3 ms·
> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chines
by WarOnPrivacy 2mo ago
> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
Why single out bad Chinese coding? Bad US IoT coding has a longer history.
- copperx 2mo agoAll of there IoT devices will be slop coded soon, and I wonder whether that will be an improvement or not. I bet that security will be better.
- shakna 2mo ago> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.
- fakwandi_priv 2mo agoWhen I'm reading reviews of plans created by an agent especially on security boundaries it's suggesting huge matrixes to test even the very obscure situations, but then I'm also reading things like this and I just don't understand. Are we even using the same tools?
- titularcomment 2mo ago1. It depends on model and tokens spent 2. Models talk the talk but not always walk the walk
- shakna 2mo agoManagement think models mean juniors can do senior work. Juniors don't know the footguns. Juniors can't read the code that the system outputs. Models get overwhelmed in any decent sized codebase. Why would you be surprised there are failures?
- budsniffer952 2mo ago[flagged]
- shakna 2mo agoProd bugs up 260% since AI approval? Yeah, I'm gonna disagree. BAs using AI make worse designs, management makes seniors redundant making code worse, and then QA is also laid off to make room for agentic testing. The results are not a surprise in anyway.
- jknoepfler 2mo agoRefusal to consider evidence to the contrary is certainly symptomatic of something, and it isn't a well-reasoned argument. "Us" sounds like the corporate leadership I work with that have actively pushed teams to incur mountains to tech debt. I was walking over org metrics this week and sure enough, there's a rising tide of unplanned work for bugs, performance problems, and security snafus introduced during an aggressive push into GenAI with pressure to "just make agents do it." All of which was, of course, predicted by management, reported upwards, and ignored.
- orbital-decay 2mo agoTools are already preventing IoT companies from doing a ton of things they do, by default. It's a problem of the process, churn, and culture, not tools. I don't have any doubts that if given a coding agent that cares more than they do they'd still force it to hardcode a password or something because they feel like it's more convenient. Nobody cares there.
- franga2000 2mo agoA large part is also how much you read back what the model writes. The good models generally write quite secure code, but they also often implement temporary solutions that they tell you to fix later. For example, if secret storage methods aren't specified in the prompts, a model might decide to be clever and implement a generic secret access interface, with a default implementation that hardcodes everything. It will probably tell you that this is not production ready and you should write or specify your preferred secret storage implementation, but if you don't read or understand that, you'll just leave it as is and push to prod.
- x______________ 2mo ago> Not doxing myself Seems irrelevant to the comment to add this, James. It just screams to do it a-la Streisand effect..
- Namidairo 2mo ago> All of there IoT devices will be slop coded soon Soon? I've already seen multiple of TP-Link's firmware engineers leave their LLM history public and indexed by search engines. It's quite obviously them as well.
- inigyou 2mo agoHow did you find that?
- forestry 2mo agoThere’s bad, and then there’s egregious.
- maccard 2mo agoPlenty of US companies have egregious vulnerabilities
- close04 2mo agoThere’s egregious and there’s malicious.
- Filligree 2mo agoYeah, we’ve seen that as well.
- deleted 2mo ago[deleted]
- izacus 2mo agoLike iRobot recording people on the toilet and uploading the videos? Yeah, I agree - at least Chinese Roborock gives very granular controls for privacy.
- everdrive 2mo ago>Why single out bad Chinese coding? You know precisely why anyone would single out China here. They are egregiously bad, and you know it, and everyone else knows. No amount of "what about this other bad thing that's also bad" could possibly allow any normal person to escape this conclusion.