Or a reminder that no system can be made to be completely safe and secure. When the political pressure or violence gets in the equation it's hard to not simply falter and satisfy the demands.
A nice and simple approach to sandbox a command. Of course with the system integration it's a bit porous bit it might be a good base for quite a few uses.
Indeed, so many things to do to deter bottom feeders. Lots of good funny ideas in there.
More ideas of things to check to harden a service, goes beyond just what's deployed. Many good points on how to handle errors and such.
Good checklist to reduce your attack surface as much as possible when deploying your service.
In other words: the security boundaries of coding agents are very porous and not where you expect. Handle with extreme care until they have a proper security model.
Those systems based on LLMs really create crazy security issues as soon as they're allowed to interact with other systems.
There's clearly an issue with the security and privacy practice of those companies...
A neat and simple explanation of what CORS is and which security issues it helps with.
You sure you can trust those systems? It's proprietary software and they're clearly on a slippery slop. For something so security sensitive this is concerning.
Interesting paper (go to the full one for all the details) which shows that with the current architecture it's really hard if not impossible to make safe systems with LLMs. This gives interesting insights in the weird form of proto-cognition those models exhibit.
What happens when targeted scams become cheap to run? This covers it fairly well, and we need to change our heuristics and trust model.
Indeed, skipping the centralized package manager might be better in the long run.
Interesting take on why CVEs are reported differently for C/C++ and Rust libraries. The responsibility for API misuse is treated differently because the abilities to express contracts is treated differently.
There's really something nasty at play. Those coding agents are clearly not insulated from the system enough and to easy to manipulate to exfiltrate sensitive information.
Microsoft has been deploying new CA certificates late... Now distros have to wake up and prepare new signatures for their shims quickly.
With Bitwarden sinking, it's maybe time to look at alternatives? This AliasVault option looks like an interesting contender even though a not young.
Sounds like a good solution to self host things at home while having some protection.
This is a good point. I feel unease at the current trend pushing toward cooldowns. The proposed rollout scheme is much better and fairer.
We've seen a stream of those security issues lately. It says something about the security practice in the industry right now. Things need to be improved.