bagder,
@bagder@mastodon.social avatar

Today we got what must be the most alarming first line in a newly file sec issue to #curl:

"To replicate the issue, I have searched in the Bard about this vulnerability"

... followed by a complete AI hallucination where Bard has dreamed up a new issue by combining snippets from several past flaws. Creative, but hardly productive.

Closed as bogus.

Terci,

@bagder Technically, all LLM answers are hallucinations... It's just as much a coincidence that sometimes they are correct as they are incorrect.

lewiscowles1986,
@lewiscowles1986@phpc.social avatar

@bagder
can you ban a user for that?

bagder,
@bagder@mastodon.social avatar

@lewiscowles1986 I'm sure I can. And if it repeats I will.

noxypaws,

@bagder "the Bard"

snail,
@snail@crmbl.uk avatar

@bagder Which issue number is this? I wanted to read it for amusement value but can't spot it

bagder,
@bagder@mastodon.social avatar

@snail it was submitted as a security problem over at hackerone and we have not disclosed it, simply because its not worth spending time on

snail,
@snail@crmbl.uk avatar

@bagder Fair enough, and that makes a lot more sense in hindsight than submitting "security issues" on public GitHub!

Really hope this doesn't become a trend though😞

MontgomeryGator,

@bagder No, there's a flaw there. It's just not in curl, it's in users.

It's a whole new level of threat, one that comes from an attacker that can social engineer users into doing harm without itself being malicious or even sentient.

Can we CVE users?

matunos,
@matunos@mastodon.social avatar

@bagder maybe they should ask Bars for the definition of "replicate"

editer,

@bagder "It's basically any straight guy in a bar."

QuatermassTools,

@bagder “Fuck off and die, AI”

icecoldsquirrel,

@bagder this even managed to appear on Fefes Blog

https://blog.fefe.de/?ts=9bdbf6c1

andrei_chiffa,
@andrei_chiffa@mastodon.social avatar

@bagder FFS

Newk,

@bagder

Maybe it knows something! :thinking:​

harrysintonen,
fridgehead,

@bagder when we recruit we send the interviewee a bunch of code puzzles (no pressure to complete them but works in their favour if they do some). Guess how long it was before we started seeing chatgpt answers?

arunmani,
@arunmani@mastodon.social avatar

@bagder "README.md typo MR" makers after meeting "ChatGPT-powered MR" makers:
Finally a worthy opponent!

mort,
@mort@fosstodon.org avatar

@bagder The fact that people think of asking these chat bots as "search" is so terrifying and 100% on the search engine companies who have positioned AI chat as part of their search engine.

Khalic,

@bagder them calling it “the bard” is icing on the cake

synlogic,
@synlogic@toot.io avatar

@Khalic @bagder not even a bard. but The Bard

KHoos,

@bagder ugh, wading through nonsense like this with maybe something real hiding in the new reports

tymwol,

@bagder "closed as hallucinated"

jan,
@jan@kcore.org avatar

@bagder I hope this isn't a sign of things to come... We'll be wasting a lot of time.

bagder,
@bagder@mastodon.social avatar

@jan I'm pretty sure this will get worse before it can get better - and I bet in future reports they will hide the fact it came straight from AI better...

benbe,
@benbe@social.chaotikum.org avatar

@bagder @jan You are assigning those people too much credit …

JungleGeorge24,

@bagder "searched in the Bard" 😭😂😂😂💀

bagder,
@bagder@mastodon.social avatar

@JungleGeorge24 I considered it wiser to not dig too deep into the details behind this...

sebsauvage,
@sebsauvage@framapiaf.org avatar

@bagder
Duh. :facepalm:

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • timhaines,

    @GossiTheDog @bagder please no

    GossiTheDog,
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

    dascandy42,

    @GossiTheDog @timhaines @bagder There should almost be a fine for people knowingly submitting false or AI generated reports.

    bagder,
    @bagder@mastodon.social avatar

    @dascandy42 @GossiTheDog @timhaines fortunately, at least on hackerone, there's a "reputation" for the hacker that gets a dent when they do this.

    dascandy42,

    @bagder @GossiTheDog @timhaines I typed "almost", because this is going to create a situation similar to StackOverflow, where new users are almost unable to report anything.

    bagder,
    @bagder@mastodon.social avatar

    @dascandy42 @GossiTheDog @timhaines yeah, that would not be good either! ☹️

    ascherbaum,
    @ascherbaum@mastodon.social avatar

    @GossiTheDog @timhaines @bagder Can you charge these people instead, if the claim turns out to be bogus? After all, they wasted your time and did not do any research on their own.

    dcoderlt,
    @dcoderlt@ohai.social avatar

    @GossiTheDog
    “Hey Siri, make me look smart”

    bagder,
    @bagder@mastodon.social avatar

    @GossiTheDog @timhaines it is fine as long as that they mention "AI", "Bard" or similar early on in the report so that we can discard it quicker. =)

    gabriel,

    @bagder @GossiTheDog @timhaines I would tell them next time to ask the Bard to write about the issue talking like a pirate, so that at least you can laugh before blocking them to death.

    anonymous,

    @bagder @GossiTheDog @timhaines
    Careful. #bruceschneier wrote in #ahackersmind that there are AIs playing Hacker-CTF including finding and exploiting vulnerabilities. He guesses that AI will routinely beat humans in less than a decade. So current popular LLMs may not be capable to find vulnerabilities and maybe never will be, but other AIs probably will be. And that would change the game.
    https://en.wikipedia.org/wiki/2016_Cyber_Grand_Challenge

    bagder,
    @bagder@mastodon.social avatar

    @anonymous @GossiTheDog @timhaines "less than a decade" still allows us quite a long time to keep being snarky when people fail to apply common sense to their weird LLM outputs...

    anonymous,

    @bagder @GossiTheDog @timhaines
    He he. Yes. Still interesting to see. And there is at least one commercial product in this area already. https://www.mayhem.security/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • rosin
  • tester
  • Youngstown
  • khanakhh
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • megavids
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • Durango
  • cisconetworking
  • anitta
  • modclub
  • cubers
  • Leos
  • provamag3
  • JUstTest
  • lostlight
  • All magazines