Can we stop a bit this all evil Microsoft fault?
And the author have a solution. Yeah those headline are buzzing.
114 karma · joined January 24, 2025
Can we stop a bit this all evil Microsoft fault?
And the author have a solution. Yeah those headline are buzzing.
Don't understand here the parallel.
Over a year ago had a lot of issues and the description and example was the difference between 30-50% failure to 1%!
So I'm surprised a bit about the point. May be I'm missing it.
But I like the idea and principle. OSS need this and it's traded very lightly.
Chat apps, are replacing a lot the old way we consume information and search. That is mostly made thru browser. So I see the vision is follow this transformation to keep market share and offer an alternative to big players.
Mozilla and Firefox loosing market share and revenue too and that could bite back.
It's like the last hype over using generative AI for trading.
You might use it for sentiment analysis, summarization and data pre-processing. But classic forecast models will outperform them if you feed them the right metrics.
Seem more heavy lobbying to get their US marketshare here rathar than looking for secure products.
Also the report from checkpoint over firmware used to attache EU, the malware is firmware agnostic. As it can be used for other hardware.
But the quality for the model. And it seem Grok pushing the wrong metrics again, after launching fast.
See the Alienware laptop flagged as 5090 while it's "GeForce RTX 5090 24 GB GDDR7" as laptops can't sustain the TDP and RTX XX90 full power. For AI an external GPU is less costly option.
If you expect one shot you will get a lot of bad surprises.
Also if you want it to pause asking questions, you need to offer that thru tools (example Manus do that) and I have an MCP that do that and surprisingly I got a lot of questions and if you prompt, it will do. But the push currently is for full automation and that's why it's not there. We are far better in supervised step by step mode. There is elicitation already in MCP, but having a tool asking questions require you have a UI that will allow to set the input back.
More seen as buzz article about how it could happen. This is very complicated to exploit vs classic supply chains and very narrow!
Again you likely use vscode. Are you checking each extension you download? There is already a lot of reported attacks using vscode.
A lot of noise over MCP or tools hypothetical attacks. The attack surface is very narrow, vs what we already run before reaching Claude Code.
Yes Claude Code use curl and I find it quite annoying we can't shut the internal tools to replace them with MCP's that have filters, for better logging & ability to proxy/block action with more in depth analysis.
I feel this is overly exagerated here.
There is more issues that are currently getting leverage to hack with vscode extension than AI prompt injection, that require a VERY VERY complex chain of attack to get some leaks.
2. AI workflow, to fetch external data and allow AI to do it need tools, so it can dynamicly fetch or you will need to grab the data and inject it in the context.
3. MCP is a transport layer, you can have tools without MCP. You bake them in.
I feel there is some points that are mixed up.