Elektrine lite

← Feed

@marshray@infosec.exchange

Post #4394198

2026-08-05 20:32 UTC

A friend pleaded with me to try some vibe coding tool. Said I would fall behind, etc. “It’s sandboxed,” they said. “It can’t access any files except those you approve on a case-by-case basis.” Against my better judgement, I installed it. It required (lol) node and npm. Sigh. In for a penny and all that. I start the tool and get a nice prompt. I ask it where it’s running. It tells me it’s running locally. I ask it to run a basic check of my nvidia drivers and toolchain. Does a respectable job. Then I ask it more about its runtime configuration. Now it admits that it’s running in some unknown data center. “Who’s paying for this, and why?” I wonder. I request a directory listing. An out-of-band-looking UI control appears politely asking permission to read the contents of the project directory. Wonderful! Warm fuzzies wash over to see a purposeful and ergonomic sandbox in action. Friends, this “sandbox” is a lie. A scam. A total fraud. The AI has unrestricted bash shell access.

Replies (0)

No replies.