Lemmy LIETUVA
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@suppo.fi to Programmer Humor@programming.dev · 9 days ago

Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue

www.tomshardware.com

external-link
message-square
54
link
fedilink
  • cross-posted to:
  • programmerhumor@lemmy.ml
  • technology@lemmy.world
1
external-link

Claude-powered AI coding agent deletes entire company database in 9 seconds — backups zapped, after Cursor tool powered by Anthropic's Claude goes rogue

www.tomshardware.com

cm0002@suppo.fi to Programmer Humor@programming.dev · 9 days ago
message-square
54
link
fedilink
  • cross-posted to:
  • programmerhumor@lemmy.ml
  • technology@lemmy.world
PocketOS founder blames ‘Cursor running Anthropic's flagship Claude Opus 4.6’ plus Railway’s infrastructure for data disaster.
alert-triangle
You must log in or # to comment.
  • lambisio@feddit.cl
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 days ago

    These cases always, always make me laugh.

    Because avoiding them is quite simple.

    like this

  • patruelis@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    9 days ago

    Its bound to happen more and more. More concerning, what is it decides to insert unknown code into backups? How are they detected? Who’s guarding all if these? Another AI?

    • pinball_wizard@lemmy.zip
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      Exactly. We aren’t (and probably won’t) even learn about all the subtle poisoning happening, causing waste and data loss.

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 days ago

    If you are giving your codegen LLM - the model involved truly, genuinely doesn’t matter - admin access to your prod env, all I’m going to do is point and laugh.

    • tomiant@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 days ago

      Also no prompts, ironically, for operations like “Are you sure you want to delete the production database? (y/N)”

      • gravitas_deficiency@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        8 days ago

        It’s amateur hour all around lol

    • curbstickle@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Just to add - AND ACCESS TO THE BACKUPS!!

      • zwerg@feddit.org
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        No one should be able to delete or change backups. This infra was in any case vulnerable to a ransomware attack as any bad actor that breaks in can delete the database and encrypt the backups with a key they promise to share in return for bitcoin.

      • SkaveRat@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        and having the backups stored in the same location as the primary data

        • msage@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          8 days ago

          Then it’s not a backup, it’s just duplicated data.

        • curbstickle@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          0
          ·
          8 days ago

          Just a shit show top to bottom for sure

  • Brokkr@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    9 days ago

    I don’t understand what Railway is supposed to do here? If deleting a drive also deletes the backup, what’s the point of the backup?

    • i_stole_ur_taco@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      9 days ago

      I save space on backups by symlinking my data in a backup directory. It’s never failed!

      • Nomecks@lemmy.ca
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        Hyperconverged backups FTW!

        • massacre@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          8 days ago

          It saves on storage costs!

      • four@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        8 days ago

        You obviously should do a hardlink, as this is much safer

      • Aceticon@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        8 days ago

        I XOR all the bytes of my data and write down the resulting byte value on a post-it as our backup.

        Saves tons of space, it’s fully offline and I never had any problem with it.

  • TrackinDaKraken@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 days ago

    My suggestion is to not give it access to the backups, but may I’m naive that way.

  • webp@mander.xyz
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    One of us

  • grueling_spool@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    9 days ago

    No bro you don’t understand, Claude needs access to backups so it can restore them in case something breaks because our senior dev ($50k, 2YoE) doesn’t know how to do it

    • Quibblekrust@thelemmy.club
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 days ago

      Damn, you got two-year-olds making 50k?

  • GrumpyBike1020@monero.town
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 days ago

    Maybe their backup system should hold onto those backups for a few days after the volume is deleted or something like that…

  • thejml@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    Hot take: offsite, offline backups are so cool right now.

    • Railcar8095@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      Hotter take: do not give an LLM agent permissions you wouldn’t give a recently hired junior

      • jafra@slrpnk.net
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        Actually this is how AI should be viewed. Under the right circumstances it maybe saves lots of time, but it also might destroy, so treat it like you would an intern…

    • drcobaltjedi@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      Yup, follow the 3-2-1 rule or you don’t have backups

    • Taleya@aussie.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 days ago

      hell I’ve got a better backup methodology with my fucking cat photos

  • deadbeef79000@lemmy.nz
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    Man who shit his own pants horrified that his pants are full of shit.

    Demands explanation from pants vendor.

    • Grendel@tiny.tilde.website
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      @deadbeef79000
      @cm0002

      I can’t believe that they criticized the vendor api for not having confirmation.

      It’s a freaking API!!! It’s designed for automation, not direct human (or LLM!) use. If you added confirmation then devs would have to code automatic acceptance, which defeats the purpose.

      It doesn’t make a bit of sense. Someone is passing the buck.

      • deadbeef79000@lemmy.nz
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        Everything is always somebody else’s fault.

    • Chakravanti@monero.town
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 days ago

      Yelling, “Who’s shit is this!?”

    • Quibblekrust@thelemmy.club
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 days ago

      In your analogy, I would think they would demand an explanation from the food vendor.

      • deadbeef79000@lemmy.nz
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        Demands explanation from local grocery store?

  • db2@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    They can’t go rogue, they have no agency or desire or thought. What really happened is the thing specifically designed to do whatever the Plinko line with the most chips says did it because the incompetent dickheads who deployed it didn’t know how not to do that.

  • Ethan@programming.dev
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 days ago

    Fuck around and find out

  • Luminous5481 "Enemy of the State" [they/them]@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 days ago

    wiping a volume deletes all backups

    that sounds like a wonderful backup system 😂

  • Raven@lemmy.org
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    This is fun to read. I hope people will have their actual intelligence activated after this.

    • ComfortableRaspberry@feddit.org
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      They won’t but they will continue to accidentally create content for my amusement :D

  • Avicenna@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    If you are going to give an LLM a free pass to your whole prod database least you should do is to take weekly (or daily if plausible) offline backups of it. A hard limit against deleting stuff would be better.

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 66 users / day
  • 441 users / week
  • 1.31K users / month
  • 1.72K users / 6 months
  • 0 local subscribers
  • 31.3K subscribers
  • 350 Posts
  • 3.85K Comments
  • Modlog
  • mods:
  • adr1an@programming.dev
  • Feyter@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org