Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
This Smashing Security podcast episode explores a bizarre incident where a New Zealand convenience store accidentally opened its website for public editing due to using Base44, a vibe-coding platform. The store was selling a combination of unusual items, including a Princess Diana commemorative plate and New Zealand's national parks, and the vulnerability stemmed from a simple setup error. The episode also touches on the growing role of AI in software development and the potential displacement of human developers, alongside a discussion about crusty socks and the ethical considerations of relying on AI for coding tasks.
This episode of Smashing Security, hosted by Graham Cluley and featuring guest Dave Bittner, doesn't delve into typical cybersecurity threats like ransomware or data breaches. Instead, it centers around a peculiar incident involving a convenience store in New Zealand. The store, using a platform called Base44 – a vibe-coding tool owned by Wix – inadvertently opened its entire website for public editing.
This wasn't a deliberate attack or a sophisticated exploit. The store simply set up the environment in a way that allowed anyone on the internet to modify the website's code. The result? A chaotic online experience where anyone could add, delete, or change anything on the site. The store was selling a collection of unusual items, including a Princess Diana commemorative plate and, remarkably, New Zealand's national parks – all available for modification by the general public.
The episode highlights the ease with which vulnerabilities can arise when using tools like Base44, even when the intended users aren't cybersecurity experts. The discussion extends to the broader impact of AI on the software development landscape. Bittner notes that the role of developers is shifting, with AI increasingly handling the actual coding tasks, raising concerns about potential job displacement and the need for human oversight. He uses the analogy of someone asking ChatGPT to create a version of Pong in BASIC for the TRS-80 Color Computer, acknowledging the AI's success but also the potential for errors and vulnerabilities.
Furthermore, the podcast touches on the seemingly mundane – crusty socks – and the growing acceptance of relying on AI to automate tasks that once required significant human effort. Bittner shares his own experience with using AI to automate simple computer tasks, emphasizing the need for caution and awareness when relying on these tools. The episode concludes with a humorous reflection on the challenges of building secure systems when dealing with users who lack technical expertise.