Jason Robinson

15 posts

Jason Robinson banner
Jason Robinson

Jason Robinson

@9thousandbytes

CEO of Auspex Labs Inc., a cybersecurity consultancy. 30 years in enterprise IT spanning AI/ML, cloud architecture, and cybersecurity.

Katılım Ocak 2026
35 Takip Edilen4 Takipçiler
Jason Robinson retweetledi
ProPublica
ProPublica@propublica·
Vaccines were once so uncontroversial that McDonald’s restaurants put the childhood immunization schedule on their tray liners. Now, as the U.S. government sows doubt, preventable diseases could come roaring back. propublica.org/article/rfk-jr…
English
57
830
1.6K
46.5K
Jason Robinson
Jason Robinson@9thousandbytes·
@kevinhoff I often discuss sycophancy and alignment with respect to AGI. The people who advocate that ChatGPT-3 wasn't AGI because it wasn't perfect and made things up, clearly hasn't spent enough time with people outside of their own circles.
English
0
0
1
30
Kevin Hoff
Kevin Hoff@kevinhoff·
Social media trained everyone to optimize for the response, not the insight. It's the sycophancy loop applied to humans. Post what gets validated, repeat. Well, I reject this formula. I much prefer just staying loose, or what others are now calling it, Retardmaxxing.
English
1
0
1
35
Jason Robinson
Jason Robinson@9thousandbytes·
@kevinhoff @karpathy There is a profound problem with the NPM library sprawl. Supply chain attacks are continuing to increase and it is harder and harder to keep on top of it. My approach is to use Dependabot unless I am feature seeking.
English
1
0
0
25
Andrej Karpathy
Andrej Karpathy@karpathy·
New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-com…
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
564
1.1K
10.5K
1.6M
Jason Robinson
Jason Robinson@9thousandbytes·
@CyberRacheal The video codex compresses data, so frames with little change use less data than data with more changes. Those deltas are going to provide a finger print for the film you are watching.
English
1
0
3
1.1K
Cyber_Racheal
Cyber_Racheal@CyberRacheal·
Interviewer: When you're using a VPN, your ISP can still see how much data you’re using, but they can't see what you’re doing. However, if you're watching a 4K movie on Netflix over a VPN, a sophisticated ISP can still guess exactly what you're watching just by looking at the "shape" of your traffic. How is that possible if the data is fully encrypted?
English
34
12
93
47.7K
Jason Robinson
Jason Robinson@9thousandbytes·
@pmitu As long as a we are making rocks think there will be AI, the field is about 70 years old. What will be after Large Language Models? Neuromorphic systems. System that learn and think, not just pattern matching, but really understand the information that they are working with.
English
0
0
0
470
Paul Mit
Paul Mit@pmitu·
What will come after AI?
English
9.5K
530
6.3K
1.8M
Jason Robinson
Jason Robinson@9thousandbytes·
Humans in the Loop may not be the best path. @jason.robinson/the-knowledge-machine-what-if-ai-could-learn-without-us-504c93eb6124" target="_blank" rel="nofollow noopener">medium.com/@jason.robinso…
English
0
0
1
17
Jason Robinson
Jason Robinson@9thousandbytes·
I have been working on an AI project. Please take a read. @jason.robinson/structural-alignment-why-training-ai-to-be-good-isnt-enough-a5667e471ac2" target="_blank" rel="nofollow noopener">medium.com/@jason.robinso…
English
0
1
1
26