lol oh my god i feel **so fucking smug** right now, it's incredible.
-
@tael i think also, banks and payment processors have made it so much more difficult to steal and do anything with credit card numbers that there's not much point in going after those anymore, especially when finding someone's crypto passphrase is like picking up money off the ground.
@peter It's easy to siphon crypto, yeah, but turning that into spendable money has gotten much, much more difficult than it used to be.
-
oh my fucking god.
@peter is wrapping a vibe coded mess into a package so it looks reasonable the new sub-prime mortgage?
-
@peter @tante @briankrebs thank you for this comedy gold
@peter @tante @briankrebs we've replaced Jia Tan with a very small prompt
-
there are **tons** of AI-related projects that use LiteLLM. it is a key part of the basic infrastructure of LLM-based development. if you use an LLM-based project, there is a good chance it uses LiteLLM.
That xkcd comic with the stacked blocks, but instead of one guy in Nebraska, it's LLM slop.
-
@peter @tante @briankrebs thank you for this comedy gold
@tante@tldr.nettime.org @davidgerard@circumstances.run @briankrebs@infosec.exchange @prietschka@mastodon.social @peter@thepit.social
@prietschka You're gonna get a laugh out of this one, methinks.
-
@tante@tldr.nettime.org @davidgerard@circumstances.run @briankrebs@infosec.exchange @prietschka@mastodon.social @peter@thepit.social
@prietschka You're gonna get a laugh out of this one, methinks.
@dogiedog64 @tante @briankrebs @prietschka @peter lol god yes he will
-
RE: https://mstdn.social/@hkrn/116284264915152671
lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.
@peter Semi-related: anyone know why that issue had hundreds of bot replies like "this worked for me"? Is that reputation farming or an active strategy to bury important information in slop?
-
plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729
looks grim!!
@peter I am, for one rare moment, actually glad to read the HN comments. The one from the dude complaining that blocking all downloads of the compromised package breaks all his setups because they're written to automatically pull a bunch of packages off the net every time they start was... :chefskiss:
-
@peter I am, for one rare moment, actually glad to read the HN comments. The one from the dude complaining that blocking all downloads of the compromised package breaks all his setups because they're written to automatically pull a bunch of packages off the net every time they start was... :chefskiss:
@wordshaper@weatherishappening.net lmao oh my god that one is amazing

-
@peter Semi-related: anyone know why that issue had hundreds of bot replies like "this worked for me"? Is that reputation farming or an active strategy to bury important information in slop?
@slab_bulkhead people were saying it's a thing this particular group does to muddy the water. pretty clever!
-
R relay@relay.an.exchange shared this topic
-
@peter is wrapping a vibe coded mess into a package so it looks reasonable the new sub-prime mortgage?
-
RE: https://mstdn.social/@hkrn/116284264915152671
lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.
@peter
I could also see from the description on what's stolen by the credential collecting part - almost all tools and their config files are those that don't follow XDG directories structure.
So, if an attacked computer configured properly, these credentials are just not there to be stolen. That's kinda hilarious.
An example: even if I have to have a .ssh in root of the homedir, it's a symlink into the .config/ssh, where no keys are present in the ~/.config/ssh (and config file is parameterised, so it doesn't include key paths, for example). -
R relay@relay.mycrowd.ca shared this topic
-
RE: https://mstdn.social/@hkrn/116284264915152671
lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.
@peter lmao my ass off
-
R relay@relay.infosec.exchange shared this topic