d3fp4r4m

3.6K posts

d3fp4r4m banner
d3fp4r4m

d3fp4r4m

@defparam

Opinions are my own

Katılım Mayıs 2014
580 Takip Edilen7.1K Takipçiler
d3fp4r4m
d3fp4r4m@defparam·
@thedawgyg @payloadartist Ignoring the bounty amounts for a moment when all the AI coding and bug hunting is at max do you think the average company will have more or less undiscovered bugs than pre-AI?
English
0
0
0
156
dawgyg - WoH
dawgyg - WoH@thedawgyg·
I think AI is going to cause bounty amounts to be lowered significantly when its mostly AI finding the vulns. Companies are going to have to make up for the huge loss of time/wages they are currently experiencing from the flood of AI reports (valid and invalid), and companies aren't going to be able to afford to keep paying 5 figure bounties for every critical. Especially since vibe coding introduces so many more vulns. I already know of several companies that are having these meetings right now to figure out whether to lower the bounty amounts or not, and some are thinking about removing the bounties all together to dissuade people from flooding them with AI generated reports hoping for a bounty,.
English
8
0
55
3.5K
payloadartist
payloadartist@payloadartist·
Will the new era of #bugbounty hunters be able to manually find bugs if Claude suddenly hikes the pricing 5x?
English
13
1
78
10.4K
d3fp4r4m retweetledi
Thomas H. Ptacek
Thomas H. Ptacek@tqbf·
People on the orange site are laughing at this, assuming it's just an ad and that there's nothing to it. Vulnerability researchers I talk to do not think this is a joke. As an erstwhile vuln researcher myself: do not bet against LLMs on this. axios.com/2026/02/05/ant…
English
7
18
120
12.2K
d3fp4r4m retweetledi
Gynvael Coldwind
Gynvael Coldwind@gynvael·
Glitches in games, especially used for speedrunning, are one of the most fun aspects of hacking to watch! As an example, check out this video "How Speedrunners BEAT Hollow Knight Silksong In 10 Minutes!" by @Abyssoft youtube.com/watch?v=M6Jnj-…
YouTube video
YouTube
English
4
5
35
15.6K
d3fp4r4m retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
Agency > Intelligence I had this intuitively wrong for decades, I think due to a pervasive cultural veneration of intelligence, various entertainment/media, obsession with IQ etc. Agency is significantly more powerful and significantly more scarce. Are you hiring for agency? Are we educating for agency? Are you acting as if you had 10X agency? Grok explanation is ~close: “Agency, as a personality trait, refers to an individual's capacity to take initiative, make decisions, and exert control over their actions and environment. It’s about being proactive rather than reactive—someone with high agency doesn’t just let life happen to them; they shape it. Think of it as a blend of self-efficacy, determination, and a sense of ownership over one’s path. People with strong agency tend to set goals and pursue them with confidence, even in the face of obstacles. They’re the type to say, “I’ll figure it out,” and then actually do it. On the flip side, someone low in agency might feel more like a passenger in their own life, waiting for external forces—like luck, other people, or circumstances—to dictate what happens next. It’s not quite the same as assertiveness or ambition, though it can overlap. Agency is quieter, more internal—it’s the belief that you *can* act, paired with the will to follow through. Psychologists often tie it to concepts like locus of control: high-agency folks lean toward an internal locus, feeling they steer their fate, while low-agency folks might lean external, seeing life as something that happens *to* them.”
Garry Tan@garrytan

Intelligence is on tap now so agency is even more important

English
2K
9.4K
50K
11.2M
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Yea im planning to! I'm fuzzing in a weird way that's helping me fuzz parts of libraries that are often over looked. So once some more of them get fixed gonna put together some posts about my fuzz setup/strat and some of the cooler bugs. I'm currently trying to teach myself to make POC exploits for some of them for practice so I'll be ready when I find something impacting Android lol
English
1
0
19
967
dawgyg - WoH
dawgyg - WoH@thedawgyg·
7 new 0days in the last 2 hurs (on top of the Write-What-Where and another buffer overflow)... the changes I made to my harnesses are making it rain vulns <3 #bugbounty #hackers #hacking #0day
English
7
3
96
9.5K
d3fp4r4m
d3fp4r4m@defparam·
@ryancbarnett Interesting, does Akamai typically use the CVE system to disclose web service vulnerabilities? Is there deeper technical information? I’m just curious how customers use this Information.
English
1
0
1
667
d3fp4r4m
d3fp4r4m@defparam·
@vxunderground I’m slightly ahead of you with an 8 month old. Truth, all of it.
English
0
0
0
133
vx-underground
vx-underground@vxunderground·
Also, before my son was born I took classes on baby stuff. I also purchased some books from Barnes & Noble. There is no book or class in the world that can truly prepare you to be a parent. It's a totally unique and subjective experience Thanks for reading
English
35
5
635
25.4K
vx-underground
vx-underground@vxunderground·
I've been bamboozled My son is 7 months old. The first 3 months were an inescapable hell. At the 7 month marker things have gotten easier, but a new set of challenges continually appear I have no reason to say any of this. I'm a first time Dad and I am learning the ropes. I haven't gotten an actual full night's rest since my son was born. I'm really, really, really tired. I love my son, but it's hard and I just wanted to complain into the void of the internet.
English
244
11
1.7K
97.8K
d3fp4r4m
d3fp4r4m@defparam·
Google could literally give 50ms of dark pattern money to ffmpeg (like incognito mode) without even feeling it and have the project funded for the next 200 years and probably should given, well, Youtube.
English
0
0
3
537
d3fp4r4m
d3fp4r4m@defparam·
@deadvolvo One extra: peer to peer audio on rushed games doesn’t give me the confidence on its security hygiene.
English
0
0
1
63
d3fp4r4m
d3fp4r4m@defparam·
@deadvolvo Two things kill in-game voip. Discord has cornered the market on gaming voip across most/all playgroups. Secondly there’s just too much audio garbage for me to give randoms unfettered access to my ears.
English
2
0
2
164
d3d aka dead (dead, мёртв, 死了)
Battlefield 6 is super fun, but the lack of people using any communications, especially in the squad, makes the game a bit less fun IMO. Great for playing with friends however.
English
2
0
4
1.2K
d3fp4r4m
d3fp4r4m@defparam·
@bl4sty @evilsocket Aren’t CVEs for the customers’ benefit not the researcher for the sake of vulnerability management?
English
0
0
1
228
blasty
blasty@bl4sty·
kind of funny that bugs that are communicated to vendors in a way they don't appreciate can result in no CVE being allocated for the vuln(s). while i guess it is bureaucratically legit (or is it?) it makes the CVE system an unreliable source of truth (more news at 11)
Goose@0xmadvise

Sucks, yesterday i've discovered a path traversal in docker compose, but unfortunately it will not be assigned as a CVE. Because i was supposed to send an email instead of opening a public issue in GH😅 anyhow the poc can be found here: github.com/0pepsi/DockerC…

English
9
11
67
16K
d3fp4r4m retweetledi
ytcracker.sol/.eth 🎤💻🔬🗝🏴‍☠️🤙
had some decent homies affected by the amzn layoffs any seceng sde or tpm roles you need to fill and want people that don’t suck reply to thread i’ll feed you souls
English
4
12
62
5.6K
d3fp4r4m retweetledi
ThePrimeagen
ThePrimeagen@ThePrimeagen·
nothing has cured me of so many anxiounesses of life like marriage + kids. I get to truly feel alive because life is no longer about what i want, but about the very real needs of people who depend on me that i love with a love i did not believe i was capable of
Matt Welter@mattwelter

i have... - an amazing girlfriend - making ~$450k this year - can work anywhere / anytime - live in a house w/ a pool yet i have anxiety every damn day, tight chest, hard to take a deep breaths, intrusive thoughts, always feeling not enough, can never relax what went wrong

English
76
130
4.3K
344.5K
d3fp4r4m retweetledi
Alex Birsan
Alex Birsan@alxbrsn·
@ArchAngelDDay Bucharest drivers see you putting on your seat belt and take it as a personal insult
English
0
1
3
610
d3fp4r4m
d3fp4r4m@defparam·
I think it’s a good time to throw my money somewhere else
English
2
0
2
655
d3fp4r4m
d3fp4r4m@defparam·
ChatGPT5 is so useless now
English
13
0
30
5.5K