HN user

dotty-

624 karma
Posts14
Comments69
View on HN

At first glance, this feels like just an internal testing prompt at their company for some sort of sales pipeline. Feels more like an accident. None of the referenced files are actually in the repository. If the prompts had more of a "If the user mentions xyz, mention our product" that would absolutely give more credence that this is an advertising prompt, but none of that is here.

I saw this too and immediately thought: well, they published this on GitHub which surely has a clause that grants it a license to use the code for training Copilot for Microsoft at a minimum, sooo should've published on another Git platform.

You joke, but that's a very real approach that AI pentesting companies do take: an agent that creates reports, and an agent that 'validates' reports with 'fresh context' and a different system prompt that attempts to reproduce the vulnerability based on the report details.

*Edit: the paper seems to suggest they had a 'Triager' for vulnerability verification, and obviously that didn't catch all the false positives either, ha.

Really wish people didn't continue to misunderstand the concept of wealth & having cash. First sentence of the article:

Back when Elon Musk had a bank account with merely one billion dollars in it he had to borrow money from the federal government to get his fledgling EV automaker off the ground. In January of 2010 the Department of Energy's Loan Programs Office floated Tesla $465 million ...

Here is an article in 2010 talking about Musk running low on cash & his divorce causing him financial issues https://venturebeat.com/business/elon-musk-personal-finances...

The Verizon Call Filter app uses the endpoint hxxps://clr-aqx.cequintvzwecid.com/clr/callLogRetrieval to lookup call history for the authenticated user and display it in the app.

Have you ever seen a more internal-looking domain name?

I don't get that at all. I understand this to point to an attempt at scrubbing information that could lead back to him personally -- but done poorly as Krebs pointed out that other personal photos continued to exist on the Facebook account afterwards.

I don't think creating a separate tier of enhanced OS upgrades would benefit Ubuntu. Ubuntu isn't connected to a multi-billion dollar corporation. Canonical has no resources to offer a free AI-powered Notepad editor. Microsoft is connected to OpenAI, Microsoft has AI-hardware partners, and Microsoft has the in-house resources to create new drivers for new hardware/software compatibility issues.

There will always be valid reasons to use Windows over Ubuntu.

I just wish Microsoft had a simpler mindset for their OS. Simple, privacy-first, consumer-first defaults and optional upgrades to more enhanced tools via their App Store.

Imagine if instead of Windows Recall being installed and available automatically on machines, they just added Recall as an optional downloadable add-on via the App Store... I don't think it would have received nearly as much backlash.

The pricing is very interesting. The company I work for pays $20k for Jira & Confluence and $20k for Slack every year. And this platform claims I can replace both of them for $3600/year? and it's open source? The marketing looks great, so I hope the platform is actually a good competitor. I'd be so curious to see what their revenue is every year.

The beauty of forking/open source is the ability to contribute back to the original project or take over an abandoned project. In this case, the original project Continue.dev isn't abandoned and actually has more traction/commits than the PearAI fork. But what PearAI did not do is a traditional fork. They took the commit history, re-branded everything to PearAI, pushed it up to their own repo, and claimed that the contributors of VSCode & Continue were their own contributors on Twitter.

That's not the spirit of open source. I'm sure the authors of Continue.dev did not intend for their work to be used this way, even if the license is permissive of it.

I hope SAP does a hard retrospective on why Wiz's research was not disrupted before they got full cluster admin. Like, I want to know from SAP's side whether they received any alerts for any of this activity and whether they investigated them properly. I wonder if there is any regulation SAP has to follow that requires them to have adequate alerting for suspicious network activity and whether this research can be used to show that they do not.

This has been happening for years. My theory is the actors running the bots are instructing their bots to use old popular threads as a blueprint to get a bunch of upvotes across all of their accounts at once. The idea being that clearly Reddit users liked the original posts and comments in the past, so the users will upvote it again. Then they sell the accounts to bad actors who are interested in purchasing accounts with real looking post histories.

When you make a transaction on the Bitcoin network (and really every other cryptocurrency), you tack on a fee to the amount of coin you want to send. Miners prioritize higher fee transactions when deciding which transactions to include in the next block. Therefore, to guarantee your inclusion in the next block, you would choose to increase the fee you pay.

So, for this transaction, they chose to pay a $5000 fee to guarantee their placement in this block.

Whether or not you agree with the greater philosophical goal of Bitcoin, Bitcoin proved the ability to create a system of value using basically just cryptography and with a built-in reward system to incentivize the decentralization of the network -- and it grew enough that it can now operate as a standalone method of payment. It's an amazing feat.

Snowden is correct here: https://twitter.com/Snowden/status/1759304612664779247

I get what you're trying to do, but the first impression I get when opening the site is "this site is asking for credentials to connect to my database for me". It doesn't have the look of a "quick utility" website to generate a command. I like crontab.guru as an example of a "quick utility" site that I go to frequently with an intuitive UX. I think if your site had the "generated command" front-and-center, maybe even pre-generated with a command already, the site's goal might feel more obvious upfront.