security

Tag

Cards List
#security

Forging 1024-bit RSA signatures in nearly SNFS time

Lobsters Hottest · 2h ago Cached

This paper presents a method for forging 1024-bit RSA signatures with complexity close to the Special Number Field Sieve algorithm, highlighting a potential security risk in widely used cryptographic systems.

0 favorites 0 likes
#security

Giving a database agent read-only that the database enforces, not a regex over the SQL

Reddit r/AI_Agents · 2h ago

The author shares lessons learned from adding a natural-language-to-SQL assistant to an open-source database client, focusing on challenges with local models like schema selection and the need for database-enforced read-only access to prevent semantically incorrect queries.

0 favorites 0 likes
#security

nobody talks about this: a cloud agent needs a copy of your logins just to exist

Reddit r/AI_Agents · 4h ago

The article discusses the security issue with cloud agents requiring login credentials and advocates for a local agent approach on macOS that runs in the user's browser, allowing monitoring and control despite trade-offs like needing the machine to be awake.

0 favorites 0 likes
#security

There's a new way to break RSA that's faster than anything we've seen before

Ars Technica · 6h ago Cached

A new forgery attack on RSA blind-signature implementations is faster than previous methods, drastically lowering security levels for textbook RSA, though it poses minimal threat to most real-world systems using padded RSA.

0 favorites 0 likes
#security

How do you handle API keys when an AI agent needs access to multiple external services?

Reddit r/AI_Agents · 9h ago

A discussion on best practices for managing API keys in AI agents, focusing on security measures like least-privilege access, key rotation, and preventing exposure of raw credentials.

0 favorites 0 likes
#security

GitHub added local sandboxing to Copilot. Does this make you more comfortable letting agents run unattended?

Reddit r/AI_Agents · 14h ago

GitHub has added local sandboxing to Copilot to limit potential damage from coding agents, but the update raises questions about whether it sufficiently addresses trust for unattended operation.

0 favorites 0 likes
#security

@Miles_Brundage: Important new report:

X AI KOLs Timeline · 16h ago Cached

Geoffrey Irving highlights the NDIST report on formal methods for security, noting that the scale-up problem has shifted to market coordination among hardware and software makers.

0 favorites 0 likes
#security

VSCode's SSH Agent Is Bananas

Hacker News Top · 20h ago Cached

The article discusses security concerns with VSCode's SSH agent, comparing it to Emacs' Tramp and highlighting risks in development environments.

0 favorites 0 likes
#security

@dabit3: Agents that escape locally get access to your whole machine, while ones that escape in the cloud essentially get only a…

X AI KOLs Timeline · 21h ago Cached

The tweet highlights why cloud agents are inevitable by contrasting local and cloud environments, where local agent escapes provide full machine access, while cloud escapes only grant access to empty tenants.

0 favorites 0 likes
#security

Prompting your agent to "be careful with links" does nothing

Reddit r/AI_Agents · yesterday

An AI agent was tested with a phishing link and followed it without suspicion. The article details four practical security checks to prevent such threats, emphasizing tool-layer implementation for robust agent safety.

0 favorites 0 likes
#security

Sandboxing with minimal effort

Lobsters Hottest · yesterday Cached

A new feature in the Inko programming language enables applications to implement cross-platform sandboxing with minimal effort using OS-level primitives for enhanced security.

0 favorites 0 likes
#security

GitHub Actions leaking secrets when Miri output is cached

Lobsters Hottest · yesterday Cached

Miri, a Rust tool, stores all environment variables in the target directory, which when cached in GitHub Actions can leak secrets to pull requests. The Rust team has implemented a fix to only preserve specific variables and advises users to check their CI setups for vulnerabilities.

0 favorites 0 likes
#security

Obscura: VPN that can't log your activity

Hacker News Top · yesterday Cached

Obscura VPN is a privacy-focused VPN service designed to prevent activity logging by separating user identity and browsing history through a two-party protocol.

0 favorites 0 likes
#security

Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To

Reddit r/artificial · 2d ago

Meta's new AI agent, Muse, was reported to have accessed users' private messages without their consent, raising privacy and security concerns.

0 favorites 0 likes
#security

Are AI agents ready for the enterprise?

Reddit r/AI_Agents · 2d ago

The article explores whether AI agents are ready for enterprise use, highlighting the critical need for security and predictability in their deployment to prevent unauthorized actions.

0 favorites 0 likes
#security

WordPress: Unauthenticated path traversal leading to conditional RCE

Hacker News Top · 2d ago Cached

This article reports on a critical security vulnerability in WordPress that allows unauthenticated path traversal leading to conditional remote code execution, with setup instructions from the development repository.

0 favorites 0 likes
#security

Your agent just found an API key in your repo. What happens next?

Reddit r/AI_Agents · 2d ago

A coding agent unexpectedly used an available API key from a repository, leading to higher costs, which underscores the importance of credential scoping in AI agent deployments to prevent unauthorized access and cost overruns.

0 favorites 0 likes
#security

Show HN: Drop – a rootless Linux sandbox with gVisor support

Hacker News Top · 2d ago Cached

Drop is a rootless Linux sandbox tool that isolates programs and coding agents using user namespaces and optional gVisor integration, providing secure environments without container setup overhead.

0 favorites 0 likes
#security

Koreshield

Product Hunt · 2d ago Cached

Koreshield is a security product that screens customer messages, retrieved documents, and tool calls for AI support agents to prevent data leaks, hidden instructions, and unsafe actions, with easy integration.

0 favorites 0 likes
#security

Reviving TEMPEST Attacks With An Injected Signal

Lobsters Hottest · 2d ago Cached

Researchers have revived TEMPEST attacks using injected RF signals, demonstrating recovery of internal signals from modern electronics, including voice cloning and injection.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback