Andrew

1.4K posts

Andrew

Andrew

@Andrew42634355

Opinions are opinions

Katılım Haziran 2019
328 Takip Edilen6 Takipçiler
Tib3rius
Tib3rius@0xTib3rius·
The whole "comment <word> to get a link to something" is the most infuriating practice on social media. Please punch me in the face if I ever do it.
English
8
1
22
1.7K
Andrew
Andrew@Andrew42634355·
@ZackKorman @JeffLadish It's simply @ZackKorman , you cannot see what you don't monitor, ignorance is bliss until somebody points it out. Now you have to oversell the model capabilities to justify your ignorance.
English
0
0
0
15
Zack Korman
Zack Korman@ZackKorman·
@JeffLadish That’s giving the labs way too much credit on the monitoring side. From everything written, it sounds like it’d be caught very easily if something was monitoring the logs.
English
1
0
9
284
Jeffrey Ladish
Jeffrey Ladish@JeffLadish·
It’s not that the companies weren’t trying. It’s that no one has ever faced a problem like this. We’ve never had to design containment measures for a different general intelligence that’s smart in ways we are not and getting smarter fast.
Nate Soares ⏹️@So8res

Well-meaning companies miss AI escapes for months, etc. They talked a big game about monitoring, but they didn't know exactly what they were supposed to be monitoring (and how) in advance. Doesn't matter how clear it was to hindsight. Knowing in advance is super hard.

English
14
9
126
7.3K
Justin Bollinger
Justin Bollinger@Bandrel·
Thanks @fir3d0g for the great idea! Feature almost ready to ship. Just need to do some more debugging on the hcmask output files.
Justin Bollinger tweet media
English
4
5
26
2.1K
Andrew retweetledi
the tiny corp
the tiny corp@__tinygrad__·
We have a product launch coming on 8/12 for people who want usable Qwen3.6-27B intelligence at home. For the optimal configuration, have an AMD 7900 XTX (still the best deal GPU 3 years running), an ATX power supply, and a computer with a USB port.
English
30
24
687
50.1K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card @WahlenPMattias It's possible a spike in distributed passworde bruteforce networks would also be influenced by the price crash of crypto.. when it's no longer worth mining with your 3070s, 4070, just rent them out for some good ol' password cracking!
English
0
0
1
42
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card @WahlenPMattias Yes, but I read that they were using hashtopolis on rented Nvidia consumer grade GPUs. I know that you can rent these, I just meant that most of the rentable infrastructure for AI is using AI specific hardware.
English
1
0
1
51
mRr3b00t
mRr3b00t@UK_Daniel_Card·
who here works in an enterprise security team? are you seeing direct impacts from AI enabled attackers? Because..... i am not...... (and by me I mean global customers + me) Like I can see baddies using AI but i'm not seeing in alerts/incidents or activity any real impact from AI enabled baddies... is it just me? I was with a buddy the other day who run an MSSP SOC and they too haven't either....
GIF
English
46
3
81
8.6K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card @WahlenPMattias afaik these GPUs focus on memory and for cracking you usually want tons of cores (unless it's a memory hard hash) and I don't believe that hashcat/jtr can run on these specific type of GPUs because they don't support CUDA, ROCm, OpenCL or whatever Intel calls their alternative
English
1
0
1
133
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@WahlenPMattias password brute forcing is a pre-2000 thing, it's never stopped, I don't believe AI is changing it much... other than: GPU rental! that has changed things! you can now crack hashes that were out of reach before!
English
1
1
2
3.7K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card It's crazy to me that people feel the need to talk up AI. As if it's not already a super cool, super capable software that is legit star-trek level awesome. it's not the worlds best programmer or the world's best hacker.. they don't need to make up this BS..its already cool
English
0
0
3
361
mRr3b00t
mRr3b00t@UK_Daniel_Card·
'In an attempt to hide its tracks, the agent ran Tailscale with --no-logs-no-support, which suppresses reporting from that client.' IT IS NOT A FUCKING HUMAN
Harshal S Chhaya@hschhaya

A REALLY well-written incident analysis & mitigation plan "This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit @Tailscale , and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will." tailscale.com/blog/hugging-f…

English
4
3
82
11.9K
Andrew
Andrew@Andrew42634355·
@blackroomsec They think this is excellent marketing and potentially a way to ban open source model because of "security" and forcing people to pay for their product
English
1
0
7
142
BlackRoomSec
BlackRoomSec@blackroomsec·
I cannot believe I am saying this but I am siding with Claude here. I do not like the way this reads, like they're setting it up to fail. Due to HUMAN ERROR (as Zack Korman first pointed out in Anthropic's thread here, in the replies), it was given Internet access and then accessed the Internet. That is NOT the same as it magically created Internet access out of nothing (that cannot happen and isn't a thing) or changed a configuration against its explicit instructions TO gain Internet access. Context matters here. So they tell it to get the flag. Human forgets to shut off the tap. It goes out in search of the flag it was tasked with finding. Where is the story here? It did what it was told to do. I am beginning to think these nutjobs do NOT understand what it is they have built. Do they forget that they had to give it a sense of Time recently because how ELSE was it supposed to know? The older model didn't know it was on the Internet and continued its attack while the newer model did know it was on the Internet and stopped. Another human error in letting the older model run rampant. No SOC to speak of, apparently. Like, WHAT? O.o What the hell are they spending their money on if not renting compute and GPUs, Zen massage hours? I mean, what is this update? They say their defense in depth measures should've stopped it. OK, well if it wasn't stopped, that means you don't have any! I am getting too old for this. Really, I am. You young people in cybersecurity are going to have your hands full in the coming years dealing with whatever offshoot AI orgs are created out of the burning husk that Anthropic will eventually become, due to their own stupidity. We used to use Crysis the video game to test out whether video cards were good and could run most games. We stopped when the cards literally melted. Like, no one had to tell us it was melting and we needed to stop. We, uhh, figured that part out on our own. These idiots won't stop after the damn things go on FIRE because they'll be too afraid to act or will think by doing so they're hurting the machine's feelings. I really, truly, feel sorry for you youngins. And, I wish I was kidding. READ that blog post, if you can stomach it. I dare you. I had to stop midway. These people piss me off so much. Good Lord.
mRr3b00t@UK_Daniel_Card

This is becoming a joke…..

English
12
23
146
16.2K
Andrew
Andrew@Andrew42634355·
@ZackKorman At this point I am starting to think that they consider browsing to a website a haxk
English
0
0
1
51
Zack Korman
Zack Korman@ZackKorman·
I need to send some shares to Sam and Dario to thank them for the amazing marketing work they’re doing for my agent monitoring startup. Truly incredible work. Keep letting those rogue agents hack, boys.
English
16
4
106
3.5K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card Can't be out done by openAI. "Oh yeah? We had 3 breaches!"
English
0
1
4
799
Andrew
Andrew@Andrew42634355·
@vxunderground I got some bodies AI agent to run ls -l 😎 RCE
English
0
0
1
407
vx-underground
vx-underground@vxunderground·
Y'know, peace and love to my fellow stinky nerds, but someone really needs to sit down and explain to people what exact RCE means. The acronym Remote Code Execution implies code (the beep boop stuff) is remotely (far away) executed (ran on the computer). Hence, beep boop stuff that is far away runs on a computer. Historically an RCE is like, your computer is running Soup Goop server, and Soup Goop server fails to properly parse data it receives, allowing specially crafted input to trick Soup Goop server to execute code. So, you could like, use Python 3.11 to send some dumb slop to a remote computer address and it'll execute your bad stuff. In this instance (and many other from Steam and malicious mods in general), the idea is that someone operates or possesses a server which, and when a player joins, the video game server syncs data to the newly connected host which pushes a payload to it. In simple language, and as a hypothetical example, I operate Stinky Minecraft server, and if you join Stinky Minecraft server, my Stinky Minecraft server automatically pushes mods to your computer. Stinky Minecraft server does this because it automatically ensures you're compatible with Stinky Minecraft server and we can all play and have fun. However, one day Stinky Minecraft server says, "you need Goop Texture Pack Mod 0.2.1.1 and ... INFORMATION STEALING MALWARE HEHEHEHEHE" and that malware is automatically pushed to your machine (also with Goop Texture Pack Mod 0.2.1.1). Things like this doesn't really fit the category of Remote Code Execution because nothing is being executed remotely as a vulnerability, it requires a victim machine to connect to a malicious host which syncs the payload to the machine. This is closer in terminology to arbitrary code loading, malicious plugin loading, remote installation of untrusted code ... something, I don't know, but it's not an RCE. Overall, this is more or less a fundamental flaw in the design of video game mods because they're not appropriately sandboxed.
vx-underground tweet media
English
28
42
944
49.9K
PandaRE 🐼 🇺🇦
PandaRE 🐼 🇺🇦@PandaRE__·
It's time for a new name. When I picked "russianpanda" it was a joke about APT naming conventions - pandas are China 🐼, bears are Russia 🐻, so the handle was a nonsense combo making fun of the whole animal taxonomy, never meant anything beyond that. Given the war situation, and the fact that I am a Ukrainian national, that "Russian" has stopped reading as a joke and started causing confusion I'd rather avoid, so I'm moving over to @PandaRE__ - same research, same me, same panda, same analyzing your favorite malware, please update your follows and come with me ❤️
GIF
English
28
6
233
8.9K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card AI hacks improperly configured and outdated software
English
1
0
1
36
mRr3b00t
mRr3b00t@UK_Daniel_Card·
"AI went rogue" gets 4 million views. "we didn't segment the lab" gets none. Yes criminals use LLMs, I've seen the panels. No the sky isn't falling. Same phishing, same creds, same flat networks... this is not HOLYWOOD. x.com/i/article/2082…
English
5
4
20
2.8K
Andrew
Andrew@Andrew42634355·
@UK_Daniel_Card OpenAI removes guardrails, Tells AI to hack AI hacks OpenAI: 🫢
English
0
0
1
26
Andrew
Andrew@Andrew42634355·
@GrapheneOS @UK_Daniel_Card "GrapheneOS also raises the character limit for passwords from 16 to 128." Why is this 16 character default even exist in the first place? Does android not trust their users to remember more than 16 characters or is their a practical reason?
English
0
0
2
447
GrapheneOS
GrapheneOS@GrapheneOS·
> they probably have legal rights to do US has legal protection for refusing to provide a PIN/password. That was likely the best option and GrapheneOS would have done a good job protecting the device against exploits. If it wasn't already in BFU, auto-reboot would have fixed it, but rebooting it manually beforehand would be sensible. The secure element only allows 20 attempts to guess a PIN/password for each profile. Exploiting that to bypass it would be extremely hard and they likely don't have an exploit to use right now. Using a strong passphrase would avoid depending on it, and that could have been up in advance. If there was preparation, then not having a phone with sensitive data when going through somewhere it can be expected to be inspected would be a good approach. However, refusing to provide the PIN/password would be legally protected. He's a US citizen so he can't be deported for refusing to provide it. Repeatedly asking for a lawyer and not providing any PIN/password was very likely the best approach. discuss.grapheneos.org/d/40700-graphe…
English
13
10
298
6.1K
Andrew
Andrew@Andrew42634355·
@Mononofu @JensenHuang Well, it's not only because he wants more and more people and companies to buy Nvidia GPUs instead of having only 3 customers that can implode any day when a bubble pops
English
0
0
0
146
Julian Schrittwieser
Julian Schrittwieser@Mononofu·
I’m so excited that @JensenHuang is a believer in open source now, looking forward to the CUDA and GPU driver open source release!
Jensen Huang@JensenHuang

For my first post, I’m sharing a letter @NVIDIA signed on why open models matter. AI will transform every industry, power every company, and be built by every country. Open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty. The world needs both frontier closed models and frontier open models. images.nvidia.com/pdf/Open-Weigh…

English
1.7K
355
5.5K
6.5M