7 ms·
Mercor says it was hit by cyberattack tied to compromise LiteLLM
- tazsat0512 6mo ago[dead]
- ashishb 6mo ago[flagged]
- notachatbot123 6mo ago[flagged]
- ashishb 6mo agoWhat makes you think that? Your cab see the commit history ~10% of code is written by agents. Rest was all written by me. Unlike other criticisms of the project, this one feels personal as it is objectively incorrect.
- bengale 6mo agoAll these commenters just yell AI about every post and comment on here now. They have a worse hit rate than a blind marksman.
- notachatbot123 6mo agoOops, sorry. Only had a look at recent commits.
- lmc 6mo agoDocker is not a strong security boundary and shouldn't be used to sandbox like this https://cloud.google.com/blog/products/gcp/exploring-container-security-an-overview https://cloud.google.com/blog/products/gcp/exploring-contain...
- ashishb 6mo agoCompared to what? Which one is superior? Running npm on your dev machine? Or running npm inside Docker? I would always prefer the latter but would love to know what your approach to security is that's better than running npm inside Docker.
- lmc 6mo agoRead this: https://kayssel.substack.com/p/docker-escape-breaking-out-of-containers https://kayssel.substack.com/p/docker-escape-breaking-out-of...
- ashishb 6mo agoSo the worst case is that you are back to running npm on your host. Right?
- dns_snek 6mo ago99% of this is inapplicable to this discussion because it's about misconfigurations. Escapes: - privileged mode (misconfiguration, not default or common) - excessive capabilities (same) - CAP_SYS_ADMIN (same) - CAP_SYS_PTRACE (same) - DAC_READ_SEARCH (same) - Docker socket exposure (same) - sensitive host path mounts (same) - CVE-2022-0847 (valid. https://www.docker.com/blog/vulnerability-alert-avoiding-dirty-pipe-cve-2022-0847-on-docker-engine-and-docker-desktop/ https://www.docker.com/blog/vulnerability-alert-avoiding-dir...) - CVE-2022-0185 (mitigated by default Docker config, requires miconfiguration of capabilities) - CVE-2021-22555 (mitigated by default Docker config, requires miconfiguration of seccomp filters) default seccomp filters in docker: https://docs.docker.com/engine/security/seccomp/#significant-syscalls-blocked-by-the-default-profile https://docs.docker.com/engine/security/seccomp/#significant... privileges that are dropped: https://docs.docker.com/engine/containers/run/#runtime-privilege-and-linux-capabilities https://docs.docker.com/engine/containers/run/#runtime-privi... --- I'll add this: Containers aren't as strong of a security boundary as VMs however this means that a successful attack now requires infection of the container AND a concurrent container-escape vulnerability. That's a really high bar, someone would need to burn a 0-day on that. The bar right now is really, really low - blocking post-install scripts seems to be treated as "good enough" by most. Using a container-based sandbox is going to be infinitely better than not using one at all, and container-based solutions have a much easier time integrating with other tools and IDEs which is important for adoption. The usability and resource consumption trade-off that comes with VMs is pretty bad. Just don't commit any mortal sins of container misconfigurations - don't mount the Docker socket inside the container (tempting when you're trying to build container images inside a container!), don't use --privileged, don't mount any host paths other than the project folder.
- nope1000 6mo ago> The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications. This is pretty funny. The leaked excel sheet with customers of Delve is basically a shortlist of targets for hackers to try now. Not that they necessarily have bad security, but you can play the odds
- _pdp_ 6mo agoI am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.
- sebmellen 6mo agoIt might feel like BS, and I'm inclined to agree with you because of the security theater aspect. (For example, Mercor had their verification done by what appears to be a legitimate audit firm.) But it's not useless. It still forces you to go through a very useful exercise of risk modeling and preparation that you most likely won't do without a formal program.
- jacquesm 6mo agoThe main use of these certs is to give people that actually want to do their job a stick to hit their bosses with.
- cj 6mo agoIf your goal is to maximize your posture against cyber threats, spending your time on SOC 2 compliance with Vanta (or similar) is a waste of time if you consider the amount of time spent compared to security gained. It's incredibly easy to get SOC 2 audited and still have terrible security. > forces you to go through a very useful exercise of risk modeling Have you actually done this in Vanta, though? You would have to go out of your way to do it in a manner that actually adds significant value to your security posture. (I don't think SOC/ISO are a waste of time. We do it at our company, but for reasons that have nothing to do with security)
- techpulselab 6mo ago[flagged]
- aservus 6mo agoThis is a good reminder that any tool handling sensitive data — even internal ones — needs to be transparent about where data goes. The assumption that SaaS tools protect your data is getting harder to defend.
- lukewarm707 6mo agoI use llms to read the privacy policies that are too long to read. They guarantee almost nothing, unless you go out of your way to get an sla
- Serberus 6mo ago[dead]
- susupro1 6mo ago[dead]
- devcraft_ai 6mo ago[flagged]
- Chepko932 6mo ago[dead]
- CafeRacer 6mo agoI am genuinely wonder if anyone have had success landing gigs at Mercor.
- bombcar 6mo agoThe way to get a gig at Mercor is to hack their LLM so that it inserts you as already hired.
- tankenmate 6mo agoGiven their AI "hiring / onboarding" process all I can say is; couldn't have happened to a nicer company.
- ffsoftboiled 6mo agoI know of a couple people. It was a pretty miserable experience.
- Adam_cipher 6mo ago[flagged]
- n1tro_lab 6mo ago[flagged]
- robshippr 6mo agoSecond major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.
- yieldcrv 6mo ago> SOC2 won't catch this Cybersecurity professionals and their certification treadmill crack me up because of this They get paid less, require more certifications to be marketable, all to simply show actual “computer wizards” where all the blind spots are
- fancy_pantser 6mo agoI am not disagreeing with your main point, but want to clarify that SOC2 is not an individual certification that a person achieves.
- jeremie_strand 6mo ago[dead]
- sharadov 6mo agoCould not happened to a more usurious company.
- arwhatever 6mo agoLinkedIn itself is far from great, but this seems like a good thread to share my LinkedIn tip of creating a job alert using a search query like rust embedded NOT lensa NOT jobot NOT alignerr NOT mercor NOT “crossing hurdles”
- cat-whisperer 6mo agoall leaks are tied together
- cindyllm 6mo ago[dead]
- signalflow 6mo ago[flagged]
- signalflow 6mo ago[flagged]