grecs

Defending networks & #training #cybersecurity by day; researching #infosec by night; running #shmoocon #firetalks each winter; always looking to make the world a better (and more secure) place

grecs boosted:
2025-06-06

Really enjoyed David Gerard's amusing take on how programming with AI becomes like a gambling addiction for many.

"Large language models work the same way as a carnival psychic. Chatbots look smart by the Barnum Effect — which is where you read what’s actually a generic statement about people and you take it as being personally about you. The only intelligence there is yours."

"With ChatGPT, Sam Altman hit upon a way to use the Hook Model with a text generator. The unreliability and hallucinations themselves are the hook — the intermittent reward, to keep the user running prompts and hoping they’ll get a win this time."

"This is why you see previously normal techies start evangelising AI coding on LinkedIn or Hacker News like they saw a glimpse of God and they’ll keep paying for the chatbot tokens until they can just see a glimpse of Him again. And you have to as well. This is why they act like they joined a cult. Send ’em a copy of this post."

pivot-to-ai.com/2025/06/05/gen

grecs boosted:
2025-05-05

Happy Star Wars Day! May the Ni! be with you.

#StarWars

monty python and the holy grail artwork in the style of the original star wars poster
grecs boosted:
Paco Hope #resistpaco@infosec.exchange
2025-04-20

I am amused that “futurism” is talking about how something from 75 years ago is “the future.”

futurism.com/the-byte/subaru-b

grecs boosted:
nixCraft 🐧nixCraft
2025-04-20

A verified ID is required to access AI models in OpenAI's API to prevent IP theft. 😂 They went from stealing everything from everyone to now claiming it's their original work, despite hundreds of pending copyright cases against them in the courts. Why is this even allowed? That's hypocrisy at best.

OpenAI identity verification screen with "Begin verifying" button.
grecs boosted:
2025-04-19

Well someone took that a little literally...

grecs boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-04-19

That moment

grecs boosted:
nixCraft 🐧nixCraft
2025-04-19

Software developer job interview madeofmistake.com/proglang

A four-panel comic strip showing a job interview where the interviewer expresses surprise that the candidate's custom programming language, XYZZY, is only a year old, as they are looking for someone with eight years of experience in it. The interviewer sighs in the final panel, wondering why it's so hard to find good people.
grecs boosted:
Security Onion 🧅​securityonion@infosec.exchange
2025-04-19

Quick Malware Analysis: Kongtuke Web Inject pcap from 2025-04-04

blog.securityonion.net/2025/04

grecs boosted:
2025-04-11

I've pulled down the most recent episode of Wide World of Cyber with Chris Krebs and Alex Stamos at the request of their employer SentinelOne, the sponsor of the series. I will say more about this in next week's Risky Business, but I want to make one thing clear: SentinelOne is not the bad guy here

grecs boosted:
David Schuetz *Looking for work*darthnull@infosec.exchange
2025-04-11

I've been hacking at stuff for years. And by hacking, I mean literally, approaching real-time problems ("gotta figure this out NOW”) with a deep bag of tricks developed over, wow, decades of experience with UNIX systems.

The bag of tricks includes a bunch of command line tools like cut, sort, uniq, awk, grep, and others, which I've used extensively when looking for "unknown interesting things" in large flat-text data files. Like big log files. Or other sources.

Recently, @Verso asked a question that caused me to think a little more about this bag of tricks I've built up, and that lead to my latest post, which you can find here:

darthnull.org/slice-n-dice/

It's a bit long, and it's all about crazy ways to quickly analyze data. Mostly, probably, the *wrong* ways to do this, but it gets me answers quickly. If not final, actionable answers, then it at least gets me asking better questions, at which point I can use more elegant and situationally-appropriate tools instead.

Anyway, it's a window into ... the unix philosophy taken to an extreme.

grecs boosted:
2025-04-08

If you want to submit vulnerability reports/findings via Bugcrowd, you're going to need to enable 2FA. Kind of crazy that it wasn't mandatory before, actually.

"We recently accelerated this work on our product roadmap after identifying threat intelligence involving leaked credentials from other bug bounty platforms. While Bugcrowd was not impacted, the situation highlighted how critical it is to stay ahead of potential threats."

bugcrowd.com/blog/bugcrowd-sec

grecs boosted:
2025-04-08

T-Minus Four (4) Days until BSidesCharm 2025...

What do you mean you don't have your ticket yet?

bsidescharm.org/registration/

grecs boosted:
Very Hairy Jerryjerry@infosec.exchange
2025-04-05

Happy 8th birthday to infosec.exchange 🎂🎈🎈🎉

grecs boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-04-02

Hello friends. The dreaded and long awaiting blog on WHAT THE FUCK HAPPENED TO THE CYBERSECURITY JOBS MARKET has arrived.

tisiphone.net/2025/04/01/lesle

I'm sorry.

grecs boosted:
Marc Ruef :verified:mruef@infosec.exchange
2025-03-26

Open Source devs say AI crawlers dominate traffic, forcing blocks on entire countries #ai arstechnica.com/ai/2025/03/dev

grecs boosted:
2025-03-23

This is your last chance to book your BSidesCharm room at the discounted hotel rate!

If you haven't booked yet, Monday is the deadline. To book at the discounted rate use the room rate link on our venue page: bsidescharm.org/venue/

grecs boosted:
World Wide Web Consortiumw3c@w3c.social
2025-03-13

Today is the anniversary of the invention of the World Wide Web in 1989 by Tim Berners-Lee.

W3C has continued to expand on what the web does by our mission to make the web work, for everyone. We bring together global stakeholders to develop open standards that enable a World Wide Web that connects and empowers humanity.
w3.org/mission/

grecs boosted:
John Overholtoverholt@glammr.us
2025-03-13

When somebody vandalized their building, this design studio responded the only way they knew how.

They made it into a typeface.
revengefont.com

Via @metafilter

A building fronting the Thames with spray painted graffiti tags of Rusht, Gewey and Pistol Pete
grecs boosted:
2025-03-11

Finally, after 11 years and 97 days, @haveibeenpwned has a new look! Today, we're "soft launching" the rebrand, that is we're giving everyone a look and welcoming contributions, but you won't see it on any publicly facing assets yet. What do you think? troyhunt.com/soft-launching-an

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst