Remote
Teaching faculty. Security researcher. Red team, DevOps, AppSec. An academic but not an academic. nerdprof @ Twitter
0
Followers
0
Following
50
Posts
Joined October 28, 2022
Posts
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange Yeah, that's fair. I think - even now - the main point of the event is to try and build community. I think what's changed is the kind of community the experience is curated towards. I've met a ton of people at Def Con that I'm still in contact with and that have absolutely helped me in a variety of ways. I've also learned a ton (particularly at PHV and in some of the trainings).
These days, it feels like the experience is more curated towards the hacker aesthetic than folks who actually want to get their hands dirty. Not to get too post-modern, but it seems more about simulacra than real experience. That said, I bet anything the old guard would say the same thing about the years I was attending.
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange I went every year between 2014-2019. It was absolutely wild to see how the experience changed even in that time frame. In 2014, it still seemed like - for the most part - a big community gathering. 2015 struck me as kind of a peak year, aside from the stupid giant record badges. Tons of actual learning, actual community. 2016ish, it seemed like there were way more folks hanging around from Black Hat. 2017, it seemed like Def Con started catering to them and it was down hill from there. 2019 was exhausting.
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange I'll have to give it a try. Wegmans has had a nice honey-brined turkey breast that grills very well. I've specifically thinking it would be good with some rosemary.
0
1
0
0
Open post
Replying to
@z3r0fox@mastodon.social
@z3r0fox@mastodon.social .
More realistically, why would an industry that makes massive amounts money trying to secure things want to, systemically, secure things?
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange
re: awoo
Hover or focus to reveal
Sensitive
0
0
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange Does the thyme actually infuse much on the grill like that?
0
1
0
0
Open post
My absolute pet peeve is someone sending an AI-generated email that takes me like an hour to write a response to.
0
0
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange I'm increasingly thinking that two of the biggest problems at the moment are the general lack of understanding of tech and an inability to detect social engineering. My discussions have been:
1) Do a feature comparison. Does the AI-enabled system win out?
2) How much does it win by and in what areas?
3) How much does it cost, looking at maybe a 5 year timeline, assuming rising costs when the subsidies companies are providing go away?
4) How does the cost compare to non-AI platforms?
5) How does the differential compare to risk reduction and/or operational costs elsewhere?
Most folks get hung up on 3.
0
0
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange (Serious take) Again? Static analysis in a box has been a thing for such a long time. I've been playing around with some AI tools for static analysis on binaries a bit this summer and there's some definite benefit for streamlining the reversing process, but source code analysis? That strikes me as something non-AI solutions were pretty good at.
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange It's a steaming hot pile of excrement. Absolute garbage, and it seems like the whole thing is a dumpster fire. By the way... What is it?
0
1
0
0
Open post
Replying to
@jik@federate.social
@jik@federate.social Fair point. I don't know anything about what school you're talking about, but there's usually a parent-run parent group on Facebook. Admissions, in particular, tends to watch that closely and take action based on things they see there. My sense is that they see the college decisions more as a parental one than the student and they're deeply worried parents with negative experiences will discourage other parents from having their kids attend.
0
0
0
0
Open post
Replying to
@jik@federate.social
@jik@federate.social If they have a parents group, go make a fuss there. Universities watch those like hawks and are often extremely sensitive to things being said there.
0
1
0
0
Open post
Replying to
on mastodon.social
@Viss@mastodon.social I dunno, but I've been rather surprised Azure's not more popular than it is given how many orgs are locked into doing business with Microsoft in other ways.
0
0
0
0
Open post
Well, this is a phrase I just saw in a course description (not at my school):
"The biblical basis and societal impact of cybersecurity"
0
0
0
0
Open post
RE: https://stefanbohacek.online/@XedYourLastY/116975872109996382
I think this is the most likely of these to be accurate.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange I've seen enough .mil docs that I legitimately cannot tell if this is parody or not.
0
1
0
0
Open post
I've had baby robins, baby grackle, baby blue jays, baby squirrels, and baby bunnies this year. I feel like I should start charging for daycare.
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange Cheers. I completely agree and just wasn't looking at social media yesterday post-morning. I'm sure we're having a totally normal one today, right?
0
0
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange Putting on my college pedant edgelord hat for a second, the core premise here - that every premise is probably true or false - is false per Gödel's incompleteness theorems.
That's not relevant, though. When I was debating, I spent most of my time pinning my opponent down on definitions. I was usually trying to a) understand how they were defining terms and b) forcing them to change their definitions, usually through bite-the-bullet scenarios. Once they swapped over, the rest of the debate was easy. The fundamental problem in discussing objective truth is linguistic. (God, I hate this crap now. Philosophy is the worst.)
Could OpenAI and HuggingFace be making the whole thing up? Sure, and it wouldn't surprise me. They don't need to, though, for this to be a load of crap.
Take HuggingFace's statement. The statement says, "A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration)".
This initially sounds like an access control failure to me, such as an exposed API that doesn't properly authenticate. Would making a request to an improperly authenticated API count as abuse, particularly if the LLM had access to API docs? Would it count as a breach? I imagine there are reasonable differing opinions.
As others have pointed out, this whole thing could be a minor whoopsie-doodle reframed to sound much more grandiose for marketing purposes because of how easy it is to be "technically true."
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange I was a philosophy minor, back in the day. I think the definition of "truth" is not as clear as anyone likes to think.
1
1
0
0
Open post
Replying to
@dalias@hachyderm.io
@dalias@hachyderm.io @cigitalgem@sigmoid.social So, there's some technical info in the HuggingFace statement, but no where near what we usually see in these kind of discussions. HuggingFace mentions they have IOCs (allegedly found by a log parsing LLMs, so probably not up to the usual evidentiary standard we expect), but don't include them.
I think most reasonable people would agree that we probably ought to treat this like any other claim presented with incomplete evidence.
0
0
0
0
Open post
Replying to
@cigitalgem@sigmoid.social
@cigitalgem@sigmoid.social @dalias@hachyderm.io Are there any technical details out there aside from the HuggingFace statement from last week we could use to independently assess the claims from either party?
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange Looks like there's at least some details in the Huggingface statement from last week, but no IOC (despite claims they had the IOC).
https://huggingface.co/blog/security-incident-july-2026
0
1
0
0
Open post
RE: https://mastodon.social/@danielcornell/116963813168908488
I wonder, when did we do away with "PCAPS or it didn't happen"?
Quoting
So if today's hype cycle is to be believed, some OpenAI model hacked Hugging Face
Cool. Cool
I'm just curious - which OpenAI execs are going to have their lives ruined and go to jail for this?
Asking for Aaron Swartz
Open quoted post
0
2
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange Is there any technical evidence in the public discussion?
0
1
0
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange Also, "Man in the middle" to just "in the middle".
0
1
0
0
Open post
Replying to
@jerry@infosec.exchange
@jerry@infosec.exchange I went from 2014-2018 with my wife and it doubled as a vacation. Loved it. Absolutely fantastic. I'd do conference stuff until about 5 or 6, we'd catch a nice dinner, and then so some touristy things in the evening. Usually got in a day or two early so that I could catch some pool time.
I went in 2019 by myself (with a buddy) and, holy hell, completely different experience. I was exhausted by the end of the week. Haven't been back since.
2
0
0
0
Open post
Replying to
@nerdpr0f@infosec.exchange
This toot inspired by someone trying to explain to me how AI can revolutionize my workflow for without listening to what the workflow for is.
In fact, LLMs are particularly good at part of the workflow for but not the specific part this person was trying to engineer a solution for. Incidentally, that's the part of that is easy (almost trivial) for humans.
I'm increasingly thinking requirements analysis and "how to listen to clients" needs to be a required class.
0
0
0
0
Open post
I've never encountered something that causes so many install errors as SecurityOnion. This is bonkers.
0
0
0
0
Open post
... Well, this is wild. A Windows laptop of mine seems to have been blocking other wired systems on the same switch on my desk from talking to the DHCP server in by basement?
0
0
0
0
Open post
We have it no where near as bad as, say, California... But I really hate it that our current dystopia comes with is own dystopian lighting. The weather outside right now is currently yellow.
0
0
0
0
Open post
Replying to
@zackwhittaker@mastodon.social
@zackwhittaker@mastodon.social @cR0w@infosec.exchange There's also a point not discussed enough - a midnight curfew isn't just pushing responsibility onto kids, it's relieving parents of the responsibility of parenting.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange Unrelated, I wonder what the depth limit is for consumer-grade underwater drones.
0
1
0
0
Open post
Open post
Jesus christ. I just watched ChatGPT consult the Merriam-Webster dictionary for firewall syntax.
0
1
0
0
Open post
Replying to
@da_667@infosec.exchange
@da_667@infosec.exchange Have you ever tried growing acorn squash? If you want a ton of meal prep at the end of the season, I haven't found anything better. We had one vine last year that gave us 32. Damn thing was about 40 ft long.
0
0
0
0
Open post
0
1
0
0
Open post
Replying to
@da_667@infosec.exchange
@da_667@infosec.exchange @cR0w@infosec.exchange Back in the day (2005-2013), I was focusing on AI content. I got into cybersecurity largely because the university I was teaching at wanted to offer a class on cybersecurity and ethics. I wanted to teach the ethics.
I stayed because I saw where AI was going and cybersecurity felt way less evil. I had some vague hope at the time that the field might be able to prevent the worst abuses.
The specific trigger for me jumping ship was a data mining conference (circa Snowden, don't recall the specific year) in which I watched a panel of AI researchers bemoan the fact they couldn't literally strap biometric sensors to children 24/7.
2
1
1
0
Open post
Jesus. I've only been online for like 5 minutes so far and the news is an absolute dumpster fire.
I think this is not a day to Internet and it's not lost on me how frequently I've been saying that to myself these days.
0
0
0
0
Open post
Replying to
@Tanath@mastodon.social
@Tanath@mastodon.social @cR0w@infosec.exchange I don't think we are.
I think the problem is the distinction between "legitimate engineering practices" and "legitimate software engineering practices."
The point that we're raising here is that most (maybe very large chunks) of the software engineering follow bad engineering practices, which have been normalized in the software industry. The root cause is, of course, that real engineers have liability and that shifts organizational risk tolerance.
"If you don't know how it works or it's wrong sometimes" is bad engineering.
For example, go try to talk to and mechanical engineer or electrical engineer into including something they don't understand or that could have, say, a 20% error rate into their designs.
2
2
1
0
Open post
Replying to
@nerdpr0f@infosec.exchange
@Tanath@mastodon.social @cR0w@infosec.exchange Two additional quick thoughts.
One: The reason it's not possible with AI (assuming LLMs) is the stochastic nature of these systems.
Two: This, of course, hinges upon a definition of "safe" and establishing risk tolerance metrics.
2
1
0
0
Open post
Replying to
@Tanath@mastodon.social
@Tanath@mastodon.social @cR0w@infosec.exchange You missed a couple of words there. "legitimate engineering practices". Note that it doesn't say "legitimate software engineering practices".
One of those legitimate engineering practices is a verifiably safe design. That, by definition, is not possible with AI.
1
1
1
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange @Sempf@infosec.exchange Can we at least get an infinite number of those coked up monkeys? We're about due for a new Hamlet adaptation.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange
@cR0w@infosec.exchange @Sempf@infosec.exchange No, but I would very much like the news not to be mad libs (no political reference intended) filled in by a 6 year old.
0
1
0
0
Open post
Replying to
@Sempf@infosec.exchange
@Sempf@infosec.exchange I haven't clicked on this link yet, but the text here is a clear reminder that I legitimately have no clue what the next day's news cycle will be anymore.
1
1
0
0
Open post
Quoting
New from 404 Media: we've got leaks from Amazon, GitHub, Adobe, Citi, and more. The big takeaway is that companies in all industries are suddenly throttling their employees' AI use because AI is actually too expensive. Cutting off access to some models entirely https://www.404media.co/companies-are-throttling-employees-ai-use-because-its-too-expensive/
Open quoted post
0
0
0
0
Remote instance
infosec.exchange
Open on original server