Readit News logoReadit News
belladoreai commented on Stimulation Clicker   neal.fun/stimulation-clic... · Posted by u/meetpateltech
belladoreai · 8 months ago
classic neal.fun
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
jiggawatts · a year ago
Wait… what!?

This is the first I’m hearing of this. Do you have any references?

belladoreai · a year ago
You can find many references by googling some variations of keywords Docker, Windows, brick
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
lyu07282 · a year ago
What does that even mean?
belladoreai · a year ago
"Bricking" is when your electronic device stops working, i.e. becomes a brick. Docker is known to occasionally brick Windows machines.
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
aintnolove · a year ago
I peered down the ComfyUI rabbit hole [1] and it is shockingly powerful. Did Adobe drop the ball on image generation? What are they doing over there? There has to be a better, more secure way to bundle up all this imagegen logic.

[1] https://learn.thinkdiffusion.com/bria-ai-for-background-remo...

belladoreai · a year ago
Yep, it's super powerful.

I would say that the "more secure way" is to just use ComfyUI without installing any obscure nodes from unknown developers. You can do pretty much anything using just the default nodes and the big node packs.

belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
Seattle3503 · a year ago
How do people feel about using docker to prevent this sort of thing? Does it strike the right balance between usability and security?
belladoreai · a year ago
Well, Docker is great for this as long as you're not one of the unlucky few whose machine is bricked because of Docker. So, mostly yes, I suppose.
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
janoc · a year ago
There was also an actively exploited XSS vulnerability on Github in the recent days.

Doesn't mean that this guy was not a malicious actor, only that one shouldn't be so quick to cast stones without evidence.

belladoreai · a year ago
The person who created the custom node is the same person who "hacked" it. Whether or not the account is technically owned by some unrelated civilian is not important, because there is no other activity on the account.
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
millzlane · a year ago
I wouldn't be so sure no one would hack an idle account. I had my Spotify account taken before I even used it. I think in my case they used my account to pump up other lesser known artists.
belladoreai · a year ago
Okay, sure. But if we have an account which has never had any legitimate activity on it ever - an account that has only ever been used to push malware - then I don't know if it matters much who is the "rightful owner" of the account. Things would be different if the GitHub account had some legitimate activity before the "hack".
belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
WarOnPrivacy · a year ago
Some entity called Nullbulge Group claims they took over the repo.

Today's capture (before the repo got 404'd) has their belligerence spiel. https://web.archive.org/web/20240609135118/https://github.co...

This is the capture from 3 days prior: https://web.archive.org/web/20240525021402/https://github.co...

belladoreai · a year ago
I have not seen a statement from Nullbulge so it's not appropriate to say that they took over the repo.

The author of the repo is claiming that their repo is hacked, but this is an obvious lie, because their very first GitHub commit is the one where they push the malware. Nobody would hack an empty GitHub account.

I don't know if the author of the repo is lying when they say that Nullbulge is behind the attack (perhaps the author is part of Nullbulge, perhaps not).

belladoreai commented on Keylogger discovered in image generator extension   old.reddit.com/r/comfyui/... · Posted by u/belladoreai
skilled · a year ago
Looks like a pretty small project. Only had 40 stars on GitHub before the repo was removed.

Was this the main method of GPT4 and Claude integrations for ComfyUI?

belladoreai · a year ago
It was an extension for ComfyUI, which has 37k stars on GitHub. The way ComfyUI is commonly used is that a person shares a "workflow" file, which utilizes various obscure extensions (called "custom nodes") and then the people who want to run the workflow on their own computer will install all these obscure custom nodes that have like 40 stars on GitHub or so.

u/belladoreai

KarmaCake day364June 9, 2023View Original