Comment by snvzz
1 day ago
The AI chatbot vulnerability reports part sure is sad to read.
Why is this even a thing and isn't opt-in?
I dread the idea of starting to get notifications from them in my own projects.
1 day ago
The AI chatbot vulnerability reports part sure is sad to read.
Why is this even a thing and isn't opt-in?
I dread the idea of starting to get notifications from them in my own projects.
Making a strcpy honeypot doesn’t sound like a bad idea…
Some clever obfuscation would make this even more effective.
That got those Core SDI abo vibes.
Flashback of writing exploits for these back in high school.
In an interesting way, this is an attempt to exploit LLMs into revealing themselves.
It's a symptom of complete failure of this industry that maintainers are even remotely thinking about, much less implementing changes in their work to stave off harassment over false security impact from bots.
Because humans generate and relay the slop-reports in the hopes of being helpful
There is or was a cash bug bounty.
And even if not, the motivation is building a reputation as a security “expert”.
s/being helpful/making money.