4 ms·
Took the article pointing out that the c and r were transposed for me to even notice there was a problem!
by arjvik 1y ago
Took the article pointing out that the c and r were transposed for me to even notice there was a problem!
- SoftTalker 1y agoYep this is the sort of typo error I make probably 10 times a day.
- javchz 1y agoWhat it's funny it's that because tokenization there is a non zero chance a LLM audit may not see anything wrong here, similar to the strawberry problem.
- TobTobXX 1y agoNah, cr and rc are different tokens and LLMs would have no issues telling them apart. An older model might have trouble explaining that cr and rc are similar and can thus get easily mixed up, but the characters are probably more different to the LLM than they are to us.
- TehCorwiz 1y agoWhat about all that GitHub training data using the wrong domain? Even being a different token it’s still being trained as a correct value.
- echelon 1y agoThe problem here is GitHub's terrible domain name. The container registry has a horrible name.
- Gigachad 1y agoWhy does it seem companies hate subdomains so much? Why is this not just registary.github.com or something? It's like they are trying to get people to fall for phishing by creating so many random domains.
- zx8080 1y agoProbably, it's cool, and honored inside an org to operate a separate domain service vs go ask for a permission for a subdomain to another team.
- JdeBP 1y agoInterestingly, the GitHub doco says outright that it superseded docker.pkg.github.com. ; so it was a conscious choice to go with this domain naming scheme instead of that one. * https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-docker-registry https://docs.github.com/en/packages/working-with-a-github-pa...
- rconti 1y agoinsecurity through obscurity
- dcrazy 1y agoIt’s best security practice to host user-generated content on a separate domain to opt into browsers’ cross-domain security policies. Hence ghcr.io, githubusercontent.com, fbimg.com, etc. https://www.reddit.com/r/webdev/comments/lg9xnm/why_do_some_websites_have_a_separate_domain_for/ https://www.reddit.com/r/webdev/comments/lg9xnm/why_do_some_...
- usr1106 1y agoNot a web programmer, so know cross-domain only for hearsay :( It does not seem to hinder e.g. Google using google.com, youtube.com, gmail.com, and several (many?) others to collect your data. Do you say security and privacy work differently here?
- missingcolours 1y agoIn those cases, the company controls all of the code running on those sites, so it's desirable for them to share data and cookies in particular. (e.g. any google.com site can read your login cookie) In the case of user data domains, intentionally in the design of the service or via a security hole, users may be able to execute code and read cookies (e.g. in JavaScript on a page hosted on githubusercontent.com) and that's undesirable.