pull down to refresh

I'm not sure promoting all the bugs they're finding is good for defenders.

Hey jackpot in this tiny underfunded developer niche!

They might do it to get more volunteers and token funding to join the red team

reply

At least help builders be aware of vulnerabilities that they wouldn't see otherwise.

reply
154 sats \ 6 replies \ @k00b 6 Aug

I'm very happy they're doing it. I'm questioning the very loud promotion of it even if it is vague.

reply

I thought the same, shouldn't they share with each project in private?

reply
147 sats \ 3 replies \ @k00b 6 Aug

That's usually how this kind of thing is done. I think because they're excited to help and, because they are being vague, they think it's maybe not the same thing. But when red teaming = skilled programmers pointing uncensored models at projects, it's not exactly vague anymore.

reply

Usually you don't disclose that you're working on something until the fix is deployed. This has gone out of the window it seems, which is extra dangerous now, because anyone can ask a bot to write a script to feed repos into bots.

reply

Good intention is not enough sometimes; it feels a bit improvised. Some people with dirty broken keyboards and more field experience in these matters should jump in.

reply

I think what they'll need most is case managers. Those are expensive though. Can't outsource that to a bot.

reply

Maybe the promotion is the point (even if they've convinced themselves it isn't)

reply
reply

they found me on signal eventually

reply