Eric Brandel

3.2K posts

Eric Brandel banner
Eric Brandel

Eric Brandel

@AffableKraut

The only way out is through | Stringer, Central Intelligence Corporation

Katılım Ocak 2015
624 Takip Edilen912 Takipçiler
Eric Brandel retweetledi
vx-underground
vx-underground@vxunderground·
vx-underground tweet media
ZXX
31
237
4K
124.1K
Eric Brandel
Eric Brandel@AffableKraut·
@SeamusHughes Mara in the Four Seasons is also great and they have a nice bar as well. Upscale mediterranean. Other great options outside of downtown: Minari, Hai Hai, Vinai, Stargazer. All in northeast Minneapolis.
English
0
0
1
37
Eric Brandel
Eric Brandel@AffableKraut·
@SeamusHughes Spoon and Stable’s lounge/bar. From like 8pm until close. If you’re looking for a spot after that, check out Meteor. Awesome drinks, alt crowd, good stuff. On the other end of the financial spectrum: Flora Room, fancier basement bar underneath Porzana. You enter around back.
English
1
0
1
154
Eric Brandel
Eric Brandel@AffableKraut·
Just found and built my best exploits ever. Really proud of these. The Internet was a mistake. Happy New Year!
English
0
0
0
70
Eric Brandel
Eric Brandel@AffableKraut·
100k users. Tracks every URL you visit. Exfil via hxxps://service[.]voicewave[.]xyz/get_styles_for_web_tts Using a persistent uid on each "styles" request. Via a delayed API call by the extension. Totally legit. Definitely necessary. chromewebstore.google.com/detail/voice-m…
Eric Brandel tweet mediaEric Brandel tweet mediaEric Brandel tweet media
English
0
0
0
129
Eric Brandel
Eric Brandel@AffableKraut·
The only acceptable way to say bye to the LLM that has done good work.
Eric Brandel tweet media
English
0
0
0
70
Eric Brandel
Eric Brandel@AffableKraut·
Buying a bunch of hardware on ebay. Seeing obvious scam listings, looking for this link and it is apparently gone. fun.
Eric Brandel tweet media
English
0
0
0
85
Eric Brandel retweetledi
MG
MG@_MG_·
I’m a bit concerned about the non-inquisitive celebration from infosec on this. Where is the “what does keystroke latency even mean?” Without that, you can’t implement it for yourself, nor can you identify weaknesses. ~3yrs I was privately proposing similar options. So, AS SOMEWHAT OF A KEYBOARD EXPERT MYSELF 🤔💅, let’s look… First, this is most likely NOT a direct measure of network latency. This machine was physically located in Arizona. DPRK started off with shipping corp laptops overseas, but the network latency was a dead giveaway. So they started colocating them in the USA and remotely controlling them. First with remote control software, which is easy to identify if the company has security software on the machine. And then with hardware like IP-KVMs. There are sometimes a few tells that an IP-KVM is in use, but a well tuned one will identify exactly like a normal external keyboard/mouse/monitor. Unless… This is where you have to start looking beyond device identity and instead look at input anomalies. Keyboard/mouse input being sent halfway across the world via network packets to an IP-KVM can look… weird. Think bursts of input. This looks very weird with mouse data that is normally smooth. But even keystrokes start to stand out when you have a big enough dataset to compare against. So, of course, you could improve the IP-KVM to smooth out and “humanize” the inputs before relaying them to the host. But… You can also present some real time control surfaces. I don’t want to blow anyone’s defense tradecraft here. So let’s just imagine the employee needs to play a 5sec game of flappybird each day. Or maybe it’s an overt “DPRK Detector” step during login. The visual input has to travel halfway across the globe, then the input has to come all the way back. That’s a massive delay for response to visual stimulus. Certainly anomalous enough to warrant investigation. How do you beat that? Maybe an AI process running on the IP-KVM that plays DPRK Detector for you? The arms race will continue. And it’s mostly because HR and Hiring Managers don’t want to do deeper background checks needed to identify fake/stolen identities. 🤷‍♂️ And for anyone not familiar with these hunts, the detection techniques are NOT definitive proof of wrong doing. They are simply turning a mountainous hay stack into a fistful of hay that a human can quickly sift through to look for other indicators. Note: there are environment-specific detections as well. But I tried to stay in territory that’s applicable to everyone who has this risk in their threat model.
MG tweet media
English
35
125
1K
126.2K
Eric Brandel retweetledi
urlscan.io
urlscan.io@urlscanio·
The urlscan Threat Research Team identified the first large-scale consumer phishing campaigns powered by WebAssembly (WASM) targeting US gov & financial brands with stronger obfuscation and evasion. urlscan Pro has the full report and what this means for the phishing ecosystem.
urlscan.io tweet media
English
3
23
73
8.5K
Eric Brandel
Eric Brandel@AffableKraut·
Claude has the sad
Eric Brandel tweet media
English
0
0
0
80
Eric Brandel
Eric Brandel@AffableKraut·
AI is learning all the wrong lessons. From some code generated to help test misconfigured settings.
Eric Brandel tweet media
English
0
0
0
76
Eric Brandel
Eric Brandel@AffableKraut·
@vxunderground I’ve got a 14 and 17 year old. The problem has never gone away. Although my sleep is a little better now I guess.
English
0
0
0
53
vx-underground
vx-underground@vxunderground·
Parents, I need your opinion Ever since my son was born my house has been a disaster. It's not filled with trash, there isn't bugs, or anything like that. But, we have INSANE clutter and disorganization. We have mountains of boxes from Amazon we have to recycle, we go through TONS of trash bags now from dirty diapers and stuff. We are always behind on laundry. On top of all of this, we made the mistake of buying him tons of stuff my baby boy has already outgrown. We have mountains of clothing that already don't fit him. My wife and I have also been moving stuff around a lot. We have a bassinet in my office, his "bedroom" (nursery), which means other furniture is literally just pushed anywhere we can fit it. It's dizzying how much is changing and so fast. Did any of you have this problem? Was your house also a mess? My son is 8 months old and everything is happening so quickly I don't even know what's going on anymore. My sleep has been ATROCIOUS since he's been born which makes doing anything else difficult as well. We're first time parents, we planned for the baby, read the books, took the classes, prepared financially, did everything how you're "supposed" to do it and it's still been a whirling wind of chaos
English
274
13
545
58.9K
Eric Brandel
Eric Brandel@AffableKraut·
Just an absolute mess. Probably why this extension was pulled. At _best_ it was someone who thought roll-your-own encryption was a valid development path. Nothing like shipping private keys in your javascript. Extension id: mboheboacomfkpknfbiknphlkbapided
Eric Brandel tweet media
English
0
1
2
237
Eric Brandel
Eric Brandel@AffableKraut·
God I love encountering this stuff when I'm trying to build tools to prevent abuse and malicious activity. Once again, AI safety is amongst the stupidest of pursuits and only hampers defenders.
Eric Brandel tweet media
English
0
0
0
58
Eric Brandel
Eric Brandel@AffableKraut·
The correct number of unapproved browser extensions that companies should allow is zero.
English
0
0
0
52
JayGallagher
JayGallagher@NDJayG·
@awstar11 How can you tell where people are located on this app?
English
1
0
0
57
Fusilli Spock
Fusilli Spock@awstar11·
UK, Japan, Canada, and New South Wales are very upset that I questioned Mark Kelly's motives in his statement.
Fusilli Spock tweet mediaFusilli Spock tweet mediaFusilli Spock tweet mediaFusilli Spock tweet media
English
16
29
238
3.6K
Eric Brandel
Eric Brandel@AffableKraut·
@DataPhysicist Unfortunately the truth of what they’re doing doesn’t garner the same level of attention that people lying about (or, if I’m being generous, misunderstanding) what they’re doing. Google scrapes the internet, it doesn’t need emails and DMs to train anything.
English
0
0
1
241
Nate McKervey
Nate McKervey@DataPhysicist·
They claim your data here is NOT used to train AI models. "Your data stays in Workspace. We do not use your Workspace data to train or improve the underlying generative AI and large language models that power Bard, Search, and other systems outside of Workspace without permission."
Nate McKervey tweet mediaNate McKervey tweet media
English
11
5
101
129.7K
Dave Jones
Dave Jones@eevblog·
IMPORTANT message for everyone using Gmail. You have been automatically OPTED IN to allow Gmail to access all your private messages & attachments to train AI models. You have to manually turn off Smart Features in the Setting menu in TWO locations. Retweet so every is aware.
Dave Jones tweet mediaDave Jones tweet mediaDave Jones tweet media
English
1.2K
69.9K
160.4K
13.5M