We’ve heard it all a couple of times: “GenAI is replacing Software Developers”, Vibe Coding, … A C-Levels dream to (finally) get rid of expensive software developers by using AI.
(more…)Blog
-
AI Agents: Loyal Only to the Prompt
Recently I thought “If AI scrapers are scraping my website, would a prompt injection work? Just adding invisible Prompt commands …?”
And just today, a colleague sent me this link to an article about prompt injection in GitLab Duo: Remote Prompt Injection in GitLab Duo Leads to Source Code Theft:
TL;DR: A hidden comment was enough to make GitLab Duo leak private source code and inject untrusted HTML into its responses.
https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duoWell – it shows: damit! Someone else was faster! 😀
But besides that: it confirms a paranoid thought that I have been harboring for quite a while. Any output of an AI system must not be trusted blindly.
(more…) -
Torture for Bitcoin: When Crypto Gets Brutally Real
It’s one thing to know that each password can be stolen by kidnapping a person knowing the passwords and then “convincing” them to reveal it. But really reading that it (very likely) happened … feels strange.
I just read an heise article (Um Bitcoin zu stehlen: US-Kryptoinvestor hat wohl wochenlang Touristen gefoltert), citing an NBC-article (Crypto trader tortured Italian man in NYC home in bid to steal his bitcoin).
Oh well, that’s one of the services that traditional banks do. Making suchthings harder. Maybe not fully impossible, but harder than “enter password”.
-
Why “Open” may not Always be Enough
If you care about open source, open data, or open standards, you should read “What we in the open world are messing up in trying to compete with big tech“.
I found it a good critique on Open Source and why “technology” and an OpenSource Licence may not be enough to compete with BigTech players. The author doesn’t argue against OpenSource but he points some quite valid points.
You might say “look at your own GitHub repo first” but wait: The difference in my view is: Do you open-source something just to make it available for others as well or do you make an OpenSource project to compete with a commercial product / to position yourself as a valid alternative …
Anyways, give it a read – and maybe follow his Blog as well!
-
Buchempfehlung: Die Logik des Mißlingens
Eine Kollegin hat mir neulich ein Buch empfohlen: “Die Logik des Mißlingens, Strategisches Denken in komplexen Situationen” von Dietrich Dörner. Klang ja wie eine Anleitung für Projektleitung. Kurz darauf lag also eine leicht vergilbte second-hand Ausgabe davon auf meinem Tisch.
“Die Logik des Mißlingens” ist kein neues Buch – es ist von 1989, aber ein Thema, das zeitlos bleibt. Weil menschliches Verhalten zeitlos fehlbar ist und – wie ich glaube – sich die generelle Denkweise in nur 30 Jahren vermutlich kaum geändert hat.
(more…) -
Podcast: Warum Arbeit häufig Zeitverschwendung ist
Gerade von Kollegen empfohlen bekommen: eine Podcast Folge über Arbeit und Meetings. – Wird irgendwie nie alt.
(more…) -
How to check the Email Security Level of your Provider
If you’ve ever wondered which security protocols your email-provider supports, there is an easy way that I found via Mastodon:
The European Commision provides My Email Communications Security Assessment (MECSA) (https://mecsa.jrc.ec.europa.eu/) with which you can quickly check, which of the protocols your provider supports (StartTLS, x509 Ceerts, SPF, DKIM, DMARC, DANE, DNSSEC).
(more…) -
How to delete all content from LinkedIn
As I’ve written earlier, I’m going more and more away from LinkedIn (like here and here). During my #unplugTrump activity, I decided that I want to go a step further and remove all my content (posts, answers, likes) from LinkedIn. On Mastodon, I have auto-delete activated already for various reasons. Now I wanted to clean up LinkedIn, too!
(more…)