Remote
Principal Penetration Tester
OSCE3, OSEP, OSWE, OSED, OSCP penetration testing certifications
Learning guitar, likes cute animal pictures and bespoke custom keyboards
0
Followers
0
Following
11
Posts
Joined November 08, 2022
Posts
Replying to
@Leslie_M@mastodon.social
@Leslie_M@mastodon.social gorgeous photo
Open post
Replying to
@mttaggart@infosec.exchange
@mttaggart@infosec.exchange They are openly admitting negligence. Must have gotten too big to contain the information so posting publicly was better than the inevitable leak of same.
4
0
0
0
Open post
Replying to
@hacks4pancakes@infosec.exchange
@hacks4pancakes@infosec.exchange The ignorant masses brainwashed from a young age with ceaseless propaganda. I was one of them until I had the opportunity to travel to many countries and see the good and the bad. From huts with now power or water to old world cities and more. When you look back at the US from the outside, it looks different. You can see what you have as well as what you are missing.
0
0
0
0
Open post
Replying to
@vpz@infosec.exchange
10
3
6
0
Open post
Replying to
@shootingtsar@mastodon.social
@shootingtsar@mastodon.social @thief_of_fire@infosec.exchange @Doug_Bostrom@scicomm.xyz @QasimRashid@mastodon.social Elon is a master conman. Literally The Best. It’s his super power.
Who has a fleets of self driving cars in major cities? Waymo not Tesla. Who has a leading AI lab? OpenAI and Anthropic, not xAI. Who has robots that businesses deploy? Boston Dynamics, not Optimus. The list goes on.
As far as I can remember, the only pitch he has delivered on is Starlink. Which is quite impressive. But nothing to justify have the P/E ratio at which Tesla trades or the valuation SpaceX received. Hype. Hype. And more Hype.
0
3
0
0
Open post
Replying to
@allpoints@mstdn.social
@allpoints@mstdn.social @mclare@recurse.social @pluralistic@mamot.fr 100% agree. Everything has moved to a license to use. You may own the hardware, but not the software. Which often means the hardware is limited to unusable for the average person without consenting to the software's demands.
A modern iPhone is a good example. While you may own the hardware from a legal claim perspective, Apple controls the bootloader, application signing, etc. Even after they have said the hardware is out of support, they offer no capability for the hardware "owner" to run anything on the device other than what they provide.
For an old Android phone that may be different depending on the unit. There is generally more support for alternatives OS and application stores with certain models.
5
0
0
0
Open post
Replying to
@nyanbinary@infosec.exchange
@nyanbinary@infosec.exchange https://www.cisecurity.org/controls/cis-controls-list The list has evolved, but the fundamentals have been the same for a long time. Mythos has increased the desirability of adding threat exposure management to vulnerability management’s toolbox. The volume and pace of vulnerabilities will overwhelm the “patch everything” teams. Exposure management will help teams prioritize on what weaknesses attackers can actually reach. And being open to compensating controls, mitigations, etc., rather than seeing patching as the only way. Patching is the goal, but you may need to act faster than you can patch, so get comfortable exercising additional options to protect assets.
0
0
0
0
Open post
Replying to
@simon@fedi.simonwillison.net
@simon@fedi.simonwillison.net Also it’s 300MW. People often don’t look at units. They recently made deals totally 11GW with Amazon, Google and Microsoft. IMO this is only news worthy because it has some relation to Elon Musk. Like the OpenAI lawsuit it’s all part of the run-up for the SpaceX/xAI IPO. An IPO that could allow SpaceX to buy Tesla and trigger his payout clause. He has being the first trillionaire as incentive to get this right. He is a master at this (or employs those who are).
0
0
0
0
Open post
Replying to
@Strandjunker@mstdn.social
@Strandjunker The US prioritizes the extremely wealthy over everything else. It allows them to control the all the talking points the public hears from birth. The indoctrination into the diligent worker is deep. The US allows the extremely wealthy to control the government. This allows them to siphon off the wealth of the public. And with that mostly gone now, they siphon off the wealth of the government. Privatize profits, socialize losses. All the while sending local jobs overseas to improve profits. The public and the government is drowning in debt while the wealthiest people and companies are growing their wealth like never before. Because they controlled the message from the beginning, we let them do it and are still letting them do it.
0
0
1
0
Open post
Replying to
@david_chisnall@infosec.exchange
@david_chisnall I think it’s entirely possible that Mythos never touched the Claude Code source that was leaked. Furthermore, it wouldn’t surprise me that Anthropic doesn’t have a great code quality or code security review pipeline even though Anthropic may be marketing a model to help other companies with security tasks. My internal penetration testing team has found dozens of critical vulnerabilities in dedicated security products that claim high security and who say companies should buy their product to improve their security posture. Some of these companies have good security research teams that regularly post detailed security analyses on the weaknesses they’ve found in other products. Yet they didn’t find what a small team found in their own product even with access to the people who made it, source code, etc.? More likely it’s corporate silos operating independently. That could be what is happening here too.
1
1
0
0
Open post
Replying to
@mattblaze@federate.social
@mattblaze@federate.social This post reminds me a lot about Operational Technology security. It is also non-trivial to fix certain security issues and they treat it like a kind of restricted knowledge. The physical system they manage was made by a company that no longer exists and it would be tens of millions of dollars to replace. But now things are ever more connected and networked. Knowledge of the process, as-in the plant’s process, becomes weaponizable information.
0
0
0
0
Remote instance
infosec.exchange
Open on original server