Manfred Paul

92 posts

Manfred Paul

Manfred Paul

@_manfp

Security but not as in "national security". Playing CTFs with @redrocket_ctf (and @Sauercl0ud). Pwn2Own Vancouver 2020..=2024\{2023}. @[email protected]

Outside of computed bounds Katılım Ocak 2020
315 Takip Edilen5.3K Takipçiler
Manfred Paul
Manfred Paul@_manfp·
@_0xTen @LiveOverflow @_mixy1 (ofc some might argue "that means those challs won't exist in the long run". but that's just putting the burden on authors too to reject lots of good ideas, spend big money on AI tooling to test, plus the mental burden if "oh it got slopped anyways" happens)
English
0
0
3
97
Manfred Paul
Manfred Paul@_manfp·
@_0xTen @LiveOverflow @_mixy1 It's not just about the learning, 90% of the challenges being irrelevant is also unsustainable because that means 90% of the challenge author effort is "wasted". High quality challenges have *always* been the bottleneck of CTF.
English
1
0
2
117
Michael Debono
Michael Debono@_mixy1·
ctfs are dead PLEASE PLEASE PLEASE stop making jeopardy ctfs. This is not fun at all to put effort into. Lets try and find a new format or something cause I'm gonna [redacted] if I see another ctf get half its challenges cleared in the first 30 minutes.
English
24
26
330
31K
Manfred Paul
Manfred Paul@_manfp·
@gynvael If it's a different game for different people, at least call it something different too?
English
0
0
1
344
Gynvael Coldwind
Gynvael Coldwind@gynvael·
A better question is: Is it a format for the same people? My guess is that the answer is likely "no", and there will be a lot of reshuffling on the CTF scene.
LiveOverflow 🔴@LiveOverflow

@_mixy1 Why is this bad? New CTF meta is AI assisted playing. The teams with the best AI tooling will win. Is that not a good new format? 😅

English
3
2
60
9.3K
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @_mixy1 Some of the most fun CTF challenges I've seen were also the most detached from the real world. Who needs to pwn an apollo guidance computer or analyze minesweeper logic gates? These are "CTFy" because they value fun over practical use, not despite of it.
English
1
0
6
228
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @_mixy1 I do object to the "CTFs are not a 'game'". Sure, they teach valuable skills. But that was never an invitation to see them as a value extraction tool or tie their worth to that. People didn't spend (unpaid) labor of creating challenges or writeups to make shareholders happy
English
1
0
3
180
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @_mixy1 If FIFA allowed robot players, and 99% of accomplished soccer players said "we hate this, this ruins our sport", would we all go "this is just what the the word 'soccer' means now"? The community gets some say in what the word "CTF" means. And nearly noone there enjoys AI v. AI.
English
2
16
120
15.7K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
@_mixy1 Why is this bad? New CTF meta is AI assisted playing. The teams with the best AI tooling will win. Is that not a good new format? 😅
English
10
2
87
23.7K
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @luminaryxd And "flag is flag" has not been the only beautiful (unwritten) principle of CTFs. CTFs are about rewarding deep technical understanding, not outsourcing thinking; being (relatively) accessible to anyone with skills+motivation+time, not requiring investment of money.
English
0
0
4
171
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @luminaryxd I don't think the numbers matter if the community isn't there. The bottleneck was always top players willing to put in the effort to build high-quality challenges for a handful of top tier CTFs, and I feel like motivation is starting to drain fast there.
English
1
0
1
228
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
What I’ve always found amazing about CTFs is that "flag is flag". Whether you found an unintentional solve or pwned the browser with n-day for a XSS challenge, it didn't matter. I totally get the frustration of AI, but there is no solution other than accepting the change.
siunam@siunam321

I started playing CTFs in 2022, and LLMs definitely changed the **competitive** CTF scene a lot, especially since mid-2025. I also started using LLMs in late 2025. Yes, those models did one-shot many challenges, but what's the fun of slopping them? I learned absolutely nothing 🥲

English
19
39
447
67.8K
Manfred Paul
Manfred Paul@_manfp·
If you're a security researcher and in Germany, consider signing cysec-reform.jetzt . Decriminalizing research might not be the top political priority right now, but it's still important!
English
1
12
77
11.9K
Manfred Paul retweetledi
David Mirren
David Mirren@davidmcgeoch9·
More important than ever!!
David Mirren tweet media
English
935
76.9K
147.2K
4.4M
Manfred Paul
Manfred Paul@_manfp·
@ecsc2024 @MITAmalta @MITAmalta, this is not how you build up a cybersecurity community in your country. It was great to see a lot of ECSC players show their support people like @_mixy1 who faced both disqualification and legal action. As the vulnerability research community, we should do the same.
English
0
4
19
5.6K
Manfred Paul
Manfred Paul@_manfp·
@ecsc2024 Only low point though was the lack of a Maltese team, apparently due to @MITAmalta blocking some of the (already qualified) team from coming after they were arrested for responsibly disclosing(!) a vulnerability in a student app in 2022. timesofmalta.com/article/winnin…
English
1
3
22
5.3K
Manfred Paul
Manfred Paul@_manfp·
Had a great time playing for the German team at @ecsc2024, shout out to the organizers for putting on a really great competition!
English
2
2
33
5.2K
Manfred Paul retweetledi
Tavis Ormandy
Tavis Ormandy@taviso·
This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n
Tavis Ormandy tweet media
English
245
3.1K
15.5K
3.3M
Manfred Paul
Manfred Paul@_manfp·
@seanhn And while we're making accusations about "being unable to contemplate the wider consequences": There should be a red line there for a reason. It's the same line that says intentional backdoors are not OK. Or that some country you don't like shouldn't be allowed to do the same.
English
0
0
3
407
Manfred Paul
Manfred Paul@_manfp·
@seanhn I really don't get how that wouldn't be a "executive decision about a counter terrorism operation" then. If you don't want tech company to play on that stage, then them following a consistent rule of "if we learn about a bug, we fix it" is the only way to have that.
English
1
0
4
487
Sean Heelan
Sean Heelan@seanhn·
I am amazed at how many people are seemingly comfortable with middle managers at an ad agency taking executive decisions about counter terrorism operations.
English
5
5
46
11.8K
Manfred Paul
Manfred Paul@_manfp·
@seanhn I'm confused, do you want them to make decisions about the operation (and not just the bugs) or not?
English
1
0
2
937
Sean Heelan
Sean Heelan@seanhn·
@_manfp The fact that you're unable to contemplate the wider consequences of "fixing and reporting bugs" in this specific context proves my point =)
English
2
0
2
1.4K