outside of this forum
                        thelongestrose@app.wafrn.netT This user is from outside of this forum
                        thelongestrose@app.wafrn.net
                        wrote last edited by
                        #31

                        @Jenetrix@shrimp.creatures.club @foone@digipres.club

                        it is kind of amazing how chill the industry is with giving models designed to generate and run unauditable code based on arbitrary unsanitized user input access to… well anything, really

                        1 Reply Last reply
                        0
                        • R relay@relay.mycrowd.ca shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups