Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. lol oh my god i feel **so fucking smug** right now, it's incredible.

lol oh my god i feel **so fucking smug** right now, it's incredible.

Scheduled Pinned Locked Moved Uncategorized
39 Posts 17 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tael@yiff.lifeT tael@yiff.life

    @peter The crypto wallet checker in this compromise really underlines the fact that there's so much overlap between LLM boosters and crypto boosters. It's all the same marks. They just found something easier to sell to people.

    peter@thepit.socialP This user is from outside of this forum
    peter@thepit.socialP This user is from outside of this forum
    peter@thepit.social
    wrote last edited by
    #24

    @tael i think also, banks and payment processors have made it so much more difficult to steal and do anything with credit card numbers that there's not much point in going after those anymore, especially when finding someone's crypto passphrase is like picking up money off the ground.

    tael@yiff.lifeT 1 Reply Last reply
    0
    • peter@thepit.socialP peter@thepit.social

      RE: https://mstdn.social/@hkrn/116284264915152671

      lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

      spinnyspinlock@infosec.exchangeS This user is from outside of this forum
      spinnyspinlock@infosec.exchangeS This user is from outside of this forum
      spinnyspinlock@infosec.exchange
      wrote last edited by
      #25

      @peter oh my a day ending in -y

      1 Reply Last reply
      0
      • peter@thepit.socialP peter@thepit.social

        let's see, who can i tag about this... @davidgerard will definitely want to know. @tante maybe. idk, tag your favorite cyber-security person. this might be the mother of all LLM supply chain attacks lol. @briankrebs

        davidgerard@circumstances.runD This user is from outside of this forum
        davidgerard@circumstances.runD This user is from outside of this forum
        davidgerard@circumstances.run
        wrote last edited by
        #26

        @peter @tante @briankrebs thank you for this comedy gold

        davidgerard@circumstances.runD dogiedog64@app.wafrn.netD 2 Replies Last reply
        0
        • peter@thepit.socialP peter@thepit.social

          @tael i think also, banks and payment processors have made it so much more difficult to steal and do anything with credit card numbers that there's not much point in going after those anymore, especially when finding someone's crypto passphrase is like picking up money off the ground.

          tael@yiff.lifeT This user is from outside of this forum
          tael@yiff.lifeT This user is from outside of this forum
          tael@yiff.life
          wrote last edited by
          #27

          @peter It's easy to siphon crypto, yeah, but turning that into spendable money has gotten much, much more difficult than it used to be.

          1 Reply Last reply
          0
          • peter@thepit.socialP peter@thepit.social

            oh my fucking god.

            Link Preview Image
            nan@mastodon.greenN This user is from outside of this forum
            nan@mastodon.greenN This user is from outside of this forum
            nan@mastodon.green
            wrote last edited by
            #28

            @peter is wrapping a vibe coded mess into a package so it looks reasonable the new sub-prime mortgage?

            prietschka@mastodon.socialP 1 Reply Last reply
            0
            • davidgerard@circumstances.runD davidgerard@circumstances.run

              @peter @tante @briankrebs thank you for this comedy gold

              davidgerard@circumstances.runD This user is from outside of this forum
              davidgerard@circumstances.runD This user is from outside of this forum
              davidgerard@circumstances.run
              wrote last edited by
              #29

              @peter @tante @briankrebs we've replaced Jia Tan with a very small prompt

              1 Reply Last reply
              0
              • peter@thepit.socialP peter@thepit.social

                there are **tons** of AI-related projects that use LiteLLM. it is a key part of the basic infrastructure of LLM-based development. if you use an LLM-based project, there is a good chance it uses LiteLLM.

                alessandro@cosocial.caA This user is from outside of this forum
                alessandro@cosocial.caA This user is from outside of this forum
                alessandro@cosocial.ca
                wrote last edited by
                #30

                @peter

                That xkcd comic with the stacked blocks, but instead of one guy in Nebraska, it's LLM slop.

                1 Reply Last reply
                0
                • davidgerard@circumstances.runD davidgerard@circumstances.run

                  @peter @tante @briankrebs thank you for this comedy gold

                  dogiedog64@app.wafrn.netD This user is from outside of this forum
                  dogiedog64@app.wafrn.netD This user is from outside of this forum
                  dogiedog64@app.wafrn.net
                  wrote last edited by
                  #31

                  @tante@tldr.nettime.org @davidgerard@circumstances.run @briankrebs@infosec.exchange @prietschka@mastodon.social @peter@thepit.social

                  @prietschka You're gonna get a laugh out of this one, methinks.

                  davidgerard@circumstances.runD 1 Reply Last reply
                  0
                  • dogiedog64@app.wafrn.netD dogiedog64@app.wafrn.net

                    @tante@tldr.nettime.org @davidgerard@circumstances.run @briankrebs@infosec.exchange @prietschka@mastodon.social @peter@thepit.social

                    @prietschka You're gonna get a laugh out of this one, methinks.

                    davidgerard@circumstances.runD This user is from outside of this forum
                    davidgerard@circumstances.runD This user is from outside of this forum
                    davidgerard@circumstances.run
                    wrote last edited by
                    #32

                    @dogiedog64 @tante @briankrebs @prietschka @peter lol god yes he will

                    1 Reply Last reply
                    0
                    • peter@thepit.socialP peter@thepit.social

                      RE: https://mstdn.social/@hkrn/116284264915152671

                      lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

                      slab_bulkhead@mastodon.onlineS This user is from outside of this forum
                      slab_bulkhead@mastodon.onlineS This user is from outside of this forum
                      slab_bulkhead@mastodon.online
                      wrote last edited by
                      #33

                      @peter Semi-related: anyone know why that issue had hundreds of bot replies like "this worked for me"? Is that reputation farming or an active strategy to bury important information in slop?

                      peter@thepit.socialP 1 Reply Last reply
                      0
                      • peter@thepit.socialP peter@thepit.social

                        plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729

                        looks grim!!

                        wordshaper@weatherishappening.networkW This user is from outside of this forum
                        wordshaper@weatherishappening.networkW This user is from outside of this forum
                        wordshaper@weatherishappening.network
                        wrote last edited by
                        #34

                        @peter I am, for one rare moment, actually glad to read the HN comments. The one from the dude complaining that blocking all downloads of the compromised package breaks all his setups because they're written to automatically pull a bunch of packages off the net every time they start was... :chefskiss:

                        peter@thepit.socialP 1 Reply Last reply
                        0
                        • wordshaper@weatherishappening.networkW wordshaper@weatherishappening.network

                          @peter I am, for one rare moment, actually glad to read the HN comments. The one from the dude complaining that blocking all downloads of the compromised package breaks all his setups because they're written to automatically pull a bunch of packages off the net every time they start was... :chefskiss:

                          peter@thepit.socialP This user is from outside of this forum
                          peter@thepit.socialP This user is from outside of this forum
                          peter@thepit.social
                          wrote last edited by
                          #35

                          @wordshaper@weatherishappening.net lmao oh my god that one is amazing 😂

                          1 Reply Last reply
                          0
                          • slab_bulkhead@mastodon.onlineS slab_bulkhead@mastodon.online

                            @peter Semi-related: anyone know why that issue had hundreds of bot replies like "this worked for me"? Is that reputation farming or an active strategy to bury important information in slop?

                            peter@thepit.socialP This user is from outside of this forum
                            peter@thepit.socialP This user is from outside of this forum
                            peter@thepit.social
                            wrote last edited by
                            #36

                            @slab_bulkhead people were saying it's a thing this particular group does to muddy the water. pretty clever!

                            1 Reply Last reply
                            0
                            • R relay@relay.an.exchange shared this topic
                            • nan@mastodon.greenN nan@mastodon.green

                              @peter is wrapping a vibe coded mess into a package so it looks reasonable the new sub-prime mortgage?

                              prietschka@mastodon.socialP This user is from outside of this forum
                              prietschka@mastodon.socialP This user is from outside of this forum
                              prietschka@mastodon.social
                              wrote last edited by
                              #37

                              @NaN @peter It's more properly understood as akin to the product innovation that was crack in the 1980s.

                              1 Reply Last reply
                              0
                              • peter@thepit.socialP peter@thepit.social

                                RE: https://mstdn.social/@hkrn/116284264915152671

                                lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

                                gemelen@mammut.moeG This user is from outside of this forum
                                gemelen@mammut.moeG This user is from outside of this forum
                                gemelen@mammut.moe
                                wrote last edited by
                                #38

                                @peter
                                I could also see from the description on what's stolen by the credential collecting part - almost all tools and their config files are those that don't follow XDG directories structure.
                                So, if an attacked computer configured properly, these credentials are just not there to be stolen. That's kinda hilarious.
                                An example: even if I have to have a .ssh in root of the homedir, it's a symlink into the .config/ssh, where no keys are present in the ~/.config/ssh (and config file is parameterised, so it doesn't include key paths, for example).

                                1 Reply Last reply
                                1
                                0
                                • R relay@relay.mycrowd.ca shared this topic
                                • peter@thepit.socialP peter@thepit.social

                                  RE: https://mstdn.social/@hkrn/116284264915152671

                                  lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

                                  jackemled@furry.engineerJ This user is from outside of this forum
                                  jackemled@furry.engineerJ This user is from outside of this forum
                                  jackemled@furry.engineer
                                  wrote last edited by
                                  #39

                                  @peter lmao my ass off

                                  1 Reply Last reply
                                  0
                                  • R relay@relay.infosec.exchange shared this topic
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups