Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Ivan Kwiatkowski

@justicerage@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security Researcher. Writer. Would-be musician. Maintainer of Manalyze and Gepetto. Trolling on a purely personal capacity.

0 Followers
0 Following
7 Posts
Joined November 05, 2022
Twitter:
https://twitter.com/JusticeRage
Blog:
https://blog.kwiatkowski.fr
Manalyze:
https://manalyzer.org
GitHub:
https://github.com/JusticeRage
Book (French):
https://lechantducygne.fr/gestalt/
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 4mo ago

It's been a while since I wrote something in long-form about cybersecurity. You've all heard about Mythos, more than you wanted to I'm sure, and I wanted to do a deep-dive into the actual stakes, impact and terrible PR that followed.

Full article: https://blog.kwiatkowski.fr/mythos

The summary, super toned down compared to the original piece:

Numbers posted by Anthropic are impressive, but hard to evaluate on their own. They certainly found a few good bugs, but most of them were not manually vetted, and for those who were all we know is that experts agreed with the severity rating. All of them could be low impact or unexploitable, we simply have no way of knowing. The same goes for the 170 "vulnerabilities" patched by Mozilla. Not all vulnerabilities are born equal.

However, putting all hype aside, it's almost certain that we'll eventually get to LLMs that are exceptional at vulnerability research. In fact GPT-5.4 and Opus 4.6, as well as open-weight models like Kimi K2.5 have already found high-severity bugs. We were there already.

There may be a future where most exploitable bugs are patched. The transition phase will be rough, and it won't change the fact that phishing is the biggest threat your org is facing.

When you hear a model is "too dangerous for the public", it doesn't mean you. It means China. Yet benchmarks and self-reports from China's AI labs indicate that their frontier models are lagging behind the US ones by 3-6 months only, so I'm not sure what we're trying to do here.

Overall, the "too-dangerous" rhetoric is used more as an argument against open-weight models and open ecosystems. Danger justifies building walled gardens with access control, API tiers, quotas, KYC, and locked-in customers.

China's approach is public models that anyone is free to tweak and run where they like. That is the real ideological divide.

It's not about model quality but access.
Closed ecosystems vs public-owned infra.

I really want the latter win, wherever it comes from.

25
6
15
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 2mo ago
Replying to @CryptoLek@infosec.exchange
@CryptoLek@infosec.exchange I think reviews might not be the endgame and they don't even check them. It's the bait to get you to mule work.
1
1
0
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 2mo ago
Today, I earned 10€ by posting a fake Google review. Short thread. Sorry for the non-French speakers, I'll try to translate. 1) This is a random Telegram ping from a stranger. I express weird enthusiasm at the idea of writing fake reviews. 2) I do write the review: one star, mentioning that that the restaurant buys fake reviews, but also that their service is terrible and that I heard the chef make racist jokes and spit in the soup. 3) I actually get paid for my 5 minutes of hard work.
1
3
0
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 4mo ago
Replying to @catileptic@chaos.social
@catileptic@chaos.social Those are good questions... not that I have any say in the matter. If I had a magic wand, I would make AI common good. I'd have the government run the datacenters in charge of inference for the country, freely available to citizens, with the assumption that it will enable all sorts of innovation without tethering us with a for-profit tech giant. There would have to be private computation, like what Moxie did with confer.to. More realistically, I'm hoping pressure on energy prices will lead to more economically viable models that can run on commodity hardware in 5-10 years, and a world where everyone just has their AI box at home like they have their ISP's router. I've played a lot with agents the past month and the way they help you offload mental burden is really amazing. I can also imagine a future where you don't need software off-the-shelf anymore (no more open-source either). You want an app, you just ask your agent to write it and deploy it to your phone or laptop. I'm not naive enough to believe we'll all get 4-day work weeks thanks to AI, but I'm fairly certain we'll have to figure out how how to deal with mass unemployment, and my intuition is that a form of communism will be the only way out that doesn't create unsustainable inequalities. But this exact problem predates AI, which "just" makes it worse and may create the opportunity. If AI belongs to the public instead of for_profit companies. The best-case scenario is a post-work world, the worst is partial collapse, and I'd bet on a bit of both depending on your social class. As for ecology and how energy is produced... This goes way way beyond technology!
2
0
0
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 4mo ago
Replying to @adulau@infosec.exchange
@adulau@infosec.exchange That's a use case I hadn't thought of at all! Really cool to be able to offload the mentally damaging work.
2
0
1
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 4mo ago
Replying to @aristot73@infosec.exchange
@aristot73@infosec.exchange He makes an excellent point. This is the cloud all over again.
1
0
0
0
Open post
Ivan Kwiatkowski @justicerage@infosec.exchange
· 1mo ago
I've long argued that the 🇷🇺 Doppelgänger-style campaigns have no demonstrated impact on public discourse and rarely exit their bubbles. Yet targeted politicians gain free media coverage, victim status or appear more relevant than they are. https://www.liberation.fr/politique/presidentielle-2027-gabriel-attal-vise-a-son-tour-par-une-ingerence-en-provenance-de-russie-20260805_3ADS475V65E3JCJA2C7SXECSZY/ We've reached a point where all incentives are misaligned. Politicians actually benefit from fake news campaignsWe know troll farms use this as evidence of their impact Do we still need to turn a few thousand bot posts into national stories?
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:25:54 UTC