Rendered at 06:59:52 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
cpcallen 2 hours ago [-]
For anyone who, like me, wasn't sure what's going on in the linked, archived PR: this is Mythos attempting to socially engineer a malicious PR during a test run by the UK AI Safety Institute.
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
ncr100 2 hours ago [-]
I saw a contribution by this maintainer to another user who ALSO HAS 14.5k followers: https://github.com/yumiaura/myCat/pull/99 "yumiaura" and a preference for "my[APPNAME]" repo naming.
What is this?
Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?
0123456789ABCDE 2 hours ago [-]
yes, the github contributions heatmap is known to be open for manipulation. folks will use it to draw art by backdating commits.
if i have it right, only commits can be manipulated, other contributions should be safe — i don't know what is possible for orgs moving old discussion archives into github, see python's issues for reference
They're almost certainly not genuine accounts, maybe used for karma farming, phishing, social engineering, future malware distribution?
3 hours ago [-]
ncr100 3 hours ago [-]
Wait, who is the robot? Am I getting that right, someone in that thread is AI?
Erem 2 hours ago [-]
I…I think there are no humans in that thread. Maybe only sinan-can-demir.
mekael 2 hours ago [-]
I'm 99.9% sure that everyone is AI in that thread.
andai 2 hours ago [-]
What does this malware do? Who operates it?
charcircuit 23 minutes ago [-]
Honestly, I expected better social engineering. People begging to have their garbage code merged or unrelated people commenting is not new and makes me trust such people little.
Yeah, if this is the new normal I might start day drinking at some point in the coming weeks.
matheusmoreira 47 minutes ago [-]
Yeah. The future is pretty bleak. I feel like the only way for us to even stand a chance is to have equally powerful AIs running locally defending the LAN.
AISI has published a report about the incident which was preciously discussed on HN: https://news.ycombinator.com/item?id=49175717
Any chance I can ask it to social engineer to get a normal style?
Both the attacker and the target account are very similar and look fake/bots.
What is this?
Are the histories that Github presents all derived from someone's uploaded git repo .. e.g. can I simply claim to have created a GIT repo in 1970, and the "github commit graph" will dutifully represent this claim in its green-colored activity graph?
if i have it right, only commits can be manipulated, other contributions should be safe — i don't know what is possible for orgs moving old discussion archives into github, see python's issues for reference
see: https://github.com/dspinellis/unix-history-repo