Comment by lyu07282

Comment by lyu07282 10 hours ago

2 replies

> If you did so too, you would've read the message from github which says "...disallow usage of camo to disclose sensitive victim user content"

They use "camo" to proxy all image urls, but they in fact did remove the rendering of all inline images in markdown, removing the ability to exfil data using images.

> Now why on earth would I take all the effort to come up with a new way of fooling this stupid AI only to give it away on HN?

You just didn't make it very clear that you discovered some other unknown technique to exfil data. Might I encourage you to report what you found to Github?

https://bounty.github.com/

munchlax 6 hours ago

I'm not sure how you could arrive at the conclusion that I've discovered any technique involving copilot whatsoever.

Feel free to spout more nonsense. I was somewhat puzzled and dismayed at first, but now it amuses me.

  • lyu07282 6 hours ago

    Because we know exactly what you did and the whole copilot team is laughing at you now! The base64 encoded source code you md5 hashed into our mainframe, you know what you did there is no denying it now. You are on thin ice buddy!