‹ BackHN Continuity

Thread

CrowdSec Source Code Leak

160 points · 57 comments · eccgecko

  1. mewse-hn · · focus · HN ↗
    Funny to see this after I spent the morning troubleshooting and fixing my crowdsec install on my debian 13 vps. Apparently they stopped supplying a community blocklist to my machine because I'm running the old debian packaged version instead of directly from them (http 500). I had a LLM build a blocklist from publicly available sources rather than tie myself more tightly to their SaaS platform.
    1. idiotsecant · · focus · HN ↗
      I feel like a massive blocklist is simultaneously exactly the kind of thing an LLM is likely to hallucinate and exactly the kind of thing you don't want to rely on an LLM for.
      1. antonvs · · focus · HN ↗
        Modern agent harnesses rely heavily on tools, as well as writing code, to avoid hallucinations affecting deterministic values.
        1. shakna · · focus · HN ↗
          Which means it'd be a lot cheaper, to use tools, and public sources, and just automate it the traditional way...
          1. KetoManx64 · · focus · HN ↗
            I'd rather spend the $0.50 in API credits than waste a couple hours of my time. How much is your time worth?
            1. shakna · · focus · HN ↗
              Well, it'd cost me about 10 minutes, and it wouldn't delete half my data. So... How much is your infrastructure worth?
              1. KetoManx64 · · focus · HN ↗
                My infrastructure is build from a git ansible repo that I tear down and rebuild regularly, so $0.
                1. shakna · · focus · HN ↗
                  Did you take that time into your account of costs as well?

                  You're already using automation tools. Seems like you just don't... Want to learn... The tool that would save you hours of frustration, tomorrow or the day after.

                  1. KetoManx64 · · focus · HN ↗
                    It won't. And there is no reason to learn the intricacies of every little script that is written because there is not enough time in the day for that. If the script fails you feed claude the logs and tell it to fix it while working on the things that I actually enjoy working on and matter in the long run.
                    1. shakna · · focus · HN ↗
                      Well, as it wouldn't be a script, congrats on already losing the skills you would need, to assess whether or not what you set out to do is actually accomplished.

                      And as we're discussing a security tool... Love to see how you judge it as something that doesn't matter in your stack. Incidentally, mind offering me your IP range?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.