‹ BackHN Continuity

Thread

CrowdSec Source Code Leak

160 points · 57 comments · eccgecko

  1. mewse-hn · · focus · HN ↗
    Funny to see this after I spent the morning troubleshooting and fixing my crowdsec install on my debian 13 vps. Apparently they stopped supplying a community blocklist to my machine because I'm running the old debian packaged version instead of directly from them (http 500). I had a LLM build a blocklist from publicly available sources rather than tie myself more tightly to their SaaS platform.
    1. idiotsecant · · focus · HN ↗
      I feel like a massive blocklist is simultaneously exactly the kind of thing an LLM is likely to hallucinate and exactly the kind of thing you don't want to rely on an LLM for.
      1. antonvs · · focus · HN ↗
        Modern agent harnesses rely heavily on tools, as well as writing code, to avoid hallucinations affecting deterministic values.
        1. shakna · · focus · HN ↗
          Which means it'd be a lot cheaper, to use tools, and public sources, and just automate it the traditional way...
          1. KetoManx64 · · focus · HN ↗
            I'd rather spend the $0.50 in API credits than waste a couple hours of my time. How much is your time worth?
            1. shakna · · focus · HN ↗
              Well, it'd cost me about 10 minutes, and it wouldn't delete half my data. So... How much is your infrastructure worth?
              1. zamadatix · · focus · HN ↗
                Maybe you value the few cents (the .50c above seems more like a phrase than an actual value, that much actual cost would be the same as nearly a full days worth of a ChatGPT Plus subscription to combine some lists) over the 10 minutes but I'm not sure I follow why you'd give it access or control of half your data to pull data from public sources on the internet and give you a combined blocklist out of it?
                1. shakna · · focus · HN ↗
                  Our current models and harnesses have not been doing a fantastic job, of keeping things confined... The harness defaults to approving random commands, meaning if the model goes for the data, it tends to find the data. And a delete all before replacing it is fine, right?
                  1. zamadatix · · focus · HN ↗
                    The sources are public lists on the internet and the result is a combined file you click to download, none of this requires the agent even run on your PC if you don't trust your sandboxes - you can hope the agent deletes OpenAI's cloud instead (even though that's never happened with a billion weekly users).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.