Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. A design flaw in the MCP protocol.

A design flaw in the MCP protocol.

Scheduled Pinned Locked Moved Uncategorized
mcpvulnerability
5 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • sempf@infosec.exchangeS This user is from outside of this forum
    sempf@infosec.exchangeS This user is from outside of this forum
    sempf@infosec.exchange
    wrote last edited by
    #1

    A design flaw in the MCP protocol. Whoda thunk. Honestly even back when they were first discussing MCP in 2024 I worried about that. Supply chain is enough of a mess, now this?

    Just a moment...

    favicon

    (www.securityweek.com)

    #mcp #vulnerability

    joriki@infosec.exchangeJ dmikusa@fosstodon.orgD 2 Replies Last reply
    1
    0
    • R relay@relay.an.exchange shared this topic
    • sempf@infosec.exchangeS sempf@infosec.exchange

      A design flaw in the MCP protocol. Whoda thunk. Honestly even back when they were first discussing MCP in 2024 I worried about that. Supply chain is enough of a mess, now this?

      Just a moment...

      favicon

      (www.securityweek.com)

      #mcp #vulnerability

      joriki@infosec.exchangeJ This user is from outside of this forum
      joriki@infosec.exchangeJ This user is from outside of this forum
      joriki@infosec.exchange
      wrote last edited by
      #2

      @Sempf

      I don't always lol lmfao, but when I do it's usually about cryptocurrency and AI

      sempf@infosec.exchangeS 1 Reply Last reply
      0
      • joriki@infosec.exchangeJ joriki@infosec.exchange

        @Sempf

        I don't always lol lmfao, but when I do it's usually about cryptocurrency and AI

        sempf@infosec.exchangeS This user is from outside of this forum
        sempf@infosec.exchangeS This user is from outside of this forum
        sempf@infosec.exchange
        wrote last edited by
        #3

        @joriki The Most Battle Weary Man in the World. "I don't ever drink beer. Scotch. Double. Neat."

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        • sempf@infosec.exchangeS sempf@infosec.exchange

          A design flaw in the MCP protocol. Whoda thunk. Honestly even back when they were first discussing MCP in 2024 I worried about that. Supply chain is enough of a mess, now this?

          Just a moment...

          favicon

          (www.securityweek.com)

          #mcp #vulnerability

          dmikusa@fosstodon.orgD This user is from outside of this forum
          dmikusa@fosstodon.orgD This user is from outside of this forum
          dmikusa@fosstodon.org
          wrote last edited by
          #4

          @Sempf I read that article and it’s got a lot of claims but is lacking in detail, have you seen anything more specific? Wondering if this is something new? Local MCP has always been a mine field, because you’re downloading unsandboxed code and running it on your machine. It’s the exact same problem as most package managers or download installer.exe and double click. It’s all rolling the dice. 🎲🎲

          sempf@infosec.exchangeS 1 Reply Last reply
          0
          • dmikusa@fosstodon.orgD dmikusa@fosstodon.org

            @Sempf I read that article and it’s got a lot of claims but is lacking in detail, have you seen anything more specific? Wondering if this is something new? Local MCP has always been a mine field, because you’re downloading unsandboxed code and running it on your machine. It’s the exact same problem as most package managers or download installer.exe and double click. It’s all rolling the dice. 🎲🎲

            sempf@infosec.exchangeS This user is from outside of this forum
            sempf@infosec.exchangeS This user is from outside of this forum
            sempf@infosec.exchange
            wrote last edited by
            #5

            @dmikusa No, it's nothing new. Once I actually got all the way down to the white paper, I discovered that there really isn't much to this at all, other than: hey, if you have an agent unprotected on your local machine, it can do bad things. That is an important message and should be gotten out there however it gets out there, but certainly not worth all the AI-generated hype and process of the original article.

            1 Reply Last reply
            1
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups