this post was submitted on 21 Jul 2025
699 points (98.6% liked)

Technology

296 readers
278 users here now

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No videos.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

More sites will be added to the blacklist as needed.

Encouraged:

founded 2 months ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] BigDanishGuy@sh.itjust.works 11 points 6 days ago (1 children)

I want to believe noone is stupid enough to give an LLM access to a production system,

Have you met people? They're dumber than a sack of hammers.

people who let an LLM loose on their system probably haven't thought about things like disaster recovery planning, access controls or backups.

Oh, I see, you have met people...

I worked with a security auditor, and the stories he could tell. "Device hardening? Yes, we changed the default password" and "whaddya mean we shouldn't expose our production DB to the internet?"

[โ€“] notabot@piefed.social 11 points 6 days ago

I once had the "pleasure" of having to deal with a hosted mailing list manager for a client. The client was using it sensibly, requiring double opt-in and such, and we'd been asked to integrate it into their backend systems.

I poked the supplier's API and realised there was a glaring DoS flaw in the fundamental design of it. We had a meeting with them where I asked them about fixing that, and their guy memorably said "Security? No one's ever asked about that before...", and then suggested we phone them whenever their system wasn't working and they'd restart it.