Remix.run Logo
athrowaway3z 4 days ago

Well this is rather dumb to the point I dont understand why they wrote this article?

This line of attack is so extremely obvious and variants of it have been discussed so many times as to be effectively the quintessential example of what not to do. Having the ?tech? consultants to a bank prance it about as a show of their skill and dedication is making me question the bank itself.

dgellow 4 days ago | parent | next [-]

It’s a case study. Why wouldn’t they present work they’ve done for a customer?

athrowaway3z 3 days ago | parent [-]

Oh i maybe was a bit too short worded. I meant specifically that they framed this as if they discovered a previously unknown class of bug and are now sharing it with the world to help save us.

I liked that they shared it - but the tone was all wrong. It wasn't an unknown type of attack and the fact that (they're presenting it as if) neither the bank nor they knew about it before hand makes both look bad.

There's not really a great way to write that blog post and make everybody happy, but if you had to i'd just not have named the bank and offer it as a case study of why this class of attacks needs attention.

JSR_FDED 4 days ago | parent | prev | next [-]

It’s a nice simple example of the problem. I will be using it to explain to my friends why they should not be using OpenClaw just yet.

gpvos 4 days ago | parent | prev [-]

https://xkcd.com/1053/