Jaisal (AtomicByte/Jess)
3K posts

Jaisal (AtomicByte/Jess)
@atomicbyte_
internet sensation 🚶♂️he/him programming, tech, hacking, datamining, game hacking, etc. chronically frickin hilarious shitpoaster
under a rock Katılım Ağustos 2023
276 Takip Edilen305 Takipçiler

@N0rbertas @Shitpost_2048 Ask a superintelligence to cure death and it'll do it by destroying all life
English

@Shitpost_2048 can someone tell me what this is referencing?
the only thing i can think of is that one Quake 3 Arena story where a guy forgot to pause his server for 4 years and when he returned all the bots were completely still but im not sure if thats it
English

@SockPup93876932 @pickover wouldn't that take... an infinite amount of time? since you *are* processing an infinite amount of digits...
English

@SockPup93876932 @pickover i doubt regex would work for an infinite string...
English

@pickover It’s doable. Have a program calculate Pi and have a regex-check for a sequence of 1 and 0 in mo particular order.
English

YOU'RE VULNERABLE. YES, YOU. EVEN IF YOU DON'T RUN OLLAMA. You'll get it by the end of this.
throwback to the time when i ratioed ollama for a bug that they still haven't patched to this day
"we take security seriously"
I've had it up to here with companies that think they have good security but never respond to real bugs.
just because it's novel doesn't mean it's invalid. I get that "CSRF" isn't usually used in a DNS-rebinding type scenario where it's browser -> localhost request forgery.
Yes, rebinding is patched but THIS 👏 IS 👏 NOT.
Because *it's not a browser bug* in the first place
it's YOUR bad cybersecurity. YOUR CORS policy leaking all over the bathroom floor.
and i released a PoC, but some of them just dont get it. they don't read the code.
honestly it's your problem atp.
because if i can make a user go onto a website and run the javascript: "fetch('127.0.0.1')", it's not the server that makes the request.
it's the client. and that client sends the information back to the server. it's remote-controlling an ollama server even if it's firewalled and cut off from the internet.
sure, there's password protection, but that was barely around when i published this and it's still not a default.
everything is vulnerable. ive been finding bugs in openclaw, hermes, and every other AI project you could imagine.
they're all so broken.
you can be hacked.
within about 5 minutes of looking through a codebase.
honestly i doubt this tweet will reach many people. i average about 40 per post (lol), but you could help out with a repost.

English

@Connie_codes @kylegawley You are employed in an unemployed way
English

@atomicbyte_ @kylegawley ok im employed but I still don't understand
English

@thenowhereway Been doing the second one for a while. Nothing.
English

they’re fucking WHAT
unusual_whales@unusual_whales
OpenAI is preparing a new AI model, per The Information
English

@gnukeith Why is my favorite browser talking about vibecoxing I don't want slop in Keith browser
English

@crvvdev It's actually a completely reasonable decision by anthropic
English

@d4m1n Anybody who claims to have done this is lying
English

@Connie_codes @kylegawley You have to be employed to understand
English

@kylegawley can someone please explain to me why calendly somehow is a successful business
English

Just received a startup deck with "March 2026" on the cover.
Today is June 12.
DO NOT - I repeat - DO NOT include the date on your pitch deck!
Don't let VCs know when you started raising.
They don't need that information.
There's zero upside for you. It can only hurt you.
Why would you even include the date?
Your pitch deck is not a class homework.
Ditch the date.

English

















