Ben Herzog

Security Researcher @research.checkpoint.com. I liked em dashes before it was cool

2025-06-10

That Apple paper about #ai is a cogent argument for code execution in the chain of thought. You try writing down the solution to 10-disk Towers of Hanoi; soon enough your verbal reasoning checks out for a coffee break, and you're an instruction-following automaton. Indeed it's not a job fit for an LLM, strictly speaking.

Just the other day I created what I consider an intermediate-level CTF exercise, which involved correctly determining the value of 25 bytes with very specific constraints. o3 one-shotted it -- exactly by heavily abusing Python in the chain of thought. If you want to say "that's not the LLM reasoning, that's -- " then fine, let's go with whatever other terminology. o3 basket-weaved the problem into a solved state. We're looking at a future full of this kind of basket-weaving.

2025-06-05

Later this year, I will be speaking at #VB2025 (link) about the full RE of Akirav2, a piece of ransomware written in Rust. For the many people who've asked me about methods and techniques that can go all the way to fully take apart an actual malicious Rust binary found ITW: congratulations, you've lived long enough to regret your wish.

2025-06-04

I fear not the man who has written 500 concertos once, but I fear the man who has written the same concerto 500 times

2025-05-30
2025-05-22

Reconnecting with an old friend after two years of silence, I am debating how long it'd be polite to wait before I say "so have you heard about Expedition 33", then a minute later he says "so have your heard about Expedition 33". This is proper fever, I don't remember the last time something like this has happened. Macron is right to be proud.

Ben Herzog boosted:
2025-05-22

All this is happening because you didn't forward that email to 10 people.

2025-05-21

Your personal slack channel opens with: "This is your space. Draft messages, list your to-dos...". Coincidentally, the mantra of the reality-ending cult featured in SCP-1425 ('Star Signals') opens with: "Now is our time. Here is our space. We take your star. We hold your bonds. Repay your debt"

Ben Herzog boosted:
John Regehrregehr
2025-05-16
2025-05-15

Every time I listen to "Piano Man" I get these intrusive thoughts about patrons literally putting bread in Billy Joel's jar, and the person next to him trying to force himself into a younger man's clothes

2025-05-11

Message due to some misconfiguration: "you pushed to topic_branch in 3 weeks". I am obligated to put on the theme from 'back to the future' before I take any further action

2025-05-08

Good time to remember this 2013 lyttle lytton contest entry, due to Sebastian Grillmaier:

Pius XIII stood on the balcony, triumphant. Earlier, when the white smoke had vacated the chimney, not one citizen of FurRome would have bet on a Shiba‐Inu to emerge.

2025-05-05

@fr0gger One time I submitted a harmless prompt to ChatGPT that happened to contain the phrase "purely hypothetical". Boom, policy violation. Took me a second to understand what happened and slightly rephrase.

Ben Herzog boosted:
Inspirational SkeletoršŸ’€skeletor@mas.to
2025-05-03
Discussions are always better than arguments, because an argument is to find out who is right, and a discussion is to find out what is right.
2025-05-03
2025-04-28
Ben Herzog boosted:
Ɖmilio Gonzalezres260@infosec.exchange
2025-04-25
Ben Herzog boosted:
alexanderkjallalexanderkjall
2025-04-21

Today my compiler told me "expected future, found a different future".

And I'm like: me too buddy, me too

Ben Herzog boosted:
2025-04-21

lol, no

Screenshot from editor where GitHub Copilot suggests naming a variable "Maxerals" after the first one in the struct was named "Minerals"
2025-04-21

Wait until you see the historical, inflation adjusted, cost of lost time due to people saying "please" and "thank you" to each other

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst