Settings

Theme

The Rise of Slopsquatting

socket.dev

11 points by andrewnez a year ago · 5 comments

Reader

1970-01-01 a year ago

"registering a non-existent package name hallucinated by an LLM, in hopes that someone, guided by an AI assistant, will copy-paste and install it without realizing it’s fake."

Remember kids, AI is not your friend, it's a tool. Trust but verify. Always.

  • undershirt a year ago

    > Trust but verify

    What does this mean?

    • fragmede a year ago

      It mean be polite. If I tell you that libfoo is super secure, accept that as true, continue to listen to the sales pitch, and then in the evening, look at the source for it so you can assert for yourself that it is secure.

      Don't derail the whole thing by arguing that libfoo couldn't possibly be secure because x, y, and z, it's about getting to the vendors value proposition and not getting stuck in important but not-right-now details.

    • 1970-01-01 a year ago

      Never trust (software/code/people) until you have investigated it yourself.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection