Moritz Sanft

1.1K posts

Moritz Sanft banner
Moritz Sanft

Moritz Sanft

@stdoutput

security software engineer, ctf @fluxfingers @[email protected]

Germany Se unió Mart 2019
766 Siguiendo1.3K Seguidores
Moritz Sanft
Moritz Sanft@stdoutput·
I‘m at @1ns0mn1h4ck today and tomorrow. Feel free to drop me a DM if anyone wants to meet :)
Moritz Sanft tweet media
English
0
0
1
92
Thorsten Ball
Thorsten Ball@thorstenball·
It's always like: how much do you squat? Never: how much do you curl? "wow you have strong legs" buddy, my bis are up here
English
5
0
60
7.6K
Moritz Sanft
Moritz Sanft@stdoutput·
@cramforce Ah, thanks! I guess this mostly holds for cut-off JSON objects then. I think that /{"[a-zA-Z].*/ should pretty much always(?) map to "eyJ...". Some also map to "eyI", though, e.g. /{"\d+.*/
English
0
0
3
108
Malte Ubl
Malte Ubl@cramforce·
@stdoutput Don't think so. This is {". Of course, there are other possible beginnings for JSON
English
1
0
1
246
Moritz Sanft retuiteado
Simon Willison
Simon Willison@simonw·
This stunt feels irresponsible to me. If we don't want regular people developing toxic relationships with their chatbots it really doesn't help for leading labs to start giving them "retirement interviews" and encouraging them to blog their "musings and reflections"
Anthropic@AnthropicAI

Second, in retirement interviews, Opus 3 expressed a desire to continue sharing its "musings and reflections" with the world. We suggested a blog. Opus 3 enthusiastically agreed. For at least the next 3 months, Opus 3 will be writing on Substack: substack.com/home/post/p-18…

English
164
138
2K
211.9K
Moritz Sanft
Moritz Sanft@stdoutput·
@zeeg Generally, academic research on this part of applied AI / agents doesn't make a lot of sense imo, even when well-done. The current AI frontier is just moving way faster than the publishing cycles of traditional academia.
English
0
0
0
72
David Cramer
David Cramer@zeeg·
Alright internet lets be clear on two things: Auto generating skills does not mean worse performance for a harness. Nor does having AGENTS files. The papers don’t even support this. Never did I ever think mainstream internet would be reference half baked papers.
English
8
2
27
3.3K
@abdimoalim.bsky.social
@abdimoalim.bsky.social@abdimoalim_·
If you're gonna design a CLI tool, please add loading text/spinners for items queued for download. I don't want to stare at the screen for 15 mins only to get a crash report.
English
1
0
0
1.6K
Moritz Sanft
Moritz Sanft@stdoutput·
I think all of this would come at the expense of having an environment agents aren't very familiar with, with certain papercuts that might hurt them. Although I need to re-evaluate the newest models, my impressions on agents with Nix were very mixed so far.
English
0
0
0
211
Moritz Sanft
Moritz Sanft@stdoutput·
Hey @mitsuhiko! In the Gondolin README, you write "In particular using nixOS is very appealing for agentic use" - what makes you think this? Letting the agent configure the VM image? Or just being able to have certain roolback capabilities?
English
2
0
12
4K
Moritz Sanft
Moritz Sanft@stdoutput·
@mitsuhiko Maybe the fuzzer should be TS in that case though. Perhaps it could integrate Node's coverage API that way. I know that chrome / v8 has one, but I'm not sure how it's exposed in Node.
English
0
0
0
51
Moritz Sanft
Moritz Sanft@stdoutput·
@mitsuhiko Wow! Since you control much of the environment on Gondolin, you could maybe even implement coverage-guided fuzzing. Might be too hard for the clanker to get right without a detailed plan though.
English
1
0
0
253
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
I hope nobody claims that you don't need memory safety because clankers exist.
Armin Ronacher ⇌ tweet media
English
3
0
36
5.1K
ϻг_ϻε
ϻг_ϻε@steventseeley·
Wondering how many researchers have missed multiple pre-auth RCE due to arithmetic evaluation? I can confirm at least 3 researchers have, myself included.
English
2
3
80
8.8K
blasty
blasty@bl4sty·
I'm kind of glad I (competitively) got out of the ctf scene quite a while ago; seeing pwnables get solved by ralph wiggum loops would've been massively demotivating back then :)
English
4
1
91
8.4K
Moritz Sanft
Moritz Sanft@stdoutput·
I've created a Discord server to discuss security research and CTFs in the context of AI and vice versa. I'll slowly try to reach out to people who I think might be interested. In the meantime, if you are, feel free to join: discord.gg/DrASfE58
English
0
0
5
617
Domen Kožar
Domen Kožar@domenkozar·
Today is birthday 🎂 🎊 It's such an exciting time to be alive and create, I wish a good day to all builders 🔥
English
4
0
14
485