Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web
https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/
90 points · 9 comments · view on lemmy.world
9 Comments
kreekybonez@sh.itjust.works · 13 pts · 130d
my company made one of these AI apps, and when I signed up I realized there was no email verification.
so, I made a fake user, with fake credentials, and an email that doesn't even exist, and it worked. oh, and it has default editing permissions, so I was able to change data in it.
it won't allow the use of an email outside of the company domain, but here's the kicker: there's a pop-up notification that tells you what domain to use.
it's been 3 weeks, and it hasn't been deleted yet.
Bluescluestoothpaste@sh.itjust.works · 2 pts · 130d
Fml people are so stupid. Claude tells you all these things you basically have to force it to make something so inanely insecure
Bluescluestoothpaste@sh.itjust.works · 1 pts · 130d
Oh wait they're talking about the vibecode platforms i think those are harnesses really, in which case yeah shame on the companies selling these insecure harnesses
Bluescluestoothpaste@sh.itjust.works · 1 pts · 130d
Hmm
Yeah, people are stupid so i believe this
s38b35M5@lemmy.world · 9 pts · 131d
Fixed link
haverholm@kbin.earth · 5 pts · 131d
Archived version?
Edit: asking in part because Wired always gives me the "you're out of free articles!" message, but also this link throws a 403 at the mo.
mrnngglry@sh.itjust.works · 3 pts · 130d
Someone posted a fixed link and it opens just fine in a browser with good ad blocking.
haverholm@kbin.earth · 2 pts · 130d
Thanks. I must have Saturday morning brain!
dumnezero@piefed.social · 1 pts · 130d
malpraxis