197 karma · joined May 11, 2022
So, while documenting the terror is a commendable thing to do, it will not change anyone's mind. Zombies will simply take it as evidence that their propaganda was right all along. "See for yourself how ruthless these Ukrainians neonazies are, killing their own people just to spite the big Russian brother."
All cloud vendors offer the same functionality, if you think about it, so it's not an obscure feature.
You need a real ability to reason and preserve context beyond inherent context window somehow (we humans do it by keeping notes, writing emails, and filing JIRA tickets). So while this doesn't require full AGI and some form of AI might be able to do it this century, it won't be LLMs.
Also, as an aside. While correctly implemented Passkeys (without fallback auth methods) would make my life as a red teamer much harder, that would have only prevented this attack if the infected machine was engineer's private PC where they used corporate LastPass account and nothing else from their work. If the machine that's used for DevOps work gets infected, that's still and endgame because you're generating all sessions I need during your regular workday, so I don't really need the passwords / decrypted vault.
Once you get password vault, it's very likely that you also get creds necessary to set up VPN. Besides, there are ways to bypass (poorly implemented) VPN and relying on VPNs isn't even the best practice nowadays.
I agree with you that a few CISOs getting sentences would be the fastest way to raise the bar across the tech sector, but that's never going to happen.
You can sorta kinda harden these systems, but that would only work against common malware. And you generally can't isolate senior engineers in their own little DMZ, so any RAT on their machines usually leads to catastrophic consequences.
Honestly, this HN thread is full of bad advice and factually incorrect patronizing. Okta-style system asking to accept every single permission would not have protected from an attack, because Okta caches and reuses authentication tokens. Clipboard snooping / keylogger detection wouldn't have worked because none of these solutions are robust against targeted attacks.
The only thing I can think of which would have (and should have) helped is alert SOC / incident reponse team. Good luck finding one though.
Starting from the current state, you could make ChatGPT much better programmer simply via brute-force approach:
1) ask it to generate (positive and negative) test cases first
2) ask it to review the test cases it wrote to make sure they fit the spec
3) ask it to produce an architecture of the program you want (you need to specifically ask it for writing modular code, consisting of small testable functions), fitting spec and test cases
4) ask it to write the tests for each function
5) ask it to find mistakes in the functions it wrote
6) run the functions against tests it wrote and present to it failures, asking to fix them (loop here until fixed)
7) run the e2e tests it wrote at the beginning and present mistakes to it, asking it to fix them
8) run the whole process in parallel multiple times, until one of them works
It's not pretty, it's not cheap and it's not super robust, but neither is the code written by majority of programmers. And I'm sure you could make it understand the code even better using some kind of evolutionary algorithms, by letting it play with interpreter.An example requesting the 'public_repo' scope (the client_id is a random one from the internet): https://github.com/login/oauth/authorize?client_id=33a703d01...
Clicking dropout shows that permission is r/w not just r/o, but does not mention stars either.
[1] public_repo: Limits access to public repositories. That includes read/write access to code, commit statuses, repository projects, collaborators, and deployment statuses for public repositories and organizations. Also required for starring public repositories. (https://docs.github.com/en/developers/apps/building-oauth-ap...)
That might have changed now, but I still can't find an official repo. You could look for older versions like this: https://github.com/robimarko/routeros-GPL or try to contact them directly (or sue if you think you have a standing).
This low-tech "attack" would also work even better with WhatsApp and Signal (better because in Telegram secret chats don't get shared between multiple devices while in WhatsApp and Signal they obviously are - cause every chat is encrypted).
(disclosure: I work for Doyensec)