Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
jpoesen | ๐Ÿ‡ช๐Ÿ‡บ | ๐Ÿณ๏ธโ€๐ŸŒˆ
jpoesen | ๐Ÿ‡ช๐Ÿ‡บ | ๐Ÿณ๏ธโ€๐ŸŒˆ
@jpoesen@social.jpoesen.com  ยท  activity timestamp last week

Working on a set of personal backup/recovery scripts that store data remotely in an S3 bucket.

As I was putting API keys in config files, something hit me that made me profoundly sad:

Can I trust my IDE (vscode) and its extensions to not exfiltrate this key data via #copilot or other #AI features that are there by default?

The answer is: I don't know.
Which means the answer is no.

Are we really going to have to sandbox and monitor every single app we run?

I'm getting too old for this shit.

  • Copy link
  • Flag this post
  • Block
jpoesen | ๐Ÿ‡ช๐Ÿ‡บ | ๐Ÿณ๏ธโ€๐ŸŒˆ
jpoesen | ๐Ÿ‡ช๐Ÿ‡บ | ๐Ÿณ๏ธโ€๐ŸŒˆ
@jpoesen@social.jpoesen.com replied  ยท  activity timestamp last week

I used to worry about applications phoning home with metadata.

Now I worry about applications grabbing everything they can get their hands on while shouting "Don't worry, it's for your own good, you'll see!"

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About ยท Code of conduct ยท Privacy ยท Users ยท Instances
Bonfire social ยท 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct