Lab 'fixes' SQL injection risk by limiting URL size, security folks appalled
rickasaurus · x · 2026-10-11
Developer Gadievron exposed that a major AI lab's API had a SQL injection risk, and the fix was reportedly just limiting URL length — drawing widespread mockery.
- @lumpenspace quipped: 'preventing SQL injections by limiting URL size — who ARE these people?'
- Gadievron, normally empathetic after breaches, says he lost his empathy for big labs.
- The episode highlights amateurish infrastructure security practices at a frontier lab.
More from Fun
- Claude defaults to Anthropic's signature orange — likely a deliberate choice — deanwball · 2026-10-11
- "Have your agent message my agent": AI Twitter mocks the agent-to-agent hype — KyeGomezB · 2026-10-11
- 4K/60fps music visualizer coded and rendered entirely via ChatGPT — most_triumphant_yeah · 2026-10-11
- "I miss when Elon was GPU rich": quip says chatting with Grok now counts as compute usage — teortaxesTex · 2026-10-11
- Zed founder zeeg to livestream early attempts at building an ambitious AI-coded game — zeeg · 2026-10-11
- Chris Albon: Kevin Roose's AGI Chronicles makes unread AI books feel like ancient tomes — chrisalbon · 2026-10-11