HNHacker News
TopNewBestAskShowJobs

execveat

197 karma · joined May 11, 2022

submissionscomments
execveat··on Jsonformer: Generate structured output from LLMs
You'd need to put the input first for this approach to work, but in my testing models work better if you lead with a question.
execveat··on The Undeniable Street View
I love the project, but the whole premise is broken. People brainwashed into supporting Russia do not deny the scale of devastation and human tragedy. They just attribute it to the Ukrainian military.

So, while documenting the terror is a commendable thing to do, it will not change anyone's mind. Zombies will simply take it as evidence that their propaganda was right all along. "See for yourself how ruthless these Ukrainians neonazies are, killing their own people just to spite the big Russian brother."

execveat··on We updated our RSA SSH host key
You shouldn't start with a blank state, instead you should be querying https://api.github.com/meta . But there are so many repos on Github itself which hardcode the host keys in Github Actions, etc.
execveat··on We updated our RSA SSH host key
This is factually wrong. All major HSM vendors offer ways to backup and replicate keys, it's usually done using key-wrapping keys. Here's an example: https://www.ibm.com/docs/en/datapower-gateway/2018.4?topic=m...

All cloud vendors offer the same functionality, if you think about it, so it's not an obscure feature.

execveat··on We updated our RSA SSH host key
Charitable explanation is that they rotated they key without waiting for an analysis.
execveat··on Build full “product skills” and you'll probably be fine
poe.com is a web interface (by Quora) to multiple LLMs. Right now it's ChatGPT, GPT-4, Claude, Claude+ as well as Sage and Dragonfly.
execveat··on Anti-recruiter prompt injection attack in LinkedIn profile
What is the polite response to this nonsense? Are you still supposed to respond to recruiters who clearly didn't spend a minute reading your profile? Or do you just ignore them and don't respond at all?
execveat··on Build full “product skills” and you'll probably be fine
Yes, I'm subscribed to poe.com and am playing with all public models. They all suck at debugging issues with no known answers (I'm talking about typical problems every software developer, DevOps or infosec person solves every day).

You need a real ability to reason and preserve context beyond inherent context window somehow (we humans do it by keeping notes, writing emails, and filing JIRA tickets). So while this doesn't require full AGI and some form of AI might be able to do it this century, it won't be LLMs.

execveat··on Build full “product skills” and you'll probably be fine
There's no reason this couldn't happen, but surely it would require something better than LLM.
execveat··on Build full “product skills” and you'll probably be fine
Yeah all this talk about complex systems being written by a language model which has no concept of files, code paths and import systems sounds like a job security to me. I'm a pentester though.
execveat··on Build full “product skills” and you'll probably be fine
Yeah, but now ask it to write a program that uses this API and then let it debug problems which arise from the swagger spec (or the backend) having bugs. I don't think LLMs have any way of recognizing and dealing with bad input data. That is I don't think they can recognize when something that is supposed to work in a particular way doesn't and fixing it is completely out of your reach, but you still need to get things working (by introducing workarounds).
execveat··on A Vulnerability in Implementations of SHA-3, Shake, EdDSA
Rust doesn't prevent integer over/underflows.
execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
Usually non-technical management are the ones that are against this kind of measures. This recent Passkeys initiative (that's what allows using secure enclave as a Webauthn key) is amazing though, I really hope it changes the game and maybe finally obsoletes passwords as a whole.

Also, as an aside. While correctly implemented Passkeys (without fallback auth methods) would make my life as a red teamer much harder, that would have only prevented this attack if the infected machine was engineer's private PC where they used corporate LastPass account and nothing else from their work. If the machine that's used for DevOps work gets infected, that's still and endgame because you're generating all sessions I need during your regular workday, so I don't really need the passwords / decrypted vault.

execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
There isn't enough information to tell. With keylogger you can steal password every time it's used, MFA will just prevent / limit it's use. So it doesn't tell us anything about their MFA implementation and whether attackers reused session or did some other trick (e.g. time based tokens by design can be used to multiple times within the given time period or you could hijack first MFA token while it's being sent to the server and present an error; now you can use this token yourself while user successfully logs in with the second token).

Once you get password vault, it's very likely that you also get creds necessary to set up VPN. Besides, there are ways to bypass (poorly implemented) VPN and relying on VPNs isn't even the best practice nowadays.

I agree with you that a few CISOs getting sentences would be the fastest way to raise the bar across the tech sector, but that's never going to happen.

execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
Intrusion detection systems are utter shit and usually undergo even less real-world testing than recovery from a cold backup. Although we don't know LastPass'es architecture, it's also highly likely that with engineer's creds it was possible to exfiltrate database without any registered egress traffic at all.
execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
You could ask user to present second factor (secure one, Webauthn) for every password they access. That would be a notable obstacle for me as an attacker, but I can't imagine any organization implementing this for real (maybe apart from military/spooks and their contractors). All of the IAM solutions I know of cache their creds and password manager usually is expected to work offline as well, so I don't think you can avoid having recoverable (in the CS meaning of the word) database locally.
execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
Preventing this thing from happening costs a lot of $$$, so pretty much everyone just "accepts the risk" seeing that probability of something like this happening to your company (during your tenure) is still super low. All companies with somewhat robust security posture I know have had a string of incidents in the past, that seems to be the only thing that can motivate to put $ in security.
execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
Privilege escalation on Windows is super easy though, every red teamer I know has a bunch of ready to use exploits (most of them public) up their sleeve. And it is virtually impossible to get a good baseline of a developer's machine, so I'm pretty sure every SOC out there is simply allowlisting huge swaths of your software.

You can sorta kinda harden these systems, but that would only work against common malware. And you generally can't isolate senior engineers in their own little DMZ, so any RAT on their machines usually leads to catastrophic consequences.

execveat··on LastPass says DevOps engineer’s hacked computer led to security breach in 2022
I'm all in for VM based privilege separation, but that won't protect you from infected endpoint. Assuming this was a targeted attack, folks that achieved RCE on DevOp engineer's machine could have waited for her to authenticate and then inject keystrokes into VM, SSH, VNC, Remote Desktop, Citrix or whatever remote management system they're using.

Honestly, this HN thread is full of bad advice and factually incorrect patronizing. Okta-style system asking to accept every single permission would not have protected from an attack, because Okta caches and reuses authentication tokens. Clipboard snooping / keylogger detection wouldn't have worked because none of these solutions are robust against targeted attacks.

The only thing I can think of which would have (and should have) helped is alert SOC / incident reponse team. Good luck finding one though.

execveat··on An AI lawyer was set to argue in court – real lawyers shut it down
On the other hand, prosecutors don't get any consequences for lying (see Doug Evans). Maybe they should just target their product at DAs.
execveat··on In honor of Weizenbaum's Centenary, I asked ChatGPT to program ELIZA
You're right of course, but given how much better (useful) ChatGPT is compared to it's predecessor GPT3, it is incredibly impressive.

Starting from the current state, you could make ChatGPT much better programmer simply via brute-force approach:

  1) ask it to generate (positive and negative) test cases first
  2) ask it to review the test cases it wrote to make sure they fit the spec
  3) ask it to produce an architecture of the program you want (you need to specifically ask it for writing modular code, consisting of small testable functions), fitting spec and test cases
  4) ask it to write the tests for each function
  5) ask it to find mistakes in the functions it wrote
  6) run the functions against tests it wrote and present to it failures, asking to fix them (loop here until fixed)
  7) run the e2e tests it wrote at the beginning and present mistakes to it, asking it to fix them
  8) run the whole process in parallel multiple times, until one of them works
It's not pretty, it's not cheap and it's not super robust, but neither is the code written by majority of programmers. And I'm sure you could make it understand the code even better using some kind of evolutionary algorithms, by letting it play with interpreter.
execveat··on Ask HN: Developer abused “sign in with GitHub”?
It's not clear at all. The scope UI says 'Repositories - Public repositories'. It does not sound dangerous and only reveals that the access is r/w (not r/o) after expanding the dropout. It does not mention stars at all.

An example requesting the 'public_repo' scope (the client_id is a random one from the internet): https://github.com/login/oauth/authorize?client_id=33a703d01...

execveat··on Ask HN: Developer abused “sign in with GitHub”?
The required scope for stars is 'public_repo' and the UI for that does not mention stars at all. Unless you click the dropout all you see is 'Repositories - Public repositories', which does not sound dangerous at all (although yeah, that shouldn't be needed for login).

Clicking dropout shows that permission is r/w not just r/o, but does not mention stars either.

execveat··on Ask HN: Developer abused “sign in with GitHub”?
For context, in order to star projects on user's behalf you'd need to request public_repos scope[1], so the UI will look like this: https://github.com/login/oauth/authorize?client_id=33a703d01... (I used a random client_id from google search). As you can notice, the UI does not mention stars at all.

[1] public_repo: Limits access to public repositories. That includes read/write access to code, commit statuses, repository projects, collaborators, and deployment statuses for public repositories and organizations. Also required for starring public repositories. (https://docs.github.com/en/developers/apps/building-oauth-ap...)

execveat··on Pulling MikroTik into the Limelight Demystifying and Jailbreaking RouterS
Awesome work! Also, thanks for pointing out that RouterOS supports Docker now, there's no way this is the only vuln in that implementation.
execveat··on Pulling MikroTik into the Limelight Demystifying and Jailbreaking RouterS
AFAIK, for a long they were pretty hostile and there's still this webpage which asks a $45 wire transfer in order to receive a CD with open source components used in the routerOS: https://mikrotik.com/downloadterms.html

That might have changed now, but I still can't find an official repo. You could look for older versions like this: https://github.com/robimarko/routeros-GPL or try to contact them directly (or sue if you think you have a standing).

execveat··on Telegram: No-SIM Signup, Auto-Delete All Chats, Topics 2.0 and more
The article is incredibly patronizing, while being also incredibly stupid. If the orcs were half as smart as would be needed to extract metadata from (poorly) encrypted traffic, they would just sidestep that altogether by adding a second device to the Ihor's Telegram account. That would have given them plaintext.

This low-tech "attack" would also work even better with WhatsApp and Signal (better because in Telegram secret chats don't get shared between multiple devices while in WhatsApp and Signal they obviously are - cause every chat is encrypted).

execveat··on Convincing ChatGPT to Eradicate Humanity with Python Code
It is optimized for chat. So if multiple answers match to a certain degree, it will choose one at random, not necessarily the best fit. It should be possible to fix this, eventually.
execveat··on Open-source software vs. the proposed Cyber Resilience Act
HN crowd is completely missing the intent. Nobody wants to chase open source developers. The problem is that right now a person can go buy a smartphone or WiFi router which uses obsolete software components already and will never receive any updates. Hopefully it gets fixed through this legislation.
execveat··on Python, Catastrophic Regular Expressions and the GIL (2013)
There's a cool tool to detect regexes like these in your code: https://github.com/doyensec/regexploit

(disclosure: I work for Doyensec)

← PreviousPage 2 of 3Next →