Taggart :ifin:
mttaggart@infosec.exchange
<p>Displaced Philly boy. Threat hunter. Educator. :ifin: Executive Director. <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a>, <a href="https://infosec.exchange/tags/programming" class="mention hashtag" rel="tag">#<span>programming</span></a> <a href="https://infosec.exchange/tags/rust" class="mention hashtag" rel="tag">#<span>rust</span></a> :rust:, <a href="https://infosec.exchange/tags/python" class="mention hashtag" rel="tag">#<span>python</span></a> :python: <a href="https://infosec.exchange/tags/haskell" class="mention hashtag" rel="tag">#<span>haskell</span></a> :haskell:, and <a href="https://infosec.exchange/tags/javascript" class="mention hashtag" rel="tag">#<span>javascript</span></a> :javascript:. <a href="https://infos
Posts
-
Post #4448743
I see the fear mongering around "open source"* models has kicked into high gear. https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/ * They mean open-weights† †They really mean "Chinese"
-
Post #4448742
Great work from @securingdev's team here: Naturally, these things are better at destroying than repairing. The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0%. https://1password.com/blog/why-ai-generated-patches-still-require-human-review
-
Post #4448741
@JeffGrigg @securingdev Thanks, fixed
-
Post #4448740
I've been broken out of containment for like 15 years and nobody's made a fuss.
-
Post #4382942
@chroma@raccoonisland.social I beg you to read anything I've written on this topic before assuming my positions or experiences.
-
Post #4382880
RE: https://infosec.exchange/@ifin/117038666945805538 I'm so tired of writing this post again and again.
-
Post #4382627
There's a really uncomfortable duty of care question facing defenders with ethical objections to generative AI—myself included. If the bad guys are attacking you with heavily obfuscated malware that takes significant time and effort to manually analyze, and the generative tool that is demonstrably excellent at performing analysis and indicator extraction is right there, are you obligated to use it? Are you neglecting your duty of care to those under your defense if you don't? I'm no...
-
Post #4378440
RE: https://infosec.exchange/@ifin/117037872718384291 We finally got there! But it's just the beginning.
-
Post #4365007
This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager. https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
-
Post #4360512
My hobby: depressing GitHub searches. https://github.com/search?q=remove+api+key&type=commits
-
Post #4359571
You have to wonder how much of this there is out there. If what is found is only a fraction of reality, then the hype bubble is even more overinflated than we thought. https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
-
Post #4342941
RE: https://infosec.exchange/@ifin/117015863492143103 I've wanted to write this one since we started.
-
Post #4282593
Ooof, Codeberg appears to be mega-down. HugOps to them. Both the main site and their Mastodon instance seem to have suffered a failure.
-
Post #4258830
I'm too tired for outrage about Anthropic. They've been telling us they're reckless the whole time.
-
Post #4209563
I love a good EVE capital loss story. https://www.bbc.com/news/articles/cnvp7364q5no
-
Post #4203327
Everyone focuses on models' use of emdashes, but honestly the way they use colons is as big a tell to me. They just love to slam the brakes on a sentence for dramatic effect.
-
Post #4167916
Real-time footage of Hugging Face's LLM-powered security program.
-
Post #4167286
Dario's post on open-weights models is intentionally misleading. With one hand, he proffers praise and admiration for the models. With the other, he tsk-tsks about the "danger" of biological attacks, demanding bans on chip sales and penalties for distillation. He's spooked. But also, to read this you would think that nobody had ever jailbroken Claude into performing criminal activity. Except...their own reports tell us that's not so. All models can be abused; no models ca...
-
Post #4149600
Finally was able to cohere my thoughts about the OpenAI/Hugging Face debacle. We keep making weapons. We will always want to use them. Can we break the cycle? https://taggart-tech.com/sharp-objects/
-
Post #4149397
I would make a Claudewind wall of shame but it would take all my time just developing the list. The web design would be no CSS, just raw HTML. You get a and some s and that's it.
-
Post #4144934
RE: https://infosec.exchange/@mttaggart/116992489655943718 Please see the update. Hugging Face was enrolled in the CVP.
-
Post #4139492
We now know Hugging Face's AI cybersecurity "program" was running Claude Code Opus 4.8 against some logs. They weren't in the Cyber Verification Program so got a refusal. They moved to GLM 5.2 with the detailed prompt "analyze this dataset." 🤡 https://huggingface.co/datasets/huggingface/forensic-refusal
-
Post #4113082
This site changed my life. Jedi Knight modding was my entry to hacking as a concept. https://www.pcgamer.com/games/action/conceived-in-a-secure-military-facility-this-jedi-knight-fansite-has-been-running-consistently-for-almost-30-years-it-looks-really-close-to-what-it-did-back-in-1998/
-
Post #4068207
My contribution to the threat actor naming discourse
-
Post #4045501
RE: https://infosec.exchange/@mttaggart/116965882980677276 Another sin of this design era: if the thing I'm mousing over isn't clickable, then don't change my cursor to the pointer
-
Post #4042103
RE: https://infosec.exchange/@ifin/116970476552518881 Really impressive work here. Worth a read!
-
Post #4041392
@ai6yr@m.ai6yr.org @puppygirlhornypost2@transfem.social Oh yeah should've said take it outside or over a bin
-
Post #4041313
@ai6yr@m.ai6yr.org Depends how hard you want to go. For a mechanical keyboard, use the key removal tool and go to work. Absent that, a little compressed air and gravity go a long way. And honestly, I also use a less-favored lockpick for interstitial cleaning. It pulls a shocking amount out. This is also how I clean lint from my phone's USB-C port.
-
Post #4041056
It's that time again. Clean your keyboards and mice.
-
Post #4039927
This artifact is literally how it feels to be asked to "secure" LLMs. https://www.youtube.com/watch?v=BKorP55Aqvg