getFrog

joined 1 year ago
[–] getFrog@piefed.social 1 points 37 minutes ago

This is the sign I needed to call in sick for the next few days. This shit is so tiring.

[–] getFrog@piefed.social 15 points 3 days ago (9 children)

For anyone else wondering: It's some sort of ergonomic mouse thing

[–] getFrog@piefed.social 8 points 4 days ago (1 children)

An incident involving an over-scoped API token too, interesting. I'll definitely be relaying those articles to the Teams chat tomorrow morning ~~(although the chances of anyone reading them when there's no subway surfer footage playing next to the text is pretty low)~~

[–] getFrog@piefed.social 11 points 4 days ago

Well they sound like a results-driven innovator who doesn't let unnecessary processes get in their way. I'm surprised my company's recruiters haven't already hunted them down and offered them a position as head architect.

[–] getFrog@piefed.social 22 points 4 days ago

Oh, I definitely am! Although plan A is to find a new job before this one implodes, but the chances aren't great because the market for software engineers is in a bit of a slump rn and I'm pretty picky about not working for unethical/enviromentally destructive causes 😮‍💨

 

..of how little any of my coworkers seem to care about the security implications of the stupid ass ai tools. They treat me like I'm crazy to suggest that maybe Claude shouldn't be able to read their Artifactory/npm token because we still don't have granular permissions on those and every token has publish permissions. ugh.
They literally have to go out of their way to give Claude access to that file too, and the only benefit is that it can run an npm install all by itself (absolutely stellar idea with the influx of npm supply chain attacks we're having).

Or when I suggest that maybe it's not a great idea to give Claude a git token with full write permissions to all repos, because commiting things from outside of the Claude terminal isn't even that much of a hassle. I'd get taking some security shortcuts if there was any actual benefit, but this is just so unnecessary.

And any time I point at any of the crazy security flaws the one mega-annoying coworker that vibecodes everything goes "uuhh no it's pointless to make the AI more secure because regular developers have a lot of permissions too and an angry developer could do way more damage than the AI".
Trying my hardest to not take him up on that.

[–] getFrog@piefed.social 1 points 5 months ago

Print that header onto the dial in a monospace font and you've got yourself an extremely marketable product. Perfect thing to bring to a white elephant gift exchange at an IT Company!