201 karma · joined March 16, 2021
It feels like people put more value on memorizing facts than writing them down, as if it’s somehow more noble to remember something about someone, but if you write it down to not forget it, it’s suddenly not as valuable a gesture.
I never understood that.
I had a problem (bad memory), I cared enough to find, and create a solution, and consistently use and maintain it, it’s way more work that I’m putting in to make sure I remember things about the people I care about vs just having it memorized better than another person by the virtue of my genetics.
This is not a criticism or a shot at smugglerFlynn here though, they already said they’re not the target audience. It’s just my personal experience and this looked like a good starting thread to post it under.
I’ve been battling the same problem, and I solved it by keeping the state in my brain, long focus hours, and breaking down the problem to smaller chunks that agents could almost one-shot. That made me the bottleneck, and although I can do it for codebases I’m familiar with, working on totally new projects has been very painful.
I’m going to test it in my own vuln research workflow.
Also, Davinci Resolve has added photo editing functionality since 2 V21 iirc, but it’s not a drop-in replacement. It’s Davinci Resolve though, so expect to be blown away.
Jokes aside, the probability of it being exploited is low though.
Also, this assumes pc1 has a publicly, where as with Croc and MW, you can transfer files between two PCs on both behind different NATs.
It started with agreeable cases, then ended up on a holier than thou attitude.
I currently have two reports (one RCE on a famous OSS ML platform, one cluster take over on a k8s related projects), both are more than 2 months old without as much as an “F you, get lost”. Just got ignored and ghosted, which hurts a lot, because I spent a lot of time finding, and verifying these (all reports with poc and patch). BUT I understand why it’s happening, because I’m also on the receiving end.
security@ and VDPs have always received BS reports and beg-bounties, but boy oh boy, these days we have two people spending 3-4 days a week sifting through this constant flood of garbage compared to 2-3 tears ago where 1 person could triage the inbox and VDP in a day’s work max, which would’ve been considered very busy. Unfortunately we can’t just shutdown the programs or the mailbox because 1. We do occasionally get important and great stuff that actually matters, and 2. We’re a critical infra company and can’t ignore anything really.
The signal to noise ratio is almost zero, but the “what if” is keeping us swimming through this unending river of garbage and burning us out.
Overall, chaotic mess on both sides.
Ending on a doom-and-gloom note: there will be a reckoning.
(Don’t take the note too seriously though, I’m a SecEng, so I have a built-in doom multiplier lol)
> The flow of data was so hard to follow, it seemed like someone was trying to cover up a murder.
> Just getting the code to run on your laptop took a week.
I always thought I’m the only one having problem understanding the data flow, or setting up a proper dev environment. Impostor syndrome (and sometimes toxic environments that pushed for “velocity”) didn’t help either.
Felt good to know I’m not the one.
I've seen it make the codebase vulnerable by changing the source, then claiming it found a vuln, or finding a well-defended and secure exec function, write a unit test that shows what exec does (which is running commands), then claiming a critical finding.
I wasn’t paying for the code tbh, I could always self-host (VaultWarden) at home behind Tailscale, it was all about the management, uptime, and most importantly, supporting a good software I used and loved for years.
Sad, really.
I’ll either move to self-hosting it at home behind TS, or going back to keepass tbh, anyway, I’m not staying on a sinking ship.
P.S: VaultWarden had a few bad CVEs this year (like an Auth Bypass), but when I looked deeper, it wouldn’t have much of a negative effect on me as a self-hosted home user that shares everything with family.
RIP dude, we’d continue the jokes, may your soul laughs as hard as we do.
Chuck Norris once bet 42 is a prime. He won.
Let’s hope one of these fake AI grifters doesn’t take this as a serious idea, raised a couple hundred million, and do real damage.
(I’m not against AI, I just don’t like nonsense either in tech, or people)
Question about this:
“Threads are positioned in the timeline by the original post’s created_at; replies within a thread are sorted by their own created_at ascending.”
Does this mean, I, as the person replying to the post can manipulate my reply time to say, 3 minutes before person X’s reply?
If so, I can imagine a few adversarial ways of (ab)using this.
I understand this is more for friend groups, just curious if my understanding is correct.
> The concept itself doesn’t even make sense if you fully understand the intersectional scope of technology and society Societies demands are the things that are unsafe not the technologies themselves
Where can I learn more about it?
Everything I find by searching is marketing BS, or the same half-baked prompt injection protection that only works for cherry picked problems.
Really need some help here finding the right communities.
This made me lol.
It's a good test, however, I wouldn't ask it in a public setting lol, you have to ask them in a more private chat - at least for me, I'm not gonna talk bad about a massive org (ISC2) knowing that tons of managers and execs swear by them, but if you ask for my personal opinion in a more relaxed setting (and I do trust you to some extent), then you'll get a more nuanced and different answer.
Same test works for CEH. If they felt insulted and angry, they get an A+ (joking...?).
A few things help a lot (for BOTH sides - which is weird to say as the two sides should be US vs Threat Actors, but anyway):
1. Detach your identity from your ideas or work. You're not your work. An idea is just a passerby thought that you grabbed out of thin air, you can let it go the same way you grabbed it.
2. Always look for opportunities to create a dialogue. Learn from anyone and anything. Elevate everyone around you.
3. Instead of constantly looking for reasons why you're right, go with "why am I wrong?", It breaks tunnel vision faster than anything else.
Asking questions isn't an attack. Criticizing a design or implementation isn't criticizing you.
Thank you,
One of the "security people".
Imagine you, as a security researcher (or any other persona in the security field), wanted to see what prior works are available around bypassing v8 sandbox using webasm, or if what’s been done or found targeting deserialization in Go.
Using this web app, you can search the indexed and tagged write ups.
Also adding MCP support to it so your agents can search too.
Hopefully going live soon.
P.S: I said HN-like, but tbh it’s just the UI that looks a bit like HN (I’m not a good designer, so got heavy inspiration from HN listing style), otherwise there’s no other overlap in functionality yet.
A few things come to mind (it's late here, so apologies in advance if they're trivial and not thought through):
- Threat Actors compromising an account and use it to Vouch for another account. I have a "hunch" it could fly under the radar, though admittedly I can't see how it would be different from another rogue commit by the compromised account (hence the hunch).
- Threat actors creating fake chains of trust, working the human factor by creating fake personas and inflating stats on Github to create (fake) credibility (like how number of likes on a video can cause other people to like or not, I've noticed I may not like a video if it has a low count which I would've if it had millions - could this be applied here somehow with the threat actor's inflated repo stats?)
- Can I use this to perform a Contribution-DDOS against a specific person?
This is a tasteless copy.