2 comments

  • semiquaver 49 minutes ago
    God damn this writing is just a string of pure claudeisms. I can’t see the actual content because I’m cringing so hard.

    Why not just post the info you want to convey and the prompt? It would be easier for everyone involved.

    • stingraycharles 15 minutes ago
      I’ve asked Claude to read this article for me and explain it to me. Somehow that makes it better, as then at least I know I’m talking to an AI:

      “The fix closed two chained flaws in RouterOS’s shared crypto and login libraries: a lax PKCS#1 v1.5 RSA signature verifier that failed to enforce the total encoded length (256 bytes) or pin the digest to its correct length for the claimed hash, allowing an attacker to forge a valid-looking signature without the private key — a pre-auth authentication bypass sitting on SSH public-key auth, IPsec/IKE, and TLS simultaneously.

      “The second flaw was missing input validation on the terminal-login username path (SSH, Telnet, MAC-Telnet), which permitted argument injection (a leading -) and control-character/log-forging injection.

      “Chained, the forged-signature auth bypass plus the hostile login-parameter handling turned an unauthenticated network position into a path toward code execution, which is why MikroTik backported it silently across all branches on the same day.”

    • spdustin 18 minutes ago
      I'm so weary of seeing Claude-isms everywhere. It makes everything so much more of a cognitive burden to read, whether you're reading for leisure or comprehension.
    • slaw3 45 minutes ago
      I agree. I would prefer just the info, if the write up was not human authored
      • a2ff6eeb0 6 minutes ago
        The info was also almost certainly not human authored. AI is almost certainly capable of writing this up given a prompt like "explain what this security update is about. Format it as a blog post."
  • a2ff6eeb0 8 minutes ago
    It's incredible that we can have full security writeups done without a human involved at all.