Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Daniel Cuthbert

@dcuthbert@defcon.social
mastodon 4.6.6
  • Open on defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

2989 Followers
238 Following
9 Posts
Joined December 25, 2022

Posts

Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Jul 25, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
Replying to @thedarktangent@defcon.social
@thedarktangent@defcon.social oh it’s wild. We’ve almost got to the point where you need to do a physical assessment of the cars telemetry systems in order to block them, or at least find out where the hell they are at first That or we need an EDR or WAF for the cars. Heaven help us all
0
0
1
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Jul 25, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
I never thought i'd side with Gen Z in how they think, but when it comes to analogue devices, we are very much in sync. Vinyl's back. Mechanical watches are back. Gen Z reads more physical books than the algorithm and tech bro's wearing patagonia would like. I'm here for it. I remember being with @thedarktangent@defcon.social in London talking about cars and tracking a while ago and it has always been in the back of my mind. I'm not anti-tech, I'm just anti-tech for techs sake. I own a modern car, it's from 2009 and it's the newest I have and have ever had actually. It has knobs. It has sliders. There's no stupid ipad in the display. I don't have it snitching on me. I don't have a sub to warm Turns out I'm not just being sentimental about this. From January 2026, Euro NCAP won't give a car five stars unless it has physical controls for indicators, hazards, the horn, windscreen wipers and such. physical knobs. wild I tell ya Their own research found touchscreen tasks can take 20+ seconds, enough to cover half a kilometre at motorway speed without your eyes on the road. Then there's the data, and this is the part that actually worries me professionally. Mozilla tested every major car brand's privacy practices. Every single one failed. Their conclusion: cars are the worst product category they've ever reviewed for privacy (https://www.bbc.co.uk/future/article/20260513-your-car-is-spying-on-you-its-about-to-get-worse) None of this is a human underwriter looking at your file anymore. It's a model turning your braking patterns, night trips and cornering speed into a risk score and quietly adjusting your price. Insurers are moving further into AI-processed pricing and claims, and even within the industry the reasoning behind a given decision is often described as a "black box" that's hard to unpick So I'm not being precious about buttons for the sake of it. I'm against tech that fails silently, phones home without asking, and quietly builds a profile of me that I'm not allowed to read. Tech for tech sake is what VC's and tech bros want and the reality is, most others dont And that's the part I can't get past, being on the inside of this stuff. I know exactly where that data goes. It's not sitting in a drawer somewhere. It's a row in a Postgres table, or an embedding in a vector database, waiting for some frontier model to slurp it up Often with shoddy security engineering processes and "oh crap we got hacked but no honestly, we DO take your security seriously" lines we've all heard to death. So here's to more analogue, less tracking and less bloody data generation If you got this far, watch Julia James Davis (she's very cool, I like her series on the death of beauty) https://www.youtube.com/watch?v=V7GKFmAbTB8&t=1s Anyway here's to hacker summer camp, tinkering and breaking and hacking.
10
2
8
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Jul 14, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
So @chompie1337@haunted.computer and I are on a mission to find creative artists who want to help design the cover for Phrack #73. retro sci-fi & chrome futures ▸ cyberpunk / terminal aesthetics ▸ dystopian systems ▸ hacker manuals from an alternate timeline ▸ weird cool stuff and machines Keen? Fancy helping? 📮 arts@phrack.org ⏰ Deadline: August 15
33
1
62
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Apr 26, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
Replying to @dpp@mastodon.social
@dpp @thedarktangent @defcon @wendynather @inkandswitch.com I’m sad to say I’m not, but I’m rectifying that now. Thank you very much.
1
0
0
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Apr 26, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social

Ever since @thedarktangent@defcon.social mentioned the concept of agency to me, I’ve not stopped thinking about how much modern technology asks us to relinquish control of our data.

I’ve never used music streaming services. I always disliked the idea of not owning my music. For me, the original iPod was the epitome of agency: mine to do with what I wanted, when I wanted.

With the relentless march of frontier models consuming as much of our data as possible, we need more agency today, not less. Control over who has access to our data. Control over when they have it. Control over what they are allowed to do with it.

Silicon Valley has given us some truly amazing inventions, but it has also welcomed some ugly things into our lives. Systems where we have very little control, very little ownership, and very little say.

That needs to change. Really looking forward to @defcon@defcon.social this year

48
5
26
1
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Apr 24, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
Replying to @Npars01@mstdn.social
@Npars01@mstdn.social @thedarktangent@defcon.social I couldn’t agree more. I kind of actively look for companies now that don’t have chat bots.
1
0
0
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Apr 24, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social

Day two of Black Hat and I got a chance to see my friend Ariel Herbert-Voss
do the keynote. It opened a floodgate of thoughts.

Oh and yay, GPT-5.5 is here and it feels like we’re entering another mad period of growth for frontier models and security research.

The big thing I’m seeing is that we need less scaffolding around these models. Give them code, context, a goal and some tools, and they are getting much better at cracking on.

That matters for bug hunting. A lot

But let’s not pretend the machines have solved vuln research. They haven’t.

The biggest gains are still at the shallow end.

Low severity bugs, obvious logic mistakes, unsafe patterns, missing checks, boring-but-real issues, that’s where models are starting to clean up. If the bug class is well documented and the code is clear, they move quickly.

The low-hanging fruit is getting hoovered up at pace. The easy stuff is becoming cheaper to find, well sorta cheaper.

We’re also seeing decent gains on modest bugs. Not deep chains. Not always novel research. But useful findings where the model can read, reason, trace, and join enough dots to help.

Where it still gets spicy is state.

Models can talk about state all day, but they don’t really feel it. They still struggle with temporal bugs, race conditions, lifecycle weirdness, multi-step flows, and those “only happens after you do these seven things in this exact order” bugs.

Spotting something dodgy is not the same as proving it is exploitable.

On the exploit side, validation, exploitability and reliability are improving, but more slowly. This is one of the big areas John and I have been working through with RAPTOR: getting away from “looks interesting, mate” towards “this is real, reachable, and repeatable”.

Because exploit reliability is still a graft. Targeting is still fragile. You still need iterations.

Oh and the human in the loop is still vital.

We all thought fuzzing would solve the bug problem. It didn’t. It changed the economics of bug discovery, but we still needed harnesses, triage, context, exploit dev, judgement, and all the boring engineering bits that make the work useful.

I think frontier models are having a similar moment.

The best results won’t come from throwing a giant model at a repo and hoping it finds magic. They’ll come from layered systems: frontier models for reasoning and code understanding, smaller focused models trained on private data, internal vuln history, remediation patterns, product context, validation loops, and humans who know when the model is chatting crap.

As models get better at writing code, they get better at breaking it. Capability doesn’t scale politely. It compounds.

Better tool use helps validation.

Better context helps reachability.

Better reasoning helps exploit chains.

But it still needs structure.

It still needs evidence.

It still needs humans who know what good looks like.

The shallow bugs are already getting compressed. The interesting bit is what comes next.

7
0
7
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Apr 23, 2026
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social

“We are going to crave more authentic in-person experiences as our online interactions are seemingly less authentic”

@thedarktangent@defcon.social utterly nailing it

20
2
7
0
Open post
dcuthbert
Daniel Cuthbert @dcuthbert@defcon.social · Nov 06, 2023
Daniel Cuthbert
@dcuthbert@defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

defcon.social
Replying to @yossarian@infosec.exchange
@homebrew @trailofbits @yossarian @openssf this is unbelievably cool and ToB continues to do the work we all need. Respect!!!
2
0
1
0

Remote instance

defcon.social
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:35:30 UTC