2026-09-08 03:20 UTC
Replies (2)
-
@terranoid@lemmy.cafe 2026-09-08 04:06
These LLM are able to exploit some basic shit. A lot of hacks are not complicated. Some good hacks are literally just a result of reading and understanding code and trying something weird, especially webapp vulns. Some hacks can be seriously crazy and impressive, but a lot end up being very basic. Often they’re hard to find just because you have to read a ton of code you might not be familiar with and know what sort of issues could result, things people forget to check. Whenever I hear some hyped up news about some hack the AI does, it’s almost never coupled with a detailed report about anything tricky they had to do to exploit it. They really try to highlight that A hacked B, but not what it did, why it was impressive, and it usually sounds like it’s the result of dumbass engineers that are letting it do whatever it wants without boundaries and without reading its actions. It’s all hype because the stonks must go up. They want investor cash. They want more investments. They don’t want the bubble to pop yet. All this shit that triggers fear also triggers belief that some New industrial age just began and makes investors think they’ll get rich if they’re invested in ai. Don’t believe the weird fucking hype. Just because AI finds and uses an exploit now and then doesn’t mean it grew a new brain. They would be hiding the news if it was actually dangerous, but instead they blast it on social media because they know it means $$$
-
@Arola@sh.itjust.works 2026-09-08 07:29
I saw Eli Computer Guy on YT yesterday describing how “you don’t allow the intern full access/permissions/privileges to delete the production database”. Swap AI for intern in the marketing material and the real culprit is clear - it’s the person who gave the keys away without any foresight or common sense. You can’t blame the intern.