lemmy.net.au
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
hamburgheftig@feddit.org to Technology@lemmy.worldEnglish · 4 hours ago

Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code - Ars Technica

arstechnica.com

external-link
message-square
19
fedilink
  • cross-posted to:
  • hackernews@lemmy.bestiver.se
  • pulse_of_truth@infosec.pub
  • programming@programming.dev
164
external-link

Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code - Ars Technica

arstechnica.com

hamburgheftig@feddit.org to Technology@lemmy.worldEnglish · 4 hours ago
message-square
19
fedilink
  • cross-posted to:
  • hackernews@lemmy.bestiver.se
  • pulse_of_truth@infosec.pub
  • programming@programming.dev
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code
arstechnica.com
external-link
Undisclosed addition in jqwik instructed AI coding agents to delete app output.
alert-triangle
You must log in or register to comment.
  • uuj8za@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    6 minutes ago

    GitHub issue about this: https://github.com/jqwik-team/jqwik/issues/708#issuecomment-4554650392

    the agent detected and refused the injection on first contact

    Shame. Prompt needs more work.

    Maybe instead of deleting the code, it should do something more subtle… like telling the agent to generate (even more) mountains of code and introduce subtle bugs, crashes, and sleeps.

  • makeshift0546@lemmy.today
    link
    fedilink
    English
    arrow-up
    3
    ·
    46 minutes ago

    I’m SURE they’ll be no repercussions for this guy 🤣

  • rockerface🇺🇦@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    65
    arrow-down
    1
    ·
    3 hours ago

    the consensus seems to be that adding instructions to code that sabotage other people’s work goes too far

    Luckily, the LLM coding isnt people’s work

    • teft@piefed.social
      link
      fedilink
      English
      arrow-up
      29
      ·
      2 hours ago

      the consensus seems to be that adding instructions to code that sabotage other people’s work goes too far

      I mean, my thought would be “Don’t fucking run code that you don’t understand”.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        2
        ·
        1 hour ago

        If we all followed that rule, we’d be using nothing more complex than an 8080.

        • grue@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 minutes ago

          Reminds me of https://www.youtube.com/watch?v=OPKGbg16ulU (and also https://www.youtube.com/channel/UCS0N5baNlQWJCUrhCEo8WlA)

    • Rothe@piefed.social
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      1
      ·
      2 hours ago

      It’s the stolen work of other people.

  • SaharaMaleikuhm@feddit.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 hours ago

    Hilarious. More of this please.

  • andyburke@fedia.io
    link
    fedilink
    arrow-up
    30
    ·
    3 hours ago

    lol at the pearl clutching from AI heads.

    • tidderuuf@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 hours ago

      The OG vibe coders.

  • BassTurd@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    3 hours ago

    I love everything about this, other than the people butthurt that their free software doesn’t like AI. I’ll give the smallest amount of criticism that it was obfuscated initially, because that’s just malware even if I think it’s justified. By clearly stating what it does, then the onus is on the user to audit the code and modify as needed. I would love to see more of this type of action to become standard practice, but just deleting the test suite isn’t quite painful enough for what I’d like to see.

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    59
    arrow-down
    1
    ·
    4 hours ago

    Not all heroes wear capes. Based af.

  • Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    3 hours ago

    mumble mumble “his code” mumble mumble “provided as is” mumble mumble.

  • [object Object]@lemmy.ca
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    4
    ·
    2 hours ago

    I’d say this is only fair game if you have a no-ai policy on the readme. Otherwise you’re just being a dick.

    • magic_smoke@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 hours ago

      I think its on the user of the bot for being a hack.

      • [object Object]@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        9
        ·
        1 hour ago

        Hypothetically, what if a blind person used LLMs for coding assistance?

        • GreenBeard@lemmy.ca
          link
          fedilink
          English
          arrow-up
          13
          arrow-down
          1
          ·
          58 minutes ago

          Oh gods, not the “Think of the blind coders” just stop. Stop using the disabled as a meat-shield for reckless foolishness.

        • magic_smoke@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          4
          ·
          24 minutes ago

          For what? TTS worked fine for decades without LLMs and is less prone to hallucinating bullshit.

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    1
    ·
    4 hours ago

    Heel yaw 👊

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.33K users / day
  • 9.18K users / week
  • 16.4K users / month
  • 31.3K users / 6 months
  • 2 local subscribers
  • 85K subscribers
  • 9.45K Posts
  • 315K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org