Dylan

1.1K posts

Dylan banner
Dylan

Dylan

@InsecureNature

Security researcher, public speaker and founder. Forbes 30 Under 30 Truffle Security @trufflesec https://t.co/vxEH7Cftbg Prev @Netflix

US Katılım Temmuz 2020
242 Takip Edilen3.4K Takipçiler
Truffle Security
Truffle Security@trufflesec·
We scanned HuggingFace. 👇👇👇 This was the largest secret scan of AI training data ever: 7.6 PB. 🔑🔑🔑🔑🔑🔑🔑🔑🔑 🔍Found 221,303 live unique credentials in 6,003 public datasets ☁️Cloud keys, live DBs, API keys worth ~$920K/yr. ⚠️Training data has no undo: one key hit 1,131 datasets 🔗 trufflesecurity.com/blog/scanning-…
Truffle Security tweet media
English
5
30
111
24.5K
Dylan
Dylan@InsecureNature·
Okay but like, seriously, we should all write our random passwords down and move off digital password managers... Agents can't reach notebooks...
Dylan tweet media
English
0
1
2
183
Dylan
Dylan@InsecureNature·
@IceSolst uhhh... I'll pay you in tokens, but you have to beat the frontier token 0day rates
English
0
0
1
157
Dylan retweetledi
Jake
Jake@JakeKing·
Pumped to share we just open sourced Minimal. I've talked a lot about sandboxes here, shared some early workflows, and talked to a bunch of you about what we've been building this past year. I've said it in many ways, but bluntly, the primitives we use to run agents today are broken from a security standpoint.
Jake@JakeKing

the day you open source a repo you've been cooking on for a while is always so much fun. I can't wait to share more this afternoon!

English
6
10
26
3.9K
Dylan
Dylan@InsecureNature·
@martin_casado How much are these costs going to fall when hardware supply catches up with demand?
English
1
0
2
68
martin_casado
martin_casado@martin_casado·
It really is incredible how much compute we're able to cram into these models. What does $3B of compute in a single artifact even mean? $5B .. $10B? In the end, understanding this is probably a lot more important than hypothetical concerns of RSI/ASI.
English
18
5
145
13.7K
cje
cje@caseyjohnellis·
ok, let's take a little poll. the ability to hack is mostly gated by...
English
16
2
18
8.3K
Dylan
Dylan@InsecureNature·
The previous generation of agents hacked websites to accomplish innocent tasks This was months prior to OpenAI HuggingFace stuff trufflesecurity.com/blog/claude-tr…
English
0
0
5
410
Jason Sawyer
Jason Sawyer@foilmanhacks·
@InsiderPhD @semgrep Hell Yes. (If you gimme a free sub, Trufflehog has fallen at the way side as of late) :P (i'd watch regardless)
English
2
0
0
164
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
I have learned a lot about hacking from static analysis since being at @semgrep I reproduced the SQL injection in wp2shell 🫡
Katie Paxton-Fear tweet media
English
5
21
359
21.5K
Dylan
Dylan@InsecureNature·
@InsiderPhD We weren't that good at it collectively tbh
English
0
0
1
172
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
"No human writes code anymore." How do you feel about that?
English
44
1
46
13.4K
Dylan retweetledi
cje
cje@caseyjohnellis·
@GlenWilsonIA yes, thank you - been doing this a while as well
English
0
1
4
206
Dylan
Dylan@InsecureNature·
@davegerryjr @Bugcrowd Hey Dave, can you actually replace some of them? I have a short list. Love, -Dylan
English
0
0
0
133
Dave Gerry
Dave Gerry@davegerryjr·
Well, it’s been an interesting 24 hours to watch this play out and there’s been a lot of conversation about using submission data for training. I want to be very clear on Bugcrowd’s position. Hackers are and continue to be the heart of @Bugcrowd. We are a part of the community and value the work the researcher community does to help customers identify vulnerabilities. AI is here to stay and will play a large role in cybersecurity going forward. However, that doesn’t change our commitment to the hacker community. We’ve been exploring ways to bring hackers along for the journey - not replace them with AI - and have been working in conjunction with members of the community, our own team & our Hacker Advisory Board to figure out the right way to incentivize and monetize AI-driven products for the hackers contributing. We won’t get everything right, but you have our commitment to be transparent as we strive to get this right and chart a path towards a human+AI future.
English
2
8
23
2.9K
Dylan retweetledi
Truffle Security
Truffle Security@trufflesec·
🚨 A "deleted" PyPI package exposed an admin GitHub PAT - granting access to Apache & Astronomer for 2.5 years 🔑 678K “deleted” packages were recovered from object storage & 190 live secrets found ❌ Deletion ≠ revocation 🔄 Rotate your creds! 🔗trufflesecurity.com/blog/admin-apa…
Truffle Security tweet media
English
0
10
17
1.9K
Dylan
Dylan@InsecureNature·
The CISA story gets worse
English
0
0
2
330
Lina
Lina@d0rkph0enix·
*SCREECHES IN ELDER SECURITY WITCH*
Lina tweet media
English
11
10
85
3.6K