arclight
Engineer (nuclear, safety analysis), scientific software developer, rehabilitator of unloved FORTRAN, recovering sysadmin, marginally competent solderator. Occasional Bond Villain (Card Overpunch). Nuclear Scoundrel™
My internet claim to fame was livetweeting the Fukushima reactor failures on the Birdsite. I'm pretty chipper for one spending so much time looking at sad melty reactors and sad creaky software.
@0xabad1dea@infosec.exchange @gudenau@hachyderm.io It's like any passive defense - it's not perfect or guaranteed, it's deterrence, like a fire door or a safe. Fire doors have a resistance rating - they'll hold back a fire for 15 minutes, an hour, etc. You install what provides adequate protection however "adequate" is defined.
Add a static "please stop" AGENTS.md file, have the build system restore it if it's deleted or refuse to build or test or whatever. The goal is to delay the sloplifting attack enough that the wasted tokens and manual bypass effort make AI processing expensive enough to not be viable. Token prices are only going to increase. Like thieves, agent users+ are driven by speed and low cost - increase the difficulty of the target and there's a point where it's not worth their effort.
- "But what about all the coders forced to use agents?" The thief role in this case is played by whatever layer of management is choosing to use agents against projects that expressly forbid them. The poor developer is caught in the middle as a "reverse centaur"; they're already screwed no matter what we do.
