Cameron Smith

493 posts

Cameron Smith banner
Cameron Smith

Cameron Smith

@Secnomancer

Engineer, Hacker, Maker, Security Wizard. I can show you how it works, but I'll need to break it first...

Indiana Katılım Ocak 2020
227 Takip Edilen87 Takipçiler
Cameron Smith
Cameron Smith@Secnomancer·
@IceSolst Shift left doesn't scale either, especially at AI speeds. We need to shift down. Processes, tooling, and security reasoning baked in at the development and platform layers.
English
0
0
1
21
solst/ICE of Astarte
Opposed to security being “approvers”. It is too late. We should collab during design and coding, with tools to help instill confidence in devs. If they come to us after 3 months of implementation work, w “sir plz approve” and wait for me, then we have both failed.
English
18
14
150
8K
Cameron Smith
Cameron Smith@Secnomancer·
@vxunderground That's amazing. As a vet myself, it makes me proud and warms my heart to hear. If your boy is looking for a gig when he gets finishes school, lemme know.
English
0
0
4
525
vx-underground
vx-underground@vxunderground·
One of my good friends was deployed to the Middle East about 17 years ago. He did a 6 year stint in the military. He got out and had some mental health issues and had problems integrating back into the world outside the military. After nearly 8 years of struggling with PTSD, depression, anxiety, and alcohol issues, I'm happy to share he's finally got his head back on straight. He told me he's attending university for cybersecurity. He got himself a really nice girlfriend who seems very supportive of him. He's got a nice home to call him own. He's doing really, really good. It all worked out. Proud of my boy.
English
74
46
3.3K
98.6K
Cameron Smith
Cameron Smith@Secnomancer·
@IceSolst I mean, if I'm distrustful of code that I write, imagine how much I trust code from other sources... 🤣🤣🤣
English
0
0
1
6
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
I distrust human and LLM generated code equally I similarly distrust human and LLM conducted code reviews equally And our tools to verify program correctness need a lot of improvement
English
26
5
119
5.8K
Cameron Smith
Cameron Smith@Secnomancer·
@HackingDave Forming yet another very strong, warm memory of that trip with the boyz.... Sounds like life happening in real time ❤️
English
0
0
1
111
Dave Kennedy
Dave Kennedy@HackingDave·
For this weekend I rented an RV with my airsoft boys… get to the facility … tight driveway, hit a branch.. rips off the entire left mirror completely off. So… no left mirror and in South Carolina in a big 30ft rv. So I run to auto zone and get a tiny mirror that I can roll window down to see to my left while driving.. While driving home on freeway half way in, lose grip of mirror out the window .. it’s gone. So we pry the broke mirror off it so I could use it the rest of the ride 😆
English
16
2
73
8.1K
Low Level
Low Level@LowLevelTweets·
I miss infosec twitter
English
101
113
1.6K
82.6K
Cameron Smith
Cameron Smith@Secnomancer·
@HackingDave Looks like the good stuff! Just life being lived by people and some warm, core memories being made...
English
0
0
1
25
Cameron Smith
Cameron Smith@Secnomancer·
@IceSolst This is what many VCs and Startups found out. If everything is backed with the "same model," you need something besides just calling the model to have differentiated value. Many new security 'scanners' aren't doing anything different than saying "Claude, take the wheel..."
English
0
0
1
165
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Building a harness to run scans with an agent. It is absolutely garbage. Completely useless. There’s literally 0 benefit to using it over plain Claude Code. Everything it can do, you can just do via Skills etc. Many were preaching the benefits of a harness, but I’m not sure.
English
64
22
484
54.6K
Cameron Smith
Cameron Smith@Secnomancer·
@chrissanders88 I think a practical, working definition for systems work is any entity taking actions, being acted upon, or being acted on behalf of. That can be a user, system, agent, etc. Additional layers of abstraction or specificity seem like they'll miss the forest for the trees... 😜
English
0
0
0
35
Chris Sanders 🔎 🧠
Chris Sanders 🔎 🧠@chrissanders88·
When you hear the word "identity" in cybersecurity, what does that mean to you? How do you define it?
English
14
1
11
3.4K
Dave Kennedy
Dave Kennedy@HackingDave·
In all seriousness though, companies that are investing in these tools have zero control over code quality, how to protect from prompt injection, what gets shoved and executed into the developers environment, what gets shoved into production. Zero. Controls. Death of cybersecurity? Nah. It's just getting started.
solst/ICE of Astarte@IceSolst

🚨‼️We have published a guide on mitigating the imminent AI security apocalypse Step #1: buy our tool Golden age of snake oil I stg. And the ‘tool’ is a prompt.

English
26
18
170
15.6K
Cameron Smith
Cameron Smith@Secnomancer·
@IceSolst Any chance you could turn the volume up louder for all the people in the back!?!?! This is soooooo true. I was talking with a financial institution where the CISO was getting bullied for AI acceleration by the CDO, but still had server 2008 and a flat network... 😭
English
0
0
1
22
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Th vast majority of CISOs do not work at Google-sized companies, and will not have to worry about 0days There’s a disconnect between the Mythos discourse, and what actually happens at most orgs: Still can’t identify assets and IPs, biggest threat is still phishing, lack of defined ID mgmt and access controls, shadow IT, misconfig’d S3 buckets… If you work at one of those companies (applies to most people) you have a LOT of work to do before AI 0days is even on the top 50 things to think about. This is why advice from Google and large company leaders isn’t relevant to most folks out there. Massive scale and attack surface difference. Sure it’s still interesting and fun to speculate at that level, but it’s just not real for most people.
English
35
89
553
43.1K
Cameron Smith
Cameron Smith@Secnomancer·
@TracketPacer I tell you... That feeling when the rack-jockey before you left a couple taped to the inside of the door or in the very tippy top slot is just... *Chef's kiss*
English
0
0
0
107
TracketPacer
TracketPacer@TracketPacer·
i found some cage nuts
English
117
63
1.4K
49.8K
Cameron Smith
Cameron Smith@Secnomancer·
@vxunderground Hahahaha, yessssssss....... Same here. I found 2-3 infinitely more fun, but wildly exhausting
English
0
0
0
2
vx-underground
vx-underground@vxunderground·
1 year olds are far more exhausting than 6 month olds. Parents warned me. They were correct. Bro HAS to put ALL FOOD on his head. - Beans - Soup - Mac and Cheese - Strawberries - Blueberries If he doesn't rub it on his head, or eat it, he throws it on the floor. I'm tired.
English
135
17
1.4K
41.3K
Cameron Smith
Cameron Smith@Secnomancer·
@HackingDave @HackingDave - Try KiroCLI with Claude, or something backed by Bedrock. It's been solidly performing for us. Anthropic isn't an infrastructure company...?
English
0
0
1
33
Dave Kennedy
Dave Kennedy@HackingDave·
I understand there’s a ton of Claude fans out there. I was there too 4-5 weeks ago. Then it got way way way worse and without explanation. What’s worse is that I would consider myself a heavy power user. What about the folks that aren’t and have no idea it was dumbed down over 60% or more since its initial release and are using this day to day. Codex is outperforming Claude in every way right now. Additionally OpenAI is much more transparent, cheaper, and produces much better code in every way to Claude at the moment. Claude has massive outages, lack of transparency to users, some really bad operational and security practices. They’ve lost me. I’m done. What happened ?
English
164
62
1K
93.4K
vx-underground
vx-underground@vxunderground·
Look at this and tell me God exists
vx-underground tweet media
English
164
155
4.2K
248.3K
Cameron Smith
Cameron Smith@Secnomancer·
@IceSolst I'd argue it's because you've transferred them to some folks who desperately needed them... 🤣🤣🤣
English
0
0
1
4
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
One year ago, I created this forsaken account. I regret everything. I’ve genuinely lost brain cells, irrecoverably. What I’ve learned: - Who wrote Task Manager - Semrure Mail Transfe Protocol - Rust (Bitcoin style) encryption - Fortinet RCE (x39) - /b/ was never good
solst/ICE of Astarte tweet media
English
51
14
617
19K
Cameron Smith
Cameron Smith@Secnomancer·
@vxunderground I'm sorry, I could hear you over the adorable bug-eyed kitten. Something about spies...?
English
0
0
0
7
vx-underground
vx-underground@vxunderground·
I get messages around the clock from nerds I get information on products, breaches, forum drama, Threat Actors, what cybersecurity companies are doing, etc Sometimes I feel like I've got an international network of spies that feed me intelligence. It's fucking badass
vx-underground tweet media
English
32
25
912
28.5K
Cameron Smith
Cameron Smith@Secnomancer·
@gabsmashh Big same... I miss that entire era. The internet felt like a place that I used to go to that was constrained to my desktop in my office rather than a pervasive digital dimension that is layered on top of everything. Simpler times, eh?
English
0
0
1
21
gabsmashh
gabsmashh@gabsmashh·
i miss limewire
English
47
3
266
14.6K
Dave Kennedy
Dave Kennedy@HackingDave·
One thing I’ll never forget until the day I die… up up down down left right left right B A select start.
GIF
English
27
5
165
7.5K
Cameron Smith
Cameron Smith@Secnomancer·
This platform remains so weird... yet still useful.
English
0
0
0
23
Cameron Smith
Cameron Smith@Secnomancer·
@HackingDave What's wild to me is that life really can be this simple if we let it...
English
0
0
1
11