Good. More please.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
These companies presumably have one or two people that know how to use computers? When your business is data, how can you have such a fragile ecosystem?
That happens when you think you don't need experienced software devs any more, because the AI can do everything now. A seasoned developer/devOp/admin would have known that the production environment needs to have different credentials from staging and these need to be protected. If that is not possible with railway then it's simply not a good product to use and (again) a good dev/admin would have seen this in the initial evaluation phase. Not preventing AI access to the production environment from the start is the third grave mistake. However, there's none of it in the "lessons learned" section of the article. You have learned nothing and are bound to repeat your mistakes.
they have a third party hosting provider that keeps backups on the same storage volume as production? That right there is a whole other concern.
whoever decided that backups need to be directly tied to storage volumes needs to reevaluate hardcore. I see no reason to link it directly to storage volumes and deleting a storage volume should not delete the backups that are tied to that volume. That is a systematic flaw that was just waiting to be abused.
In this case, it was an AI agent "going rogue", but what if it was a hostile attacker that just decided they wanted to be malicious. deleting a storage volume, using an API key, should not delete the backups that are associated with that volume, Realistically, that should be a whole separate system, and you should be able to restore backups that are under your account to whatever volume you want to.
LLMs can’t ’go rogue’, as that would require innate coherence and intent.
They’re explosively imprecise, statistically luke-warm grey goo extrusion sphincters of historical sewage.
Anyone who deploys one without supervision deserves everything it excretes, and anyone impressed by it enough that it resembles intelligence is betraying their limited natural capacity.
I'll never happen to me. I ain't stupid enough to use this shit. I'm not stupid enough to make myself unneeded. But damn, a lot of fucking programmers who I'm sure make 100k+ a year, are stupid fucks working to put themselves on the street by using this shit.