YSEByy

12.3K posts

YSEByy banner
YSEByy

YSEByy

@YSEByy

Security Engineer | OSCP | I don't post serious stuff that often | Former good boy | My views, not my employer(s)

Katılım Haziran 2011
317 Takip Edilen302 Takipçiler
YSEByy
YSEByy@YSEByy·
Todays mood is that my headphones dont go loud enough
English
0
0
0
15
YSEByy
YSEByy@YSEByy·
@IceSolst Don't have a talk specific but after every con I circle back to the idea of talking about actually doing sec eng in an org vs loose single usecase tools that the market is flooded. When scale and number of people come into play, shit hits the fan and nobody talks about it really
English
0
0
2
122
solst/ICE of Astarte
Conference talk rejected? Comment your abstract below, and we can record a YouTube video on it. Gets more reach than a conference talk anyway. And can be used as reference for some CFPs.
himug-lamuh@HimugLamuh

@inf0stache i've got loose plans to post rejected talks on youtube. if they get 50 views, that's a small conf talk anyway.

English
25
31
181
19.5K
society
society@societynotreal·
@YSEByy literally my entire life, have a whole lot of stuff that looks cool but I’m like “yeah nobody will care anyway” and I just close the app lol
English
1
0
0
21
YSEByy
YSEByy@YSEByy·
Sometimes I think I should post more. With that, I have alot of stuff I can talk work wise, security wise and just general thoughts. At the same time, none of it matters so I rarely post anything here anymore
English
1
0
2
38
YSEByy
YSEByy@YSEByy·
@IceSolst whats your workflow for claude??? share prompts
English
1
0
1
1.4K
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Claude is CRAZY here are all my hackerone payouts just from today
solst/ICE of Astarte tweet media
English
48
28
971
63.4K
YSEByy
YSEByy@YSEByy·
@InsiderPhD Sbom analysis is only good for known cves that are days late. The problem here is the trust we put into packages that we import, even more with how much packageslop is going to come out.
English
0
0
0
31
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
love how we’ve spent years building out SBOM tooling and reachability analysis only for attackers to go “lol what if we just hid the payload in an audio file inside a trusted vendor SDK”
English
3
3
16
1.7K
YSEByy
YSEByy@YSEByy·
@IceSolst Hate all of this vibecoded saas that doesnt solve any of this shit. But also glad that what i was thinking about and talking about coming to light in the forefront
English
0
0
1
15
YSEByy
YSEByy@YSEByy·
@IceSolst Wish I was smarter but I even did a small talk about how current tools are already post factum and some things need to check behaviour in regards to supply chain. Not alot of mature stuff for it and even then, how do you determine when it comes to new stuff.
English
1
0
1
44
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
I’m so sick of AI comments pitching vibecoded products. In this case they’re pitching their tool to…. TeamPCP the literal attackers Every post I make, I get a bunch of comments like this about some Claude api wrapper “make this secure” ass product
Helixar AI@Helixar_ai

@pcpcats @IceSolst @xpl0itrs the attacker’s budget is irrelevant when your detection is signature-based. $150 or $150M the IOCs won’t match your ruleset either way. this is why we built around intent trajectories, not known indicators. state-sponsored or script kiddie, the kill-chain stages are invariant.

English
16
2
134
9.1K
YSEByy
YSEByy@YSEByy·
@toshkyo Love adding more for my pile of shame :(
English
0
0
1
18
Toshino
Toshino@toshkyo·
Amazon just delivered my Blood Angels Intercessors I guess that means that I'm ready to buy more
English
5
0
20
308
YSEByy
YSEByy@YSEByy·
@IceSolst Feel like the env has alot to do with it. If you can have a sandbox for internal tooling? Sure fuck it. If its a business critical payment system? Nothing ever.
English
0
0
1
62
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
What would make you comfortable auto-merging PRs? No human review. Someone mentioned reaching 100% test coverage but imo that is impossible
English
72
1
73
36.1K
YSEByy retweetledi
Malika 🧬
Malika 🧬@malikules·
when a man has no real achievements like chess elo, viral tweet, niche spotify wrapped he takes pride in useless stuff like salary and career achievements
English
67
1.7K
15.7K
269.8K
YSEByy retweetledi
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
13
148
842
34.9K
YSEByy
YSEByy@YSEByy·
@toshkyo Okay :D i thought you doing security freelance so wanted to learn something there
English
0
0
1
13
Toshino
Toshino@toshkyo·
@YSEByy All my freelance work is related to media/content creation/video editing and probably vtubbing rigging next year, those are all things that I learn as a hobby and end up making money from it after I get skilled enough
English
1
0
2
33
Toshino
Toshino@toshkyo·
unironically learning a second skill on my free time instead of gaming is how I started freelancing while having a full time job so I could move from broke to where I'm now, including paying for an apartment instead of renting and now I keep doing freelance because I like money
skum🧊@skumWgmi

STOP TELLING BROKE PEOPLE TO BUDGET. THERE, I SAID IT. YOU CAN'T BUDGET YOUR WAY OUT OF POVERTY. AFTER BASIC NECESSITIES I HAVE $0 LEFT OVER, HOW AM I SUPPOSED TO BUDGET?

English
6
3
34
791
YSEByy
YSEByy@YSEByy·
@IceSolst Its very weird going to a conference thinking youre a moron and then listen to the most basic talks on the planet that have no value
English
0
0
3
84
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
@YSEByy You’re right, but imo that’s still above average, mostly to highlight how low the bottom tier is
English
1
0
1
866
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
There’s an astronomical skill gap between good security people, and the rest. There’s no mid. Accounts you see posting their research here are absolutely cracked, it’s not the norm. When you go out and talk to security folks that don’t go to conferences, don’t read up on research, you realize- holy shit. They have no fucking clue. The majority of the cybersecurity work force is absolutely incompetent. It’s partly why vendors can come up with inane bullshit as marketing material and it works on many CISOs. If you’re reading this, you’re most likely 1000x the skill level of the average person. Like I cannot emphasize enough how low the bar is when the sample size is the entire industry.
English
146
96
1.6K
174K
YSEByy retweetledi
Nels
Nels@nelsyuu·
can’t wait to see this panel animated tomorrow
Nels tweet media
English
23
4.3K
49.5K
432.3K