HNHacker News
TopNewBestAskShowJobs

tjbecker

35 karma · joined June 12, 2020

submissionscomments
tjbecker··on Copy Fail
https://x.com/i/status/2049687923814281351

> and yes, RHEL 14.3 doesn't exist We meant to say RHEL 10.1. Sorry for the confusion!

tjbecker··on Copy Fail
For this crowd, I highly suggest checking out the technical writeup

https://xint.io/blog/copy-fail-linux-distributions

tjbecker··on Copy Fail
This is correct. The container escape exploit and writeup is not yet released.
tjbecker··on Copy Fail
I recommend reading the technical writeup https://xint.io/blog/copy-fail-linux-distributions
tjbecker··on Autonomous code analyzer beats all human teams at OSS zero-day competition
This is fair, and we will gladly share the extraordinary evidence as soon as we can.

If you're curious, we have already released the full traces of finding a sqlite3 0day with an early version of Xint Code (submitted to the AIxCC competition and now open sourced): https://theori.io/blog/exploring-traces-63950

tjbecker··on Autonomous code analyzer beats all human teams at OSS zero-day competition
In the commenter's defense, it's reasonable to be skeptical about the level of autonomy claimed in the post.

We are very eager to share more evidence (including the raw inputs and output artifacts for these bugs) and will absolutely do so as soon as we can.

tjbecker··on Remote Code Execution in Slack desktop apps
> Sure, but that isn’t the user’s fault, and they’re the ones who are going to get attacked.

This is true, but the responsibility to protect these users is ultimately on Slack, not the researcher. If Slack's bounties are nowhere near competitive with black market prices, they are failing to protect their users and should be called out on it.