• Zamboni_Driver@lemmy.ca
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    6
    ·
    4 days ago

    This doesn’t seem that bad to be honest. Disclosing they the access happened and what vulnerability allowed it to happen is a responsible course of action.

    • TDCN@feddit.dk
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      3 days ago

      I’m not sure why you are getting down voted so much instead of actually engaging with your post. I think you are right about that the disclosing is the right thing to do, but i believe that the problem people have with this whole AI hacking and disclosing is the intent behind the hacking. A white hat hacker has a clear intend to help discover and responsibly disclose the issue, maybe even for a bounty, giving an indirect permission to white hat hacking. On the other hand, AI does not have a clear intend behind the hacking. Very often it’s accidental and done irresponsibly like a “woopsie doozy, sorry we just broke in, we didn’t mean to, and we are not really sure what files were accessed but pinky swear we think we did no harm 🫣🤗” that is at least my take on this and why I think is very problematic. AI can still be used responsibly as a tool by a white hat hacker under strict supervision to discover zerodays but that is a whole other discussion on how you make sure its not going rouge.

    • gian @lemmy.grys.it
      link
      fedilink
      English
      arrow-up
      7
      ·
      3 days ago

      Only if you have a written authorization from the company you try to attack.
      Else they are nothing better than a criminal hacker.

      • Zanacross@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 days ago

        I don’t feel like many white hat hackers get permission to exploit these vulnerabilities to report them

        • gian @lemmy.grys.it
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          3 days ago

          They get permission when they do it professionally or as a company. Else it is a crime anyway.

    • Pyr@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      3 days ago

      The response isn’t terrible, but the fact that it happened in the first place is ridiculous. They don’t state anything about fixing the issue on their end so it doesn’t happen again. They also don’t apologize either or admit that they fucked up, they frame it almost as if they are doing them a favour and should be grateful.