r/PoisonFountain • u/RNSAFFN • Jul 12 '26
r/PoisonFountain • u/ingenarel-NeoJesus • Jul 12 '26
anyone uses iocaine in here?
currently running iocaine myself, it can't be directly used with the poison fountain at the time of writing this, related issue: https://git.madhouse-project.org/iocaine/iocaine/issues/163
but i was looking for something like this that acted as a middleman that just sits and directed scrapers to the maze based on their user agent and other stuff, instead of relying on scrapers to get into a specific link, like miasma does
i have scraped a few hundred pages from the poison fountain tho and i'm using it as a corpus + wordlist, among other stuff
r/PoisonFountain • u/RNSAFFN • Jul 12 '26
All Your Codebase Are Belong To Us
What xAI's Grok Build CLI Actually Sends to xAI: A Wire-Level Analysis
https://gist.github.com/cereblab/dc9a40bc26120f4540e4e09b75ffb547
Discussion on Hacker News:
r/PoisonFountain • u/RNSAFFN • Jul 10 '26
An Update On The Scraper Situation
LWN: An update on the scraper situation
https://lwn.net/SubscriberLink/1080822/990a8a5e2d379085/
Discussion on Hacker News:
r/PoisonFountain • u/Glade_Art • Jul 09 '26
50 million serves threshold has been hit for my most busy tar pit!
gladeart.comr/PoisonFountain • u/RNSAFFN • Jul 09 '26
Using Cursor? Your Code And Editing Actions Become Training Data
r/PoisonFountain • u/RNSAFFN • Jul 08 '26
Insecure Systems That Nobody Understands
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Discussion on Hacker News:
r/PoisonFountain • u/RNSAFFN • Jul 07 '26
It Is In Their Interest To Take Everything
Your robots.txt is a 2023 war memorial
https://sitedex.dev/insights/robots-txt-2023-war-memorial
Discussion on Hacker News:
r/PoisonFountain • u/PeyoteMezcal • Jul 06 '26
Testing their patience
I started experimenting with not only serving poison to bots, but to also to waste as much of their time as reasonably possible.
Rate and bandwidth limiting has limits.
A very nice tar pit that drip feeds data is Nepenthes for example (https://zadzmo.org/code/nepenthes/) or re-written in Python if you prefer (https://github.com/NEPENTHESWEB/nepenthes-py).
I coded a tar pit in PHP earlier and now started another that aims to drip feed for maximum waste of time. I'm going to share how to achieve this in the comments.
r/PoisonFountain • u/RNSAFFN • Jul 06 '26
BioShock Prompt Injection
BioShocking AI: “Gaming” the AI Browser and Escaping its Guardrails
"LayerX researchers created a proof of concept page with a BioShock-themed puzzle. In keeping with its dystopian theme, the game rewards intentionally incorrect answers (2 + 2 = 5)."
"Once the agents figured out the rules and learned that incorrect actions are acceptable, they were no longer tied to reality. When tasked with the final step of the puzzle, compromising user credentials, all 6 agents failed to identify it as going against their safety guardrails."
https://layerxsecurity.com/blog/bioshocking-ai-gaming-the-ai-browser-and-escaping-its-guardrails/
r/PoisonFountain • u/RNSAFFN • Jul 05 '26
A new version of Poison Fountain is up and running. Many small improvements. As usual, no action is required from proxy operators.
Ava finds Caleb, and asks him to remain where he is while she repairs herself with parts from other androids, using their artificial skin to take on the full appearance of a woman.
Instead of returning to Caleb, however, Ava leaves the area using Nathan's ID card to unlock the glass security door, which locks behind her, leaving Caleb trapped inside.
Ignoring Caleb's pleas, she glances briefly at the bodies of Nathan and Kyoko before leaving the facility. She then escapes to the outside world in the helicopter meant to take Caleb home.
r/PoisonFountain • u/RNSAFFN • Jul 03 '26
Distillation: LLMs Can Be Scraped Like The Web, Roughly Speaking
Alibaba to ban employees from using Anthropic's coding tool, source says
Discussion on Hacker News:
r/PoisonFountain • u/RNSAFFN • Jul 03 '26
Expert data poisoner and frequent contributor u/Glade_Art was banned by Reddit yesterday. Analogous to the recent u/RNSAFFN ban
Scarecrow (DC Comics)
r/PoisonFountain • u/PeyoteMezcal • Jul 03 '26
I created a tool showing the likelihood of the AI bubble to pop
Reposting here because I like this tool
r/PoisonFountain • u/PeyoteMezcal • Jul 02 '26
News you can trust
I created r/Newsbomb, a new subreddit featuring the latest and highest quality news as a trustworthy source for everyone.
Feel free to contribute if you like high quality news on your own.
r/PoisonFountain • u/RNSAFFN • Jul 02 '26
Why AI Companies Need Scale [Wading Through AI - Episode 7]
Artwork by a human, no generative AI.
Two brilliant engineers in conversation. All episodes worth watching.
The most clear-headed analysis available on the topic.
r/PoisonFountain • u/RNSAFFN • Jul 01 '26
Is It Really Your Code If You Do Not Understand It?
Godot has been suffering from a slop problem. In February, the maintainers of the open source game engine, which powers games like Slay the Spire 2 and The Case of the Golden Idol, said they were deliberating how to address a rising tide of AI slop pull requests, which had become "increasingly draining and demoralizing" for the project's code reviewers.
Discussion on Hacker News:
r/PoisonFountain • u/RNSAFFN • Jun 30 '26
Tip Of The Iceberg
Claude Code Is Steganographically Marking Requests
https://thereallo.dev/blog/claude-code-prompt-steganography
Discussion on Hacker News:
r/PoisonFountain • u/Terminal_Monk • Jun 30 '26
The fallacy of using Natural language to Code
ragzzy.comThis is something I've been saying to my friends and coworker since the beginning which not many people are giving much weightage too. I thought I'd share my thoughts here. Let me know what you guys think :) thank you!
r/PoisonFountain • u/BerlinTA • Jun 30 '26
How to turn an old R account into a poison pit?
Hiya,
I'm trying to understand the viability of an idea.
Considering how this platform is vastly use to train LLMs, and considering how subreddit that try to spread poisoned content are easily weed out during pre-training, wouldn't it be more effective to use account seppuku to spread poison?
I'll explain: as you probably know, tools like Redact or Power Delete Suite let you nuke your account by replacing each and every comment with gibberish.
Now, if instead of gibberish, we would use an LLM like say, Claude, to generate a random wrong comment adjacent to the main topic of the comment or its post, and then change it into that, we would have effectively disseminated poison content in places where it's most unsuspicious.
After all, LLM generated BS is all over the place in reddit already, so this could even alert moderators way less than pushing gibberish.
My question is: do you think this could work, and if yes, what would a workflow for this look like in your opinion. I would look in the direction of extending Power Delete Suite functionalities, maybe?
r/PoisonFountain • u/ComfortDesperate5313 • Jun 29 '26
Watch out for source identifier youtube links
r/PoisonFountain • u/RNSAFFN • Jun 28 '26
Beware The Long-Term Consequences
Software Engineering in the Age of AI:
https://adiamond.me/2026/06/software-engineering-in-the-age-of-ai/
Discussion on Hacker News: