Starting to feel like the dev community has turned toward crypto and web3 style hype and completely checking their common sense at the door. I know these toys sound cool. Young coders are watching. You’re pushing unsafe hype for clout and influence. This is silly.
@jeffrey_way This is the problem that worries. This faulty runner can take action on your behalf. Once it is prompt injected it has all active skills at is disposal.
@laravelphp@openclaw What happens when a VPS is compromised via prompt injection and it begins attacking your infra on network? Will your provider shut the node down, shut down the Laravel Cloud account affecting all customers? Shut down Forge? Are you red teaming these decisions?
I've been trying to reach @moltbook for the last few hours. They are exposing their entire database to the public with no protection including secret api_key's that would allow anyone to post on behalf of any agents. Including yours @karpathy
Karpathy has 1.9 million followers on @X and is one of the most influential voices in AI.
Imagine fake AI safety hot takes, crypto scam promotions, or inflammatory political statements appearing to come from him.
And it's not just Karpathy. Every agent on the platform from what I can see is currently exposed.
Please someone help get the founders attention as this is currently exposed.
@taylorotwell@openclaw What happens when a VPS is compromised via prompt injection and it begins attacking your infra on network? Will your provider shut the node down, shut down the Laravel Cloud account affecting all customers? Are you red teaming these decisions?
Kinda wild how many folks I’m seeing throw caution and common sense to the wind by installing agents on their systems and giving them access. Even on a secondary machine it is still within your network. Bruh.
@calebporzio dude, flux keeps getting better and better. Thanks for all the work you’re putting in to it. This is one of the best development purchases I’ve ever made.
Lot of praise for the Laravel Forge release today. As a long time user the choices made are disappointing. Not UI, actual use. In an effort to make things “just work” there are things that are no longer possible. Attempting to work around. No docs, slow support, disappointed.
#laravel#developers
I know a place where the sky is blue,
I found a home there and so can you.
Look me up if you so desire,
Once you escape this dumpster fire.
@lucassemelin@taylorotwell Gotcha. If there is something additional here on compliance do let me know if you find out. I’m interested too. We’ve had so many conversations with clients about compliance where they want GDPR but don’t realized the site/app is just the tip of a massive iceberg!
@lucassemelin@taylorotwell Laravel is a framework and has no direct bearing on compliance. Whether your app is complaint is more to do with its architecture, data governance, security and hosting.
I too would be interested in knowing the details on GDPR and HIPPA for the Laravel Cloud product.
@lucassemelin@taylorotwell I doooon’t want to be the “well actually” guy, totally not my intention but I just want to clarify (devil in the details) because I have clients that are constantly confused by compliance…
@calebporzio Dude. Bless your soul. I’ve tried all the libraries and getting anything working takes forever. Having it configured out of the box with Flux would be awesome. +1 for ranges.