The strongest Ai users usually do not win because they have magical prompts.
They win because they manage (scope , context , state , verification and decisions)
One thing I don't see people discuss about the case of OpenAI and Hacktron is the fact that a linked LLM account is effectively bypassing all your 2FA and Zero Trust corporate candies.
I have a hard time even assuming that OpenAI is not enforcing 2FA and access controls to their Github, or not enforcing common restrictions. If that's the case, then they have a more serious problem than an RCE.
But the gap is the fact that, nowadays popping an employee's OpenAI, Claude, ... account one way or another, is the equivalent of a browser universal XSS and bypass of all other layered defense. Which is hilarious and eye opening at the same time.
It's a reminder about how (NOT) to happily linking everything to your ChatGPT or similar agents without any guards around them, personal or corporate, and hope that nothing will fall between the cracks. Also worth noting that LLM agents, as a software product and subsequently their threat-model and security, are still immature as fuck!
@AshkanRmk هوش مصنوعی قرار نیست متخصصها رو حذف کنه
قرارِ آدمهای بیمهارت و کارهای بیارزش رو حذف کنه.
کسی که واقعاً بلده با AI قویتر میشه و
کسی که چیزی برای ارائه نداره جایگزین میشه.
@ArgosXAI Exactly
And that’s the scary part.
You can’t prompt an AI to check for a class of vulnerability you don’t even know exists.
At some point security stops being about generating code and becomes about knowing what questions to ask.
AI makes coding faster.
But what happens when the developer’s understanding doesn’t scale with the code?
Vibe coding could turn small knowledge gaps into large security vulnerabilities.
Are we creating better developers
or
just faster ones ?!
@Pizza__Geek دوتا فاز پیش رومون داریم.
فعلا فاز اول این شکلیه که بیشتر انتظار میره مهندس ها معماری رو هندل کنن و کنترل جریان پروژه رو به دست بگیرن و نظارت داشته باشن.
فاز بعدی به همین هم نیازی نیست.
باید ببینیم به شکلی تغییر میکنه.