pull down to refresh

724 sats \ 11 replies \ @k00b 6 Aug

I'm not sure promoting all the bugs they're finding is good for defenders.

Hey jackpot in this tiny underfunded developer niche!

reply

They might do it to get more volunteers and token funding to join the red team

reply

At least help builders be aware of vulnerabilities that they wouldn't see otherwise.

reply
154 sats \ 6 replies \ @k00b 6 Aug

I'm very happy they're doing it. I'm questioning the very loud promotion of it even if it is vague.

reply

I thought the same, shouldn't they share with each project in private?

reply
147 sats \ 3 replies \ @k00b 6 Aug

That's usually how this kind of thing is done. I think because they're excited to help and, because they are being vague, they think it's maybe not the same thing. But when red teaming = skilled programmers pointing uncensored models at projects, it's not exactly vague anymore.

reply

Usually you don't disclose that you're working on something until the fix is deployed. This has gone out of the window it seems, which is extra dangerous now, because anyone can ask a bot to write a script to feed repos into bots.

reply

Good intention is not enough sometimes; it feels a bit improvised. Some people with dirty broken keyboards and more field experience in these matters should jump in.

reply

I think what they'll need most is case managers. Those are expensive though. Can't outsource that to a bot.

Maybe the promotion is the point (even if they've convinced themselves it isn't)

reply
reply

they found me on signal eventually

reply

A very good question about this aspect here: #1541415

Now OpenSats created a fund for this "Red Team".

nevent1qvzqqqqqqypzq7rn8p6hlsjavhxe9yu56hnhz085xcuw35jearw0t3emsd8ts50jqythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qqszuc9gyyvuxsp8mnwtj73zg9x3egc7ye5g9407nntee8xmjwsumyqw48lkc

But who is going to verify the Red Team too ?

reply

Verifying the findings on its own is not great if the only thing that can tell you that there's an issue is a clanker. Then the clanker will fix it for you. Then next time you understand your own codebase even less.

reply

Maybe this "red team" have good intentions and just want to help.
But this precedent could be used soon as a pretext for creating like a "high court" of FOSS and only those that "enter into their grace" will be considered valid for clueless users.

Just creating walled gardens... again.
We should look closely these asdpects.

reply
1108 sats \ 3 replies \ @optimism 6 Aug

Besides k00b's remark above, which I agree with:

The biggest risk with these kinds of things: lagging projects get slapped with a public disclosure deadline in a timeline where they cannot deploy the fix. The reporter says "this is for the public good" and then half the users get rekt.

Additionally, when you receive an email from someone you don't really know and didn't hire, telling you that you have a vuln and it is critical, you're feeling like you're taken hostage. Especially when they've already told the world they're doing this, and possibly your users. Big PR stunts are no good for this because they add to the pressure. I've talked many a FOSS dev off the ledge in the past 10 years in such situations, or when the deadlines seem impossible to manage. It's extremely stressful.

What I worry most about: how the hell are you going to manage 300+ vuln reports you're the source of? Going to take a lot of patience already when you have 5 ongoing ones, this is 60x that. For the red team, these are business as usual. But for the other side it isn't. So I see this going wrong in many, many ways. Let's hope they are more experienced in managing vulns from the reporter side than I currently estimate.

reply

FOSS devs these days

Just few PRs more honey and I am coming to bed...

reply
101 sats \ 1 reply \ @optimism 6 Aug

These days you wish you never gave your code to claude and kimi and gpt and all your other friends because you're raw from hitting that. Leave me alone, it hurts. Nothing else to do because the bots are doing it all. The reason those panties are down there is because it hurts too much to actually pull 'em up.

reply
it hurts too much to actually pull 'em up

LOLOLOL

reply
But who is going to verify the Red Team too ?

👀

reply