I added some notes to the gist.
HN user
eliya_confiant
Hi Simon,
Big fan of your work with the LLM tool. I have a cool use for it that I wanted to share with you (on mac).
First, I created a quick action in Automator that recieves text. Then I put together this script with the help of ChaptGPT:
escaped_args=""
for arg in "$@"; do
escaped_arg=$(printf '%s\n' "$arg" | sed "s/'/'\\\\''/g")
escaped_args="$escaped_args '$escaped_arg'"
done
result=$(/Users/XXXX/Library/Python/3.9/bin/llm -m gpt-4 $escaped_args)
escapedResult=$(echo "$result" | sed 's/\\/\\\\/g' | sed 's/"/\\"/g' | awk '{printf "%s\\n", $0}' ORS='')
osascript -e "display dialog \"$escapedResult\""
Now I can highlight any text in any app and invoke `LLM` under the services menu, and get the llm output in a nice display dialog. I've even created a keyboard shortcut for it. It's a game changer for me. I use it to highlight terminal errors and perform impromptu searches from different contexts. I can even prompt LLM directly from any text editor or IDE using this method.Is it POKT?
Hi, author here. I liked this comment a lot and I can help to shed some light:
We do see phishing pages like this increasingly popping up with obfuscation. I think at this time less than a third are obfuscated, but this is gradually increasing. The thing is, most of the folks running these sites are likely not very technical. They buy the template from a vendor and plug in the config settings and just focus on driving traffic to the site - this happens through Discord & Twitter spam.
The thing with fraudsters and threat actors that play in this space is that at the end of the day it's a business and they want maximum reward for minimal effort. I think right now there's not a very aggressive takedown feedback loop with these phishing sites, but we are working to accelerate this and as this happens the perpetrators WILL need to rely more on obfuscation to try and thwart on the fly static detection. My guess is that eventually most of the logic will be server-side and cloaked as has happened with many other categories of phishing and fraud (particularly malvertising campaigns). Sooner or later the more amateur scam operators in this space will likely get shaken out by this acceleration of the cat and mouse game and only highly technical operators will be left.
With regards to the sites that we see obfuscated today, we are still able to do accurate attribution, as we've been specializing in the detection and blocking malicious client-side code for some time now.
Thanks again for your comment.
That's correct. It's just a subtle way of doing OS fingerprinting.
The user still needs to go through with the fake Flash update. Even if one is to accidentally fat finger the download, they still have to proceed with the installation. To protect yourself, please be vigilant and only accept software updates directly from the vendor of the software you are using. This is more of a phishing attack to get folks to install malware / adware.
The industry is moving in a direction where more and more ads will be sandboxed, we are just not there quite yet.
Hi everyone, I'm the author of the blog post. We at Confiant help websites to protect their users by detecting and blocking malvertising. We are hiring in our security and engineering teams.
If you're interested in working to combat the problem outlined in the blog post, we would love to hear from you! Please reach out to me [eliya AT confiant DOT com].
I will be back a little bit later to answer some of the questions that I see here in the comments as well. Thanks!