Parsia Hakimian

9K posts

Parsia Hakimian banner
Parsia Hakimian

Parsia Hakimian

@CryptoGangsta

"Trust this man, he has a Power Glove." Appsec and Static Analysis @ MSFT. ^(🇮🇷|🇺🇸|🇨🇦)-ian$

Vancouver, BC / Redmond, WA Katılım Haziran 2009
969 Takip Edilen3.6K Takipçiler
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
(Hoping) They are alive and well somewhere, The smallest sprout shows there is really no death - Song of Myself by Walt Whitman
English
0
0
3
185
Parsia Hakimian retweetledi
rand0h
rand0h@dakacki·
Making a concentrated coffee effort to stop mindlessly doomscrolling so replacing that time with watching at least one hacker video every day. Today was @CryptoGangsta’s PowerPoint glove. Need this thing for @WSIIAOfficial 😂 youtu.be/SJ-kfVUoENk?si…
YouTube video
YouTube
English
2
2
11
788
dunadan
dunadan@udunadan·
@CryptoGangsta Did they specify how mini was mini? Maybe specific models were mentioned?
English
1
0
1
376
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
Attended an internal talk by Taesoo Kim (of team Atlanta AIxCC) and holy shit it was a breath of fresh air. An actual nuanced take about LLM vuln research from someone who has already done it as opposed to all the Claude code hype people here.
English
2
4
59
5.8K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@udunadan 3. Issue with Claude Code style VR: AI finds and AI judges. Requires a lot of human capital to verify the code and see the proof. They had much better luck with AI having access to validation harness where it could actually test its hypothesis. Granted a lot of AIxCC is fuzzing.
English
0
0
2
165
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@udunadan What stuck with me was: 1. Larger models do not automatically mean better. They had better answers from mini models that think less and do not hallucinate for specific tasks 2. The LLMs were a small part of AIxCC, the harness and validations are the major part. /1
English
2
0
10
563
tetsuo.cpp (no slop)
tetsuo.cpp (no slop)@tetsuo_cpp·
When you want to learn a new skill, one of the best ways is to observe a master practicing their craft. So when I wanted to truly understand engagement bait, I went to the LinkedIn mines. My takeaway so far is that we should add “agree?” at the end of every post. Agree?
English
1
0
11
715
Haifei Li
Haifei Li@HaifeiLi·
lol, at this point, I don’t why Anthropic needs funding, they can literally short stocks before they announce their new AI tool for the sector and easily make billions.
Haifei Li tweet media
English
2
1
50
10K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@HaifeiLi I don’t know cloudflare said that. I was making fun of the market randomly selling companies
English
0
0
1
113
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@m19o__ It's the perfect opportunity to create SARIF for Markdown!
English
0
0
2
315
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@amaanq It just the building block of every static analysis tool, no biggie ;). Thank you very much for maintaining tree-sitter.
English
0
0
2
25
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
I use models for static analysis everyday. You have to give them targeted prompts and use “traditional sast” to pinpoint the code to ~10KBs of hotspots to get good results. Granted a small code base in my scope is 100MBs of code so YMMV. I am still long tree-sitter.
Claude@claudeai

Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…

English
4
1
35
4.7K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@HaifeiLi Haha yeah I am sure. I literally have to use traditional sast to reduce the code to a few KBs before LLMs become usable so I am still long Office and tree-sitter.
English
0
0
2
75
Haifei Li
Haifei Li@HaifeiLi·
@CryptoGangsta Good for you! Meanwhile I'm still buying the dip because I don't think they can vibecoding another Office, I mean, c'mon!:)
English
1
0
2
90
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@HaifeiLi Haha. My grant price was $420 so I am not that much under water. I actually do not hold a lot of MSFT outside of recent vests after I saw SP500 is basically tech so I cashed out to buy a home
English
2
0
1
92
Haifei Li
Haifei Li@HaifeiLi·
@CryptoGangsta I don’t know man, but as an $MSFT holder like you I was on the “first time?” meme.😂
English
1
0
3
262
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@udunadan I only use OpenAI models running in our own Azure subscription.
English
0
0
0
292
dunadan
dunadan@udunadan·
People using publicly available models (ChatGPT, Claude, etc.) for zero day research, aren't you concerned for the privacy of your findings?
English
6
1
44
9.3K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@moyix Text has always been dangerous. Instruction manuals and warnings on packaging. We haw now decided to talk to machines so we need the same guard rails.
English
0
0
1
62
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
I must be getting old because I see people taking about “skills” and how they can be malicious and how some people are building “skill scanners” and I have a hard time understanding how we messed up so bad we made text files dangerous
English
13
14
155
10.7K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@TR4NNYKISSER People lionize and dream of being "the only person who knows X and changes $$$/hr." In my industry (security), a lot of entry level steps like helpdesk have been effectively cannibalized or outsourced but are still expected by the old guard.
English
0
0
7
209
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@TR4NNYKISSER There is an unfortunately not so small section of experienced engineers who think this is good and provides job security. We’ve had companies who claimed to only hire seniors, Netflix being the most prominent off the top of my head. The industry has been going down this path.
English
1
0
20
2K