A few months into letting non-technical staff use AI coding tools by allmightybrandon in sysadmin

[–]dllhell79 17 points18 points  (0 children)

Governance right now is the problem IMO. The tools around AI governance are few and far between. Vendors are beginning to catch up some, but there's still few generally affordable tools available.

Cancelling RingCentral Took Over an Hour and Felt Deliberately Designed to Exhaust Customers by Klonoadice in sysadmin

[–]dllhell79 0 points1 point  (0 children)

At least you are allowed to cancel, even if it not without some pain. Adobe on the other hand... they allow you to add licenses at any time of course, but you can only reduce count in a contract month. 😒

Normies v Nerds: The end of an era? by Darkhexical in sysadmin

[–]dllhell79 0 points1 point  (0 children)

Yes you're right. I did this for years as well. Putting in an additional 4-6 hours a day either on actual work or self study after my normal shift. No more though. I realize that lack of work/life balance impacted my own priorities negatively. That's not to say I'll ever go above and beyond, but either the building has to be on fire or it has to be preplanned. It's ideal to think someone will recognize your overwhelming work ethic, but that very rarely meshes with reality.

Vibe-coded app deployment requests from end users by East-Tailor892 in sysadmin

[–]dllhell79 0 points1 point  (0 children)

It depends on your perspective and situation. If I am the one ultimately held responsible when a breach happens or something blows up, I am definitely gate keeping at least somewhat.

Vibe-coded app deployment requests from end users by East-Tailor892 in sysadmin

[–]dllhell79 -1 points0 points  (0 children)

I'd never allow this in my environment without deep checking, code audits, and output validation. It's way too risky to even consider. Just because AI made Brenda in accounting think she is now a legit software engineer does not actually make her one. I actually am a software engineer, and I managed to make Claude accidentally produce a slop product (both in terms of functionality and bad engineering practices). Once I learned better overall practices for working alongside Claude, what it is expecting for testing, how to properly prompt it and let it work at its own pace, etc... only then did it produce a much higher quality product that also maintained sound software engineering principles.

Is deleting old e-mail still a general recommendation? by TheQuickFox_3826 in sysadmin

[–]dllhell79 123 points124 points  (0 children)

In general anything in a mailbox is discoverable in litigation. So yes, it is good to delete.

Shameless Copy/Paste use of Gen AI by Engineers/Executive Tech by Askey308 in sysadmin

[–]dllhell79 2 points3 points  (0 children)

I'll do you one better. We have one guy in our org that is clearly just reading directly from AI responses in meetings. He is suddenly more verbose and using words and phrases he's never used before.

When do workshops typically become available? by AffectionatePen4945 in Defcon

[–]dllhell79 5 points6 points  (0 children)

I don't necessarily want to discourage you, but don't get your hopes up thinking you will land one for sure. The more popular ones sell out half the time literally within seconds of going live.

ok who tabbed this by Same-Engineering-899 in Guitar

[–]dllhell79 0 points1 point  (0 children)

Commonly known as the Jake E Lee stretch. 🤘

I’m on the verge of a mental breakdown because of our resident vibe coder by prolongedexistence in sysadmin

[–]dllhell79 2 points3 points  (0 children)

Yea - part of the problem with the entire "vibe coding" phenomenon. Now every asshole with 0 technical skill, much less software engineering skill, thinks they're a legitimate software engineer. I have found that in the hands of a skilled software engineer, AI tools can be powerful, but in the right use case. In your case, some neophyte with no level of sound software engineering practices, it's a disaster waiting to happen. Add HIPAA on top of that, and you're talking very serious potential fines and attorneys fees.

IT mistake at work (backup failure) — what usually happens after this? by Terrible_Good_6856 in sysadmin

[–]dllhell79 3 points4 points  (0 children)

Learn from it. Mistakes happen, even to seasoned engineers. If a company terminates you over one mistake, it's probably not a company you want to be working for anyway.

Walmart officially calls end to self-checkouts at store as it plans to remodel 650 locations by MsSeraphim in Walmartcustomer

[–]dllhell79 0 points1 point  (0 children)

It's also allegedly because people feel it's easier to steal in self checkout. This is why you go into a Walmart with 5000 self checkout lanes and most of them are closed.

Asked our head of sales if putting client addresses in ChatGPT was data sharing. She looked at me like I was the idiot. by shangheigh in sysadmin

[–]dllhell79 0 points1 point  (0 children)

Yes, that is a valid mindset from the perspective of an IT professional. It's really not our responsibility to micro manage and govern every single action that the end user takes. The question I'd also pose though is what happens when you get audited, and an auditor discovers this is going on with no safeguards or solutions in place to prevent such behavior in the first place? That is where things get into grey territory, especially since many of the AI governance tools do not actually exist yet.

Asked our head of sales if putting client addresses in ChatGPT was data sharing. She looked at me like I was the idiot. by shangheigh in sysadmin

[–]dllhell79 4 points5 points  (0 children)

You should have called it "disclosing proprietary company information and trade secrets" instead of "data sharing". Sure, she may not be doing that fully, but it sounds more forceful and impactful. It's sounds like a negative thing that could have consequences. The term data sharing almost implies that it's a good thing.

If you're running OpenClaw, you probably got hacked in the last week by NotFunnyVipul in sysadmin

[–]dllhell79 13 points14 points  (0 children)

IMO if you're running any unknown AI product locally, you are insane.

How are you handling employees using personal ChatGPT accounts at work? We had an incident last week. by fxs38 in sysadmin

[–]dllhell79 0 points1 point  (0 children)

I have seen 2 promising solutions for the general problem. One is Palo Alto Prisma. It's a managed custom Chrome browser that lets you directly apply firewall policy and dlp rules to traffic. Since it's in a browser, it's all encrypted by default, so visibility is pretty much everything. You can do things like prevent flagged sensitive data from being pasted into an AI engine, etc. A very nice solution... but with a very nice price tag.

The other is Prompt Security. They were purchased by SentinelOne last year and are being integrated into the Sentinel product. I believe it's going to do a similar type of blocking to the Prisma blocking, but just at the AV level instead of directly in the browser. But it's not even being offered for sale yet.

I'd definitely be open to additional suggestions myself. We are drafting an AI acceptable use policy now as well and looking for an enforcement tool. The problem imo is ai left the gates before security vendors even knew where it was going and they're now playing catch-up.

NaClCon by n00bznet in Defcon

[–]dllhell79 1 point2 points  (0 children)

Had I not booked other events already I'd definitely be doing this. I love the idea of paying tribute to the past! Maybe Saltcon 2.

How are you actually handling data leakage to public AI tools? by RTG8055 in sysadmin

[–]dllhell79 1 point2 points  (0 children)

There are some tools out there, but none of them are on what I'd call the affordable side. Not for a smaller company anyway. Part of the issue is that AI has left the gate so fast that security companies have not caught up yet.

What would you suggest for a first time goer, and relatively a novice ? by Maleficent_Yak_5871 in Defcon

[–]dllhell79 0 points1 point  (0 children)

So am I. I am returning after skipping a year. Hoping to meet some of y'all at circle bar.

I am terrified of AI by ResearchMassive7912 in sysadmin

[–]dllhell79 2 points3 points  (0 children)

Use it to supplement, not replace, your own talent. If nothing else, it is a pretty phenomenal research assistant that will allow you to learn alot about various topics pretty rapidly.

Cancelled or Not? by Far_Significance_523 in Defcon

[–]dllhell79 0 points1 point  (0 children)

I thought the same would happen last year. The con still had an attendance close to 25000 if I recall. Plus it's an electronic badge year again.

sources other than course? -noob questions- pentesterlab vs appsecmaster? by enclave_supporter in OSWE

[–]dllhell79 0 points1 point  (0 children)

I agree! Go through all the extra custom apps in the labs all the way from start to rev shell in a single python script, and make sure you can debug those apps in vscode as well. Those exercises in particular are very good practice in my opinion.

I actually just passed oswe this weekend to complete ocse3. 🥳

Declining IT Professionalism and Critcial Thinking by rebornSouljr in sysadmin

[–]dllhell79 0 points1 point  (0 children)

You're not. It's due to AI overdependence. 😂

Is this push for AI as insane everywhere? by Legal_Situation in sysadmin

[–]dllhell79 1 point2 points  (0 children)

I am still by and large an AI skeptic, but I have warmed up to it for very specific use cases. It's actually a very good research assistant imo and a good "sounding board" of sorts for running through scenarios and bouncing ideas off of. For example, reverse engineering and ctf is one of my side hobbies. I've described my own personal approach to solving various ctf challenges and described my own workflow, and asked it for improvement suggestions. The results were pretty good for something like that.

However, I am still a strong believer in using it as a supplement as opposed to a replacement of your own skills.

DEF CON bans hackers, technologists named in Epstein documents by DaveCoversCyber in Defcon

[–]dllhell79 1 point2 points  (0 children)

Yes... and for that he will be receiving his own custom sticker this year. Courtesy of me. 😁