Got targeted in a phishing attack for stealing my X account today. @ domboyce @domboyce asked to book a meeting, which redirected to a URL that seemed like a bloomberg domain. It redirected to a fake calendly meeting page, which showed an X login button
this redirected to an X app asking for broad privileges meant to take over my account
stay safe everyone
cc @nikitabier please shut off this attack vector, it is too easy
VibeOps? importance of DevOps and good security practices have just increased massively. we are slowly approaching the challenger-level disaster @simonw is warning about. imagine bezos deleting us-east-1 while vibecoding a new company
it’s clear there needs to be clear boundaries and friction at deployment level. it’s fine when you are starting a new project, but once it starts making real money, you should slowly take away production write access
you can’t give infra write access to LLMs indefinitely