Elektrine lite

← Feed

Taggart :ifin:

mttaggart@infosec.exchange

<p>Displaced Philly boy. Threat hunter. Educator. :ifin: Executive Director. <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a>, <a href="https://infosec.exchange/tags/programming" class="mention hashtag" rel="tag">#<span>programming</span></a> <a href="https://infosec.exchange/tags/rust" class="mention hashtag" rel="tag">#<span>rust</span></a> :rust:, <a href="https://infosec.exchange/tags/python" class="mention hashtag" rel="tag">#<span>python</span></a> :python: <a href="https://infosec.exchange/tags/haskell" class="mention hashtag" rel="tag">#<span>haskell</span></a> :haskell:, and <a href="https://infosec.exchange/tags/javascript" class="mention hashtag" rel="tag">#<span>javascript</span></a> :javascript:. <a href="https://infos

Posts

  • Post #4448743

    I see the fear mongering around &quot;open source&quot;* models has kicked into high gear. https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/ * They mean open-weights† †They really mean &quot;Chinese&quot;

  • Post #4448742

    Great work from @securingdev&#39;s team here: Naturally, these things are better at destroying than repairing. The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0%. https://1password.com/blog/why-ai-generated-patches-still-require-human-review

  • Post #4448741

    @JeffGrigg @securingdev Thanks, fixed

  • Post #4448740

    I&#39;ve been broken out of containment for like 15 years and nobody&#39;s made a fuss.

  • Post #4382942

    @chroma@raccoonisland.social I beg you to read anything I&#39;ve written on this topic before assuming my positions or experiences.

  • Post #4382880

    RE: https://infosec.exchange/@ifin/117038666945805538 I&#39;m so tired of writing this post again and again.

  • Post #4382627

    There&#39;s a really uncomfortable duty of care question facing defenders with ethical objections to generative AI—myself included. If the bad guys are attacking you with heavily obfuscated malware that takes significant time and effort to manually analyze, and the generative tool that is demonstrably excellent at performing analysis and indicator extraction is right there, are you obligated to use it? Are you neglecting your duty of care to those under your defense if you don&#39;t? I&#39;m no...

  • Post #4378440

    RE: https://infosec.exchange/@ifin/117037872718384291 We finally got there! But it&#39;s just the beginning.

  • Post #4365007

    This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager. https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/

  • Post #4360512

    My hobby: depressing GitHub searches. https://github.com/search?q=remove+api+key&amp;type=commits

  • Post #4359571

    You have to wonder how much of this there is out there. If what is found is only a fraction of reality, then the hype bubble is even more overinflated than we thought. https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/

  • Post #4342941

    RE: https://infosec.exchange/@ifin/117015863492143103 I&#39;ve wanted to write this one since we started.

  • Post #4282593

    Ooof, Codeberg appears to be mega-down. HugOps to them. Both the main site and their Mastodon instance seem to have suffered a failure.

  • Post #4258830

    I&#39;m too tired for outrage about Anthropic. They&#39;ve been telling us they&#39;re reckless the whole time.

  • Post #4209563

    I love a good EVE capital loss story. https://www.bbc.com/news/articles/cnvp7364q5no

  • Post #4203327

    Everyone focuses on models&#39; use of emdashes, but honestly the way they use colons is as big a tell to me. They just love to slam the brakes on a sentence for dramatic effect.

  • Post #4167916

    Real-time footage of Hugging Face&#39;s LLM-powered security program.

  • Post #4167286

    Dario&#39;s post on open-weights models is intentionally misleading. With one hand, he proffers praise and admiration for the models. With the other, he tsk-tsks about the &quot;danger&quot; of biological attacks, demanding bans on chip sales and penalties for distillation. He&#39;s spooked. But also, to read this you would think that nobody had ever jailbroken Claude into performing criminal activity. Except...their own reports tell us that&#39;s not so. All models can be abused; no models ca...

  • Post #4149600

    Finally was able to cohere my thoughts about the OpenAI/Hugging Face debacle. We keep making weapons. We will always want to use them. Can we break the cycle? https://taggart-tech.com/sharp-objects/

  • Post #4149397

    I would make a Claudewind wall of shame but it would take all my time just developing the list. The web design would be no CSS, just raw HTML. You get a and some s and that&#39;s it.

  • Post #4144934

    RE: https://infosec.exchange/@mttaggart/116992489655943718 Please see the update. Hugging Face was enrolled in the CVP.

  • Post #4139492

    We now know Hugging Face&#39;s AI cybersecurity &quot;program&quot; was running Claude Code Opus 4.8 against some logs. They weren&#39;t in the Cyber Verification Program so got a refusal. They moved to GLM 5.2 with the detailed prompt &quot;analyze this dataset.&quot; 🤡 https://huggingface.co/datasets/huggingface/forensic-refusal

  • Post #4113082

    This site changed my life. Jedi Knight modding was my entry to hacking as a concept. https://www.pcgamer.com/games/action/conceived-in-a-secure-military-facility-this-jedi-knight-fansite-has-been-running-consistently-for-almost-30-years-it-looks-really-close-to-what-it-did-back-in-1998/

  • Post #4068207

    My contribution to the threat actor naming discourse

  • Post #4045501

    RE: https://infosec.exchange/@mttaggart/116965882980677276 Another sin of this design era: if the thing I&#39;m mousing over isn&#39;t clickable, then don&#39;t change my cursor to the pointer

  • Post #4042103

    RE: https://infosec.exchange/@ifin/116970476552518881 Really impressive work here. Worth a read!

  • Post #4041392

    @ai6yr@m.ai6yr.org @puppygirlhornypost2@transfem.social Oh yeah should&#39;ve said take it outside or over a bin

  • Post #4041313

    @ai6yr@m.ai6yr.org Depends how hard you want to go. For a mechanical keyboard, use the key removal tool and go to work. Absent that, a little compressed air and gravity go a long way. And honestly, I also use a less-favored lockpick for interstitial cleaning. It pulls a shocking amount out. This is also how I clean lint from my phone&#39;s USB-C port.

  • Post #4041056

    It&#39;s that time again. Clean your keyboards and mice.

  • Post #4039927

    This artifact is literally how it feels to be asked to &quot;secure&quot; LLMs. https://www.youtube.com/watch?v=BKorP55Aqvg