Simple as that, because that's the attack surface.
https://cookie.engineer/weblog/articles/malware-insights-git...
I wrote that article December 2024. Still ongoing, Microsoft. Best enterprise security practices, I suppose shrugs ...
7,955 karma · joined August 15, 2016
For the last years I've been building a (co-evolutionary) AI-driven startup in the form of the https://tholian.network
The open source projects I've built in the past can be found on:
- https://github.com/cookiengineer (same account on gitlab)
- https://cookie.engineer
Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.
I only use reddit, HN, and LinkedIn. All other accounts are probably fake, because I don't like the toxicity that social media embraces as you might've guessed already.
PS: If you want to contact me, check my personal website's Contact Me page.
Have a great day, stranger!
Simple as that, because that's the attack surface.
https://cookie.engineer/weblog/articles/malware-insights-git...
I wrote that article December 2024. Still ongoing, Microsoft. Best enterprise security practices, I suppose shrugs ...
Post November and post openclaw agentic environments need to be built differently, and for selfhosting models the context size problem really requires a strong harness which intelligently helps reduce context size.
Planner/orchestrator architecture, agent to agent summarizer, specification based tools (fck all this markdown memory bullshit btw), tool call shrinking, and workflow management are all really important because of the context size problem.
Nobody has enough VRAM for the large K/V caches, and nobody can afford f16/f32 caches in terms of memory, which are also necessary for longer conversations. MoE 30b models have improved so much though, qwen 3/3.6 coder is the real champion doing almost the same things with less than 1/10th the memory requirements. Just think about that in terms of engineering and what your bet is going to be. Haiku pales in comparison.
Currently my focus with exocomp is trying to figure out how I can record, replay, restart, and debug workflow sessions of agents in a better manner so that I as a human can understand what's going on. Currently I think that UI will be something like a gantt chart where you have a graph with connections representing agent to agent communication. And yes, that's a lot of fiddling with SVG as it turns out, so I'm not quite there yet.
Anyways, in case you're interested. I'm manually building this env and trying to unit test the critical parts. [1]
(Author of Gooey [1], a GUI framework for WebASM in Go)
I also built a convenient CLI tool to switch identities on a per-repository basis. [1] [2] ...which makes working in enterprise environments much easier, as I can just have separate identities/keypairs for each customer.
[1] https://github.com/cookiengineer/git-identity
[2] https://cookie.engineer/projects/development/git-identity.ht...
The point behind agentic environments and an orchestrator/planner architecture is that you can delegate defined and specified tasks to short living and low tempered agents. Well, at least if you know what you are doing, and know how to specify these things based on an AST and not markdown notes, for example.
(Judge for yourself if Claude is the right IDE for that, given that their source code from a couple weeks ago is available)
Languages that use pointers and have dependencies on time need strong specifications for LLMs to make sense. And that's what's missing.
Disclaimer: I am building a pentesting and Go focused agentic IDE for short living agents, so my point of view is not using hyped tools but trying to understand harness engineering well enough to let the kids mess with your codebase.
Other than that, I can recommend going for IoT devices like VOIP phone MAC addresses in conference rooms, because they're specifically allowlisted for everything and/or are in a different VLAN that doesn't block the endpoints.
Enterprise-grade security is always fun :D
My question is now: Which company is gonna buy the IRS now?
In the US?
Hahaha, that was a good one, buddy.
That's the real reason.
If you don't believe me, take a look at the leaked codebase from a couple weeks ago. It's the stuff of nightmares, because too many junior devs slopcoded in all places without any plan or understanding of software architecture patterns. They never actually take the time to refactor, there's dozens of outdated redundancies and orphaned modules all over the place.
Without good architecture patterns, there can be no good GUI nor good UX.
I laughed out loud when I read this paragraph. There are so many "consciousness" or "memory" or "learning" AI bullshit startups right now...all of them not understanding how positional encoding of LLMs work. It's getting so ridiculous that I don't even understand why they're in the (uncurated) news everywhere.
It's like everyone tries it out, and writes without any journalistic integrity because it's a sponsored article that costs 100$, and moves on. Spamming as a bought in service or something. It doesn't make sense to me, and I have no clue how broken the economics of this must be to get into the state of "AI news" we are in right now. Excuse my French, but something must be utterly broken.
The slow turtle wins the race against the overly eager rabbit... so I'm okay with that
That was the original stealth game in my opinion :D
... well, apart from XIII, NOLF, Commander Keen and Agent Sam, of course.
The 90s sure had some awesome games
It's actually more like 50 devs, each of them specialized in their own field, with 20+ years programming experience.
And even they make mistakes sometimes (see the recent TOCTOU exploit wave).
What vibecoders never get: it's about stability of software. Nobody will rely on your vibecoded project if even you yourself don't give a damn about any API stability or API contracts.
If you expect others to use vibecode assistants to use your software/library... then what was the reason in the first place to write it, if it's effectively not solving a problem? The whole points of dependencies and packages goes out of the window once the library maintainers start to use slopcoding practices.
Managing agents is a lot like managing children. They will outsmart you 99% of the time. If your agentic environment isn't built for good sandboxing, you won't succeed.
If you build an environment that can represent mutual cooperation (e.g. helping an agent by doing the tool calls yourself if it was stuck) then it's soooo much better than just trying to rephrase the ruleset of the engagement.
Don't optimize for retries. Optimize for sandboxing and strong agent to agent communication that you can also observe, modify, and summarize.
...because they never patch it, and are busy building robots instead.
Assuming reasonable implementation standards at this point is the irrational assumption, not the rational one.
Your mismatch is that you think in policies, not assessments here. Nothing in my normal go workflow will ask me if I want to run "curl download whatever from the internet" when I run go build.
Though I agree with the difference in workflow, there is not a single mechanism in go catching this. go.mod files can be just patched by the worm, and/or hidden behind a /v123 folder or whatever to play shenanigans on API differences.
Examples that come to mind: webview/webview, webkit, cilium/ebpf and most other CGo projects that I have seen.
NPM's achilles is the pre/postinstall step which can run arbitrary commands and shell scripts without the user having any way to intervene.
Dependencies must be run in isolated chroot sandboxes or better, inside containers. That would be the only way to mitigate this problem, as the filesystem of the operating system must be separated from the filesystem of the development workflow.
On top of that most host based firewalls are per-binary instead of per-cmdline. That leads to the warnings and rules relying on that e.g. "python" or "nodejs" getting network access allowlisted, instead of say "nodejs myworm.js". So firewalls in general are pretty useless against this type of malware.
How could anybody besides a Microsoft employee, given the appearance of this bypass technique?
> thats an LPE, not an encryption backdoor
No. RedSun and Bluehammer were LPEs
> the USB stick doesnt decrypt bitlocker, it just gives you root after bitlocker was AUTOMATICALLY decrypted
No, that's not what the bypass does. Maybe go try it out and verify it before you come to your quickly made conclusions?
It's not tied to "automatically decrypted" volumes, whatever that would imply for your setup requiring a pretty pointless TPM keystore for that.
If your case were true, it would also imply that any bitlocker cryptography never really worked because it was automatically decryptable without the need for a password/hash/whatever to get your keys from the keystore, which actually makes it so much worse. Even worse than the previously known coldboot attacks.
A USB stick containing a masterkey to decrypt a bitlocker volume is literally the definition of a backdoor.
Go on, try it out. It works.
Do you know how hard discovering even one of those is? And how many months of work it takes?
That's what this is about. Microsoft doing bad security practices while trying to get away with it, leading to this outcome.
The researcher also claims to have another version ready which allows to also bypass TPM+PIN via a similar backdoor, which I'm inclined to believe.
Why do I believe that? 5 ring 0 zero days within 3 months are so statistically unlikely to be found, by the same person, in such a short time. Whoever this person is really knows their exploits, and must be in the league of Juan Sacco.