Settings

Theme

The Rise of Slopsquatting

socket.dev

11 points by andrewnez 9 months ago · 5 comments

Reader

1970-01-01 9 months ago

"registering a non-existent package name hallucinated by an LLM, in hopes that someone, guided by an AI assistant, will copy-paste and install it without realizing it’s fake."

Remember kids, AI is not your friend, it's a tool. Trust but verify. Always.

  • undershirt 9 months ago

    > Trust but verify

    What does this mean?

    • fragmede 9 months ago

      It mean be polite. If I tell you that libfoo is super secure, accept that as true, continue to listen to the sales pitch, and then in the evening, look at the source for it so you can assert for yourself that it is secure.

      Don't derail the whole thing by arguing that libfoo couldn't possibly be secure because x, y, and z, it's about getting to the vendors value proposition and not getting stuck in important but not-right-now details.

    • 1970-01-01 9 months ago

      Never trust (software/code/people) until you have investigated it yourself.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection