Glen Arrowsmith

3.1K posts

Glen Arrowsmith banner
Glen Arrowsmith

Glen Arrowsmith

@garrows

InfoSec/CyberSecurity, Javascript/Node.js dev, system architect, roboticist, father.

Brisbane Katılım Ekim 2007
634 Takip Edilen1.1K Takipçiler
Ryan Hickman
Ryan Hickman@ryanmhickman·
To top off a wild launch week, Business Insider did a deep dive today on how we're using this system to turn real-world gig work into the foundation for physical AI models: businessinsider.com/instawork-inst… The physical data chasm is massive, but we are officially scaling. If you’re building VLA models and want to talk data capture, custom sensor pipelines, or calibration—my DMs are open. Let’s build. 👇
English
2
0
11
794
Ryan Hickman
Ryan Hickman@ryanmhickman·
Everyone in Embodied AI is talking about Vision-Language-Action (VLA) models. Almost no one is talking about the physical nightmare of collecting the data to train them. You can't scrape a kitchen table or a warehouse shelf from a web browser. To get to millions of hours of diverse, real-world manipulation data, you need hundreds of rigs. But you can't buy them. If you build them out of off-the-shelf developer kits, they weigh 15 pounds, overheat in an hour, require bulky cabling, and break the first time an operator wears them on a job site. At the Instawork Robotics Lab (IRL), we had to build our own. Meet the Instacore: a rugged, 4lb wearable egocentric data-capture engine designed specifically to survive a full shift on a standard power pack. We didn't build a flashy humanoid. We did hard, blue-collar systems engineering: 💾 THE COMPUTE — A custom MediaTek Genio carrier board that runs completely fanless, routing 5 camera streams directly to on-board storage. ⚡ THE I/O PIPELINE — We ditched USB for industrial GMSL. Thin, ultra-flexible coaxial lines route high-speed data down to the backpack and Power-over-Coax (PoC) back up, completely eliminating batteries on the wrist. ⏱️ UNIFIED SENSOR CLOCK — The MediaTek Genio SoC drives a shared master clock straight to the ISPs driving our 5 global shutter sensors, stamping metadata at the microsecond of capture to ensure zero-drift temporal alignment. 👁️ OPTIMIZED OPTICS — 95 DFOV lenses on flexible PCB ribbon modules keep the wrist cams flat to prevent snags. A 145-degree chest camera captures the macro workspace, while a 50mm baseline rectilinear stereo head pair preserves close-up 3D mapping. To build hundreds of these, we took over a warehouse in Mountain View in April, called it the Instalab, and brought in talented Pros with assembly backgrounds from Tesla, Apple, and Meta. To test the systems, we had our Pros wear active rigs while assembling more rigs. The video below shows the raw, time-synchronized Foxglove playback of that exact loop. Now, we’re shipping these units globally to scale data collection for real Pros on the job.
English
9
18
188
26.3K
Stephen Last
Stephen Last@stephen_last·
I gave my dog Macy a Tracy! 🐶✍️
English
1
0
1
45
Glen Arrowsmith retweetledi
Luke Muscat
Luke Muscat@pgmuscat·
My 2nd solo dev game is coming soon. It is a very normal golf game.
English
102
1.2K
20K
2M
Chris Raethke
Chris Raethke@codesoda·
Dropped a project today: Discuss CLI No more reviewing agent plans in the terminal. Discuss CLI turns any Markdown file into a browser review surface with PR-style comments — and your coding agent can join, read the exact text, and reply in the margins. github.com/codesoda/discu…
English
2
1
3
194
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
On one hand, I want to name my home ssid to something extremely common like "Guest" so things like @wiglenet can't easily find me. But on the other hand if my devices are all looking for the "Guest" ssid, it will likely see those in the wild and be handing out my password to each one it sees.
English
17
1
91
18.9K
Glen Arrowsmith
Glen Arrowsmith@garrows·
Slack is down. Productivity improves 10x
English
1
0
1
179
vx-underground
vx-underground@vxunderground·
Regarding the BlackBasta leaks: we haven't reviewed them in totality yet. It's quite a bit of messages in JSON format. It also has some Russian slang which makes it difficult to translate accurately. Thankfully there are some native Russian speakers who have made some interesting highlights. 1. Somewhere in the conversation BlackBasta members discuss Lockbit ransomware group. They believe he cannot be trusted. 2. In the conversation Dispossessor ransomware group is discussed. Dispossessor wants to join BlackBasta. One of the members "Hshsi Jdidi" says they believe Dispossessor has a "good resume" but think they only want to work with them because of their "fame". They also express concern that Dispossessor may be a law enforcement officer. They express concern with the takedowns from Lockbit, Conti, and others. 3. One of the BlackBasta affiliates is a minor. They are 17 years old. 4. They are EXTREMELY interested in VPN exploits. They go to great lengths to acquire, purchase, or find people, capable of delivering VPN exploits. 5. Someone is wanting to grant them access (or sell them access) to their private loader for the cost of $84,000/month 6. Following the success of Scattered Spider, BlackBasta has begun incorperating social engineering into their operations. They have a person named "Nur" who is responsible for identifying key personnel at organizations they want to target. Once a person of influence is identified (manager, HR, etc) they contact them via telephone call. 7. BlackBasta maintains a spreadsheet of victims they're trying to target. It is shared between members and they collaborate on it together. It has the person of interest, if they've tried social engineering them, and general strategy notes. They often identify multiple targets at companies. 8. The caller who contacts victims is tasked with having the employee install "Remote Monitoring and Management" from level-dot-io. Once the application is installed they begin work (eventually). 9. Targets are not selected randomly. BlackBasta has immense interest in Electrical companies, Industrial supply chain companies (Steel, wood, recycling, general supplies), and Tax and/or Financial management companies (companies which manage finances for other companies). 10. Their workflow is documented fairly well. However, because these leaks are from 2023 - 2024, they may be outdated. Here is the general idea: Step 1: Get victim to execute malicious .HTA file. The .HTA file is delivered from either a masqueraded malicious download link, social engineering, or a masqueraded malicious e-mail Step 2: The .HTA file drops a .BAT or .EXE file which contains commands to connect to their C2 server. Step 3: The C2 server has a .JS file which can then deliver an actual payload file allowing either ransomware deployment, or tooling for remote access.
English
9
62
346
56.2K
Glen Arrowsmith
Glen Arrowsmith@garrows·
How dare you! My code is artisanal, single origin, micro-brewed in traditional heirloom graymatter.
English
0
0
1
60
vx-underground
vx-underground@vxunderground·
Hello, this is now an ultra-rare-limited-edition-last-second-speedrun-giveaway. Our friend @_MG_ thought it would be funny to gift us 4 @Hak5 OMG. hacker cables right before my vacation begins. This is a speedrun. I've got 4 cables to giveaway (via voucher, you still have to pay for shipping) before 11PM EST. (approx. 6 hours from now). Leave a comment below, I'll pick 4 random people. If you live in a different timezone and miss this — I'm sorry. Blame MG, not us, because he wanted to do this the very last second (he's a troll). See subsequent post for details on OMG cables (if you live under a rock).
vx-underground tweet media
English
1.3K
58
964
74.2K
Glen Arrowsmith
Glen Arrowsmith@garrows·
AI can't generate ASCII art thumbs up. Prove me wrong.
Glen Arrowsmith tweet mediaGlen Arrowsmith tweet media
English
0
0
0
73