Remote
professional troublemaker
1407
Followers
427
Following
50
Posts
Joined November 02, 2022
Website:
Hart voor Internetvrijheid:
Languages:
NL/EN/ES
GPG:
0x2C9686C23DF31CBF602F2906748800B2AB826D05
Posts
Open post
Replying to
@dantalion@fosstodon.org
@dantalion@fosstodon.org not too bad then! :) no big performance loss while running steam games?
0
0
0
0
Open post
Insane and inhumane: "YC founder asks desperate job seekers to tattoo themselves for an interview"
https://sfstandard.com/2026/07/30/lemonlime-tattoo-job-interview/
18
0
33
0
Open post
RE: https://infosec.exchange/@drwhax/116997238394916522
Maybe confirmation bias, but an interesting read nevertheless https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities
Quoting
I know Mastodon hates LLM's and AI. So here goes!
I recently got access to trusted access of cyber capabilities of both openai and anthropic, which also allows you to weaponize security vulnerabilities.
The speed at which these parrots can find bugs and be creative enough to exploit them is staggering.
I recently pointed an LLM at an kernel fix that was reachable by an unprivileged namespace on Debian and it fully weaponized it, without too much me prompting it in the right direction, in about 7-9 hours.
I don't think open-source and companies will know what's coming for them once these open-source weight models will have broader reach and get better at exploiting vulnerabilities on a massive scale as anyone can access them.
The bottom line I think is, you cannot patch faster than the attackers can easily chain all kinds of vulnerabilities together and just move laterally on an incredibly fast pace.
I've started reporting vulnerabilities to all kinds of projects and the majority have trouble or patching issues found. There's not enough maintainers, or there's simply none anymore.
I've been getting quite worried about what our future will look like for data privacy. I think outright not running an LLM over your codebase to find critical security vulnerabilities because of your moral stance will keep us more insecure.
Please run an LLM over your code base if it's internet facing or something critical, we thank you!
Can't wait for the discussions on this!
Open quoted post
0
0
0
0
Open post
Open post
Replying to
on tech.lgbt
@Netzblockierer@tech.lgbt tell me you dont understand it, wihtout saying you dont understand it
0
0
0
0
Open post
Replying to
@castedo@mathstodon.xyz
@castedo@mathstodon.xyz yes, some of these got an CVE assigned here: https://github.com/tuxera/ntfs-3g/security
As these are reported privately, there's no open issue. I could however make these findings open-source in a git repo if that's useful?
0
0
0
0
Open post
Replying to
@Netzblockierer@tech.lgbt
@Netzblockierer@tech.lgbt if your data leaks on a next LLM powered leak you can't cry!
0
0
0
0
Open post
Open post
Replying to
@passwordsarehard4@mastodon.social
0
0
0
0
Open post
Open post
Replying to
@LordCaramac@discordian.social
@LordCaramac@discordian.social we both hate capitalism dont get me wrong
0
0
0
0
Open post
Replying to
@em_and_future_cats@mastodon.social
@em_and_future_cats@mastodon.social @zimzat@mastodon.social unfortunately less cute than Mr Snufflepagus: https://en.wikipedia.org/wiki/Mr._Snuffleupagus
https://github.com/jvoisin/snuffleupagus/
0
0
0
0
Open post
Replying to
@em_and_future_cats@mastodon.social
@em_and_future_cats@mastodon.social It might've been immersion cooling :) https://en.wikipedia.org/wiki/Immersion_cooling (although I don't know what the difference would be when it would come to electricity..)
0
0
0
0
Open post
Replying to
@drwhax@infosec.exchange
@em_and_future_cats@mastodon.social that is to say, were abusing huge plots of land for... what exactly??
0
1
0
0
Open post
Replying to
@em_and_future_cats@mastodon.social
@em_and_future_cats@mastodon.social we both agree on this! I don't see them making a profit on these gigantic datacenters either!
0
1
0
0
Open post
Excellent trolling of a city council in Arizona: https://www.404media.co/casa-grande-arizona-flock-city-council/
0
1
0
1
Open post
Open post
Replying to
@zimzat@mastodon.social
@zimzat@mastodon.social No one wants to fund it is what I think.
Suhosin did something like this for PHP, now it's just jvoisin maintaining snufflepagus: https://github.com/jvoisin/snuffleupagus
I don't remember if there was something similar for other languages. Grsecurity for the Linux Kernel, that's the three I know :/
0
1
0
0
Open post
Replying to
@alice_pea_3526@mastodon.social
@alice_pea_3526@mastodon.social the parrots are pretty good at pattern recognition which is where I think they shine. Some smaller projects as well, but architecture wise, you'll have to handhold them a lot. Its almost like having a junior that's good in some incredibly niche things, but you'll be iterating a lot over code.
I think curl maintainer said something similar, the reports used to be bad from LLM's and they suddenly got a lot better. It still requires a pair of human eyes to understand if its not hallucinating.
I wish it was better at eliminating whole bug classes tho, that'd be the ideal situation?
0
0
0
0
Open post
Replying to
@MossyQuartz@social.vivaldi.net
@MossyQuartz@social.vivaldi.net I still think thats a good idea to this day :)
0
0
0
0
Open post
Open post
Replying to
@MossyQuartz@social.vivaldi.net
@MossyQuartz@social.vivaldi.net Apologies that this is just talking about computer vulnerabilities, but yes, you're right about risk modeling in the away from keyboard world!
0
1
0
0
Open post
Replying to
@koehntopp@infosec.exchange
@koehntopp@infosec.exchange this parrot is really good at pattern recognition, it can code and fix some I think given enough constraints and a feedback loop of adversarial review, but it still might not be up to the style of the codebase or it might even introduce new vulnerabilities. I still think we also haven't it fully figured out yet? I think this needs more benchmarks that are reproducible in some fashion
2
1
0
1
Open post
Replying to
@0v1@infosec.exchange
0
1
0
0
Open post
Replying to
@davidfstr@mastodon.world
@davidfstr@mastodon.world I liked Halvar Flake's analogy, which i was sometimes a long the lines of, a bug every 10 years instead of 1 year. I think we can do a lot to prevent it, but there's always going to be bugs. I also think Mythos is way too hyped and these capabilities already exist in modern frontier models.
0
0
0
0
Open post
Replying to
@SDRHoernchen@chaos.social
@SDRHoernchen@chaos.social Yes, I think this is a huge problem and it shows a huge gap. Sadly, I don't think this will be fixed as the line between offence and defence is too thin these days.
0
0
0
0
Open post
Replying to
@macattackmicmac@mastodon.social
@macattackmicmac@mastodon.social yeah, it's pretty wild at the cost to be honest.
0
0
0
0
Open post
Replying to
@edward@activitypub.ro
@edward@activitypub.ro I do think that's the case at the moment, cross-file vulnerabilities are sometimes not found. What I feel they're mostly good at is, pattern recognition, e.g, there's a specific bug class fixed from past git history that it found repeated or as a variant. After all, LLM's is just a stochastic parrot and it shows
0
0
0
0
Open post
Open post
Replying to
@failedLyndonLaRouchite@mas.to
@failedLyndonLaRouchite@mas.to They are, but they have flaws and the way these models are created is quite shit and there's a lot of things to say about that. It's not that I say, anthropic good, or openai good. It's more to say, we're entering an era with a lot of shit going to be thrown at people, companies and maintainers and I don't think people realize what's about to hit them!
0
0
0
0
Open post
Replying to
@macattackmicmac@mastodon.social
@macattackmicmac@mastodon.social for that particular session it was roughly 122 USD in API costs, but since it was subsidized, it was only $20 in a subscription: https://gist.github.com/DrWhax/465da154f2ac1575cfc72aa71aa979e6
0
1
0
0
Open post
Replying to
@gimulnautti@mastodon.green
@gimulnautti@mastodon.green I think they already classify themselves as dual-use. which yes, I think is the right distinction
0
0
0
0
Open post
Replying to
@agowa338@chaos.social
@agowa338@chaos.social I agree and that's unfortunately the shitty side of it.
0
0
0
0
Open post
Replying to
@glitchypixel@mastodon.gamedev.place
@glitchypixel@mastodon.gamedev.place I think art should be made by artists and not AI fwiw!
1
0
0
0
Open post
Replying to
@bartavi@mastodon.nl
@bartavi@mastodon.nl attackers don't care about your keylengths when exploiting your endpoints is just 7 hours away
0
0
0
0
Open post
Replying to
@whvholst@eupolicy.social
@whvholst@eupolicy.social it's one crazy rollercoaster right, including after the subsidy for compute ends
0
0
0
0
Open post
Replying to
@fnrd@toots.nu
@fnrd@toots.nu you're right, but I think if we take this defeatist stance we're not going to improve things for the better.
Unfortunately, we'll not be able to make our own models, we're compute starved, our best bet is maybe open-weights models.
It's all a mess though, I do agree with that.
0
1
0
0
Open post
Replying to
@gary_alderson@infosec.exchange
@gary_alderson@infosec.exchange there will be no superabundance, there's only scarcity from here on out
0
0
0
0
Open post
Replying to
@Offbeatmammal@mastodon.social
@Offbeatmammal@mastodon.social @can@haz.pink I think that's accurately describing my view on AI for the past couple months now hehe
0
0
0
0
Open post
Replying to
@Offbeatmammal@mastodon.social
@Offbeatmammal@mastodon.social @can@haz.pink I'm very curious to hear if it helps! If you need help i'm here!
0
1
0
0
Open post
Replying to
@hughsie@mastodon.social
@hughsie@mastodon.social I'd love to hear more on the maintainer side of this. What i'm ultimately scared of is that everyone will burn out from the immense amount of stuff maintainers have to clean up.
0
0
0
0
Open post
Replying to
@decapitae@mastodon.social
@decapitae@mastodon.social Ideally we get more Suhosin's projects for all these different languages, but I doubt it'll happen at this point.
0
0
0
0
Open post
Open post
Open post
Replying to
@can@haz.pink
@can@haz.pink yes for sure!
There's a couple things you can do, one of them is indeed as basic as, this is app XYZ, written in PHP, review the codebase for security problems, then adversarially review your findings before writing them down in findings/ per bug in markdown. Also make a root cause and look for variants of the same class of issues across the code base.
What are some good skills to run is from Trail of Bits which are open-source: https://github.com/trailofbits/skills
If it's C/C++, LLM's are pretty good at making fuzzers and seeding the dictionary needed to fuzz them effectively.
If it's open-source you can apply for some openai codex api grant: https://openai.com/form/codex-open-source-fund/
36
0
7
0
Open post
I know Mastodon hates LLM's and AI. So here goes!
I recently got access to trusted access of cyber capabilities of both openai and anthropic, which also allows you to weaponize security vulnerabilities.
The speed at which these parrots can find bugs and be creative enough to exploit them is staggering.
I recently pointed an LLM at an kernel fix that was reachable by an unprivileged namespace on Debian and it fully weaponized it, without too much me prompting it in the right direction, in about 7-9 hours.
I don't think open-source and companies will know what's coming for them once these open-source weight models will have broader reach and get better at exploiting vulnerabilities on a massive scale as anyone can access them.
The bottom line I think is, you cannot patch faster than the attackers can easily chain all kinds of vulnerabilities together and just move laterally on an incredibly fast pace.
I've started reporting vulnerabilities to all kinds of projects and the majority have trouble or patching issues found. There's not enough maintainers, or there's simply none anymore.
I've been getting quite worried about what our future will look like for data privacy. I think outright not running an LLM over your codebase to find critical security vulnerabilities because of your moral stance will keep us more insecure.
Please run an LLM over your code base if it's internet facing or something critical, we thank you!
Can't wait for the discussions on this!
246
88
177
17
Remote instance
infosec.exchange
Open on original server