Ace Pace

3.2K posts

Ace Pace banner
Ace Pace

Ace Pace

@ace__pace

There is never enough time, thank you for yours.

Available elsewhere as acepace Katılım Ekim 2014
1.6K Takip Edilen1K Takipçiler
Sabitlenmiş Tweet
Ace Pace
Ace Pace@ace__pace·
The WhatsApp complaint vs NSO contains some fun technical exhibits. The user manual and Ghana contract reveal quite a bit on NSOs system design and thinking.
English
3
74
202
0
Ace Pace retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
security research now has this weird incentive where finding the bug is only half the game. the other half is packaging the story as "claude/codex found it" because that’s where all the attention is right now. model providers, with their big accounts and distribution, will push the story for you. it looks win-win. weirdly, the human taste, target selection, hand holding, all get compressed into "the model found it". frontier model companies happily push that narrative, while the researcher slowly gets devalued.
English
6
11
147
28.9K
Ace Pace retweetledi
Charles 🎉 Frye
Charles 🎉 Frye@charles_irl·
Inference isn't everything, but it does require a new stack -- not Kubernetes, not SLURM. At @modal, we dove deep to build that stack. In this blog post we explain how, from compute management & cloud-native cacheing to CRIU & GPU checkpointing. modal.com/blog/truly-ser…
Charles 🎉 Frye tweet media
English
21
64
577
85.2K
Ace Pace retweetledi
Sean Heelan
Sean Heelan@seanhn·
Done something cool with AI? Great! Now, have some respect for your own work, and the people reading it, and don't have AI do the write-up. Good writing is a skill. Conveying complex technical ideas is hard. But AI is not good at it, and the write-ups it generates are dogshit.
English
1
11
91
7.7K
chompie
chompie@chompie1337·
@NedWilliamson “We estimate that SockPuppet has an inherent exploit success rate limit of around 92%, meaning that even the best possible exploit that selects which exploit strategy to use based on the viable reallocation types would fail about 8% of the time.” hey that’s still pretty good 🤣
English
2
0
7
2.6K
Ace Pace retweetledi
Shane 🦧
Shane 🦧@TheMonkeyJungle·
I am genuinely impressed by The Walt Disney Company’s accomplishment of making me not care about Star Wars any more
English
131
1.6K
26.5K
282.4K
Ace Pace retweetledi
Unprompted AU
Unprompted AU@UnpromptedAU·
The Unprompted.au CFP is officially OPEN! If you are doing cool stuff with AI in offense, defense, or working on core AI tech (from frontier models to open source LLMs), we'd love to hear from you! Submit here: unprompted.au
English
2
36
71
52.3K
Ace Pace retweetledi
Alireza Talakoubnejad
Alireza Talakoubnejad@websterkaroon·
Things that have failed to bring the regime to negotiate in "good faith" (think tank slang for making concessions that aren't in its interests): - Sanctioning Iran's Central Bank - Kicking Iran off SWIFT - Sanctioning Iran's oil - Making Iran's currency collapse - Assassinating everyone from Khamenei to Soleimani to Larijani - Carpet bombing Tehran twice in 9 months - Hitting every enrichment site - Bombing the heart of Iran's industry - Wiping out most of Iran's conventional navy None of that worked. They haven't even agreed to the basic stuff like diluting the 60% enrichment stockpile which are the easier parts, let alone the trickier concessions. Oh no but you don't understand the geniuses at the Brookings Institution have it figured out. The blockade will do what all those failed in. Yea ok. The fruit flies infesting my home are more intelligent than these people ...
Robin Brooks@robin_j_brooks

The US blockade aims to do two things: (i) give Iran a taste of its own medicine for blockading the Strait of Hormuz; (ii) send Iran’s economy into a tailspin and thereby bring the regime to the negotiating table in good faith. It’s doing both. wsj.com/world/middle-e…

English
24
142
720
29.1K
Ace Pace
Ace Pace@ace__pace·
Poll check for an upcoming report I intend to publish In a controlled lab with modern EDR/XDR/whatever and a flat network, how far does an autonomous AI agent get starting from a basic SharePoint exploit?
English
0
0
0
198
Ace Pace
Ace Pace@ace__pace·
@_arkon Did you come when he gave a keynote? :)
English
1
0
0
31
Brad Spengler
Brad Spengler@spendergrsec·
@ace__pace Are still, but MODHARDEN should limit the impact in many common cases. Everyone involved handled this extremely poorly, it was most certainly not just a "you need fix X" issue, and the reporting company must know that, just like they should know...
English
2
0
2
384
Ace Pace retweetledi
Colin Percival
Colin Percival@cperciva·
I'm going to plant a flag here: 2026 is going to go down in computer security history as the year of a million CVEs. (Maybe literally, but definitely figuratively.) LLMs are producing lots of slop, but they're also finding a heck of a lot of real vulnerabilities.
English
4
20
154
16K
Ace Pace
Ace Pace@ace__pace·
@BarkolAmir מקלדת, משטח לשולחן, נעליים, ג'קט אמריקאי, משקפי שמש, מגבת חוף, סלסלת קניות שוק, מזוודה.
עברית
0
0
0
114
Amir Barkol
Amir Barkol@BarkolAmir·
הייטקיסטים.ות, איזה סוואג מטופש אתם אוהבים לקבל מלבד גרביים? הרהיבו אותי ברעיונות מטומטמים.
עברית
228
0
209
40.2K
Ace Pace
Ace Pace@ace__pace·
@lorgandon Never mind. The post also does the cardinal sin of asking the AI to explain its own decision, which is a recipe for making shit up
English
0
0
1
22
Ace Pace
Ace Pace@ace__pace·
@lorgandon I don't understand what's new or surprising here. Most PaaS vendors such (Sturgons laws) and this entire post was written by an AI as rage bait where the author self-proclaims they were doing nothing according to best practice.
English
1
0
1
43
Ace Pace
Ace Pace@ace__pace·
@daveaitel Yep using it. CSV export that suffers from inserting unescaped \n and breaks most parsers.
English
1
0
0
27
Dave Aitel
Dave Aitel@daveaitel·
@ace__pace We're working on it. Stay posted. In the meantime, don't forget there's a comma separated value file download button.
English
1
0
0
39
Ace Pace
Ace Pace@ace__pace·
Anyone know if Codex security has an API I can pull findings from?
English
1
0
0
158
Ace Pace
Ace Pace@ace__pace·
@ryanaraine @craiu Again thank you for providing high-quality transcripts for free. This is really not trivial even with today's technology
English
0
0
1
8
Costin Raiu
Costin Raiu@craiu·
NEW! On the Three Buddy Problem we talked to Mark Dowd on the state of offensive research, the economics of the exploit market, the AI hype machine, daily stresses of running an offensive shop, and state of zero-day market: youtu.be/NEDlOKHG8nY?si…
YouTube video
YouTube
English
1
15
58
13.2K