HN user

erans

62 karma

http://eran.sandler.co.il https://x.com/erans/ https://bsky.app/profile/esandler.bsky.social https://linkedin.com/in/erans/ https://tkmx.odio.dev/user/erans

Posts11
Comments26
View on HN
Copy Fail 3 months ago

For agents, if you are concerned about that, block access to "su" as it is interactive anyway. Not loading it into the memory will block the attack. If you are using AgentSH (https://www.agentsh.org) you can add a rule to block "su" and soon be able to block AF_ALG sockets if you want to further protect things.

The part that seems most important here is that npm install was enough.

Once the compromise point is preinstall, the usual "inspect after install" mindset breaks down. By then the payload has already had a chance to run.

That gets more interesting with agents / CI / ephemeral sandboxes, because short exposure windows are still enough when installs happen automatically and repeatedly.

Another thing I think is worth paying attention to: this payload did not just target secrets, it also targeted AI tooling config, and there is a real possibility that shell-profile tampering becomes a way to poison what the next coding assistant reads into context.

I work on AgentSH (https://www.agentsh.org), and we wrote up a longer take on that angle here:

https://www.canyonroad.ai/blog/the-install-was-the-attack/

true that there is a some kind of a ceiling of what can or can't be done. But that ceiling is way up there. Also, there are enough examples and articles and code that allows enough combination to be made so that its good enough - and that is a very important bar.

There are A LOT of businesses (even big ones managing money and what not) that rely on spreadsheets to do so much. Could this have been an app/service/SaaS/whatever ? probably.

What if these orgs can (mostly) internally solidify some of these processes? what if they don't need an insanely expensive salesforce implementor that can add "custom logic" ?

A lot of times companies will replace "complex software" with half complex process!

What if they don't need Salesforce at all because they need a reasonable simple CRM and don't want to (or shouldn't) pay $10k/seat/year ?

There are still going to be very differentiating apps and services here and there, but as time move on these "technological" advantages will erode and with AI they erode way faster.

I would argue that due to the way MCP servers/tools are added to calls, there will be a pre-step that will figure out which MCPs are even relevant for a request prior to executing it.

Most Thinkpads will work just fine out of the box. The hardware is great (I specifically like the keyboard and the little red point mouse).

The T series (and W series) are the work horses here with various screen sizes, disk options and RAM.

I personally use the X1 Carbon 3rd gen (X series) as it is comparable in specification to a Macbook Pro 13" (I have the one with the 16GB of RAM). It's a little costly but its worth while and will probably serve me for the next 2+ years.

I know this is too much, however we plan on adding the ability to inject sharing data directly to websites, that's why we asked for it in advance.

We would never do anything to miss use it and we felt that an optional permissions scenario was rather too complex.

How would you fill with an optional permissions scenario?

We've been analysing sharing patterns for a while. We tend to see that Twitter shares correlate too much with the amount of posts per day which may indicate its more bot driven.

FB Likes and +1 are much harder to fake and seems to correlate more with actual human traffic.

From our experience +1 tends to be factored into Google search results so there is direct value in having +1 on your site and having your visitors who like the content click on it (not to mention it gets circulated inside Google Plus itself).

We are working to add more sites as we go along and we would be happy to share some information about patterns across sites and topics.

Thanks for the vote of confidence. We think its a great tool too. There is much to wait for with additional insights that we are thinking about.

Would love to get feedback from the community about which other types of information and analysis they would like to see.