Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

OpenAI reported the Artifactory vulnerability, patched it, then the agents immediately found a new zero day.


Because of the architecture of Artifactory. It's design is premised on the idea it is bug free. What incredible hubris.

Licencing fee structures and human laziness motivates single instances. Feature growth results in multiple independent services in the same system. Delivering features quickly motivates lack of rigor, a complete absence of systematic security testing.

On the client side, valid fears about supply chain security are painted over with scanning so they can keep using nodejs and PyPI and moving quickly. Tools designed for humans are pressed into service as AI interfaces, but without human restraint they need rethinking.

A whole industry has been built on the idea of worrying about downside risk if it happens, and just not being the slowest in the pack. No one thought it could happen to everyone at once.


> Because of the architecture of Artifactory. It's design is premised on the idea it is bug free. What incredible hubris.

So we should stop using SSH? Because it's based on the same premise - that it is bug free.


I can think of better straw men. But if they had approached their task with half the seriousness of the openssh maintainers then they probably wouldn't be failing to check the return value of authentication functions.

OpenSSH authors have spent considerable effort separating concerns, reducing privileges, process isolation, etc. So I would say they have been planning for potential bugs. These techniques are very much absent from Artifactory.

https://vivianvoss.net/blog/technical-beauty-openssh


So you agree that you can have designs premised on the idea that they are bug free without this being hubris.

So the issue is with the actual Artifactory project/team, not with this premise which obviously you seem to agree that is not hubris for the SSH project.


Exactly the opposite of what I wrote. The OpenSSH team have taken extensive efforts to mitigate against bugs; they suspect themselves of erroneous thinking.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: