Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Posts
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
If I had a project like Mesa or virglrenderer, I would pay a premium for a CI service that offered bare-hardware runners for various embedded boards that are safe to run on not-yet-reviewed contributions.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
RE: @thedarktangent@defcon.social
As this post shows very well, hosting user-generated content has very real economy of scale. Abuse prevention and response is very expensive to do well, and the consequences of not doing it well are severe.
Even end-to-end encrypted apps like Signal still need to be able to respond to abuse reports!
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
If an IPS is found to break some feature of TLS, browsers should force that feature on in the next update, with no opt-out.
“Nobody can connect to the Internet” is, hopefully, enough to force changes.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
It’s fine to not allow LLM-generated, or even LLM-assisted, code contributions.
Rejecting valid reports of security vulnerabilities because they were generated with LLM assistance is foolish. All it does is make life easy for criminals and cyberweapon vendors.
For what it is worth, OpenBSD seems to have exactly this policy. They reject LLM-generated code, but promptly fixed a remote DoS found by Claude Mythos Preview and confirmed by Anthropic.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
What are best practices for situations where one has reason to suspect there is a security vulnerability in a project, but cannot confirm it?
Especially when there have been similar vulnerabilities in the past, and one is about to file public issues that will tell others exactly where to look.
Software developer and security researcher. Currently working on Spectrum. Follows are not endorsements.
If one is going to be using a whole server for one task, it’s best (performance-wise) for that one task to have all the drivers. So DPDK + SPDK.
Of course, that’s a lot of development work, but only because this was not the model from the beginning.