Post #3166139
2025-08-12 16:34 UTC
Replies (2)
-
@shafik@hachyderm.io 2025-08-12 16:50
@kevlin@mastodon.social apropos: https://embracethered.com/blog/posts/2025/claude-code-exfiltration-via-dns-requests/ Prompt injection through LLM allowing data exfiltration via DNS 😱 Surely state actors are working day and night looking for these issues and I am sure they have found plenty and are already exploiting them given how many folks are blindly using these tools w/ obviously bare or no code review at all. The near universal lack of skepticism around these products has to be one of the biggest gift to black hats in a long long time.
-
@kevlin@mastodon.social 2025-08-12 16:55
@shafik@hachyderm.io Indeed. There are a number of curves in play: what the tech can do; what developers can do; what developers actually do; what the hype says they can do. The hype curve is the most extreme of these. Would be nice if it settled down and starting converging with the reality of the other curves.