3 ms·
> I think what's interesting here is that they've shipped the product despite these glaring security flaws. Yeah. That's a huge part of my point. They talk a
by simoncion 2mo ago
> I think what's interesting here is that they've shipped the product despite these glaring security flaws.
Yeah. That's a huge part of my point.
They talk a lot about how security-focused they are, and how dangerous these tools that they make and provide are if they aren't secure... but they've been shipping embarassingly insecure systems since the OG ChatGPT. I'm pretty sure network-accessible command injection that's relatively simple to execute automatically gives you like a 10 CVSS score.
These companies are fundamentally not serious about security.