Sabitlenmiş Tweet
Mudge
4.7K posts

Mudge
@dotMudge
Make a dent in the universe. Find something that needs improvement: go there and fix things. If not you, then who? {he/they}
DARPA^2|Stripe|Google|L0pht Katılım Eylül 2011
337 Takip Edilen62.7K Takipçiler

Postfix: apologies for not being able to provide all of the details here.
With much appreciation to the people on those multiple teams.
You know who you are.
And thank you to the Board and Execs continually demonstrating over the years how much you appreciate the work of your current, AND former staff. Because of that, I have no doubt you will always have a pipeline of the best future staff eager to join.
(Word gets around when places play the long game)
English

I honestly think we're at "L0pht is testifying at the Senate" levels of fucked. LLMs finding vulns has gone from possible to trivial RAPIDLY and the use of generic coding agents is currently the lower bound!! The security industry is not at all ready for the reality of today. 🫠
Calif@calif_io
We asked Claude to find a bug in Vim. It found an RCE. Just open a file, and you’re owned. We joked: fine, we’ll switch to Emacs. Then Claude found an RCE there too. Full story: blog.calif.io/p/mad-bugs-vim…
English

@dildog @medus4_cdc @Grifter801 @dakami @angus_tx @defcon I’ll take a “not mudge[*]” shirt too…
Sheesh. Make even *more* of a target on me why don’t you 😉
(Or at least “occasionally mudge”)
English

Dr. Morris (he doesn’t like being called Jr. he and his father have different names) was doing well the last I heard.
I believe he’s still a professor at a very prestigious academic institution.
He was going to be great no matter what field he chose (the security field was basically closed off by a particular professor at the time who made a big fuss and lobbied to have the book thrown at him).
Fortunately there were good people like Steve Bellovin and others who went to bat for him and fought the zealot.
English

Aleph took it much further and made it much more accessible.
I’m proud to have contributed in even the slightest way.
Today In Infosec@todayininfosec
1995: Mudge published "How to Write Buffer Overflows", one of the first papers about buffer overflow exploitation. Then @dotMudge sent a copy to @aleph_one, who wrote "Smashing the Stack For Fun and Profit" in 1996. Seminal paper to seminal paper. Mudge's: insecure.org/stf/mudge_buff…
English





