Jered Bare

5.5K posts

Jered Bare banner
Jered Bare

Jered Bare

@jeredbare

^ Not my profile pic InfoSec, Fitness, and Python. Expect delays.

Katılım Mart 2009
1.7K Takip Edilen750 Takipçiler
Sabitlenmiş Tweet
Jered Bare
Jered Bare@jeredbare·
per ⊂_ヽ   \\ my    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\last    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\email  | 丿 \ ⌒)  | |  ) / ノ )  Lノ (_/
日本語
0
0
14
0
Dom Lucre | Breaker of Narratives
🔥🚨BREAKING: Aftoman revealed to me that he is far from done exposing corruption, Afro announced that he will be targeting pedophiles, people that abuse their power, and help change the way our government is ran forever.
English
309
2.2K
16.8K
370.6K
Jered Bare retweetledi
Stephen Sims
Stephen Sims@Steph3nSims·
I just shared some brief thoughts for those looking to move into cybersecurity, the shift with AI, the job market, and some things I think students should focus on in case it's helpful. I'm just one opinion, but believe we need to be more grounded. youtube.com/watch?v=SUy19R…
YouTube video
YouTube
English
3
24
122
12.8K
Jered Bare retweetledi
Luke Stephens (hakluke)
Best way to grow in this industry: share what you learn publicly. Write a blog post about that weird bug you found. It doesn't have to be groundbreaking. Someone out there needs exactly that piece of knowledge right now. My career in cybersecurity started with a blog about my OSCP experience.
English
9
24
208
15.5K
Jered Bare
Jered Bare@jeredbare·
The right man for the job. Congrats Dave!
Dave Kennedy@HackingDave

Happy to announce that I took a board position (thanks @edskoudis) to SANS Technology Institute (college degree programs). I'm truly excited here as it fits right in to my passion of helping the next generation of cybersecurity folks get into the industry. Amazing mission reaching our youth, and impacting the next generation of hackers. I'm also on the board of Paradigm Cyber Ventures which focuses on K-12 cybersecurity hands-on courses in the high school level and we sponsor and fund many high school cybersecurity programs. Make the world a better place. sans.edu/about/governan…

English
0
0
1
26
Jered Bare retweetledi
GrapheneOS
GrapheneOS@GrapheneOS·
There's a group coordinating attacks on GrapheneOS on X via a Telegram group. They have a couple dozen accounts here. They've based their attacks around claiming modular builds and updates via packages somehow aren't open source. We debunked this here: x.com/GrapheneOS/sta…
GrapheneOS@GrapheneOS

We've written this post as a thorough debunking of extraordinarily inaccurate and misinformed claims being made about GrapheneOS. The main post making these claims is linked at the bottom. A growing number of our apps are built and signed separately from the OS to provide out-of-band updates. Each of these apps has reproducible builds. The official standalone releases are included in the OS rather than making separate builds for each device as part of building the OS. This is the standard and most sensible way to do things. It means the apps bundled with the OS are the same builds as the standalone releases instead of having two separate types of builds with two separate build systems. Both forms of building the apps are reproducible. It makes far more sense to use Android's standard app build system and tooling for standalone apps. It makes it much easier to work with them and for people to contribute. Needing to build apps as part of building the whole OS is a major barrier to contributions and can be avoided. Android supports out-of-band updates for the vast majority of the OS. These out-of-band updates are a major advantage over iOS. Many people aren't aware of how much can be updated out-of-band for Android. It's gradually turning into the entire OS having quite modular out-of-band updates which are fully compatible with the verified boot system. It still makes sense to have regular full OS updates which update all of the bundled components. A huge portion of Android is shipped as APKs which can be updated out-of-band. These can be built with the OS for simplicity but can also be built separately with their own standalone releases. If they have their own standalone releases, those are supposed to be bundled with the OS as a prebuilt instead of using a separate build system for the OS updates and out-of-band updates. It would also not be reproducible if separate build systems and toolchains were being used for both. An even larger portion of the OS can be updated out-of-band via APEX components which are an APK containing a structured filesystem with native libraries, services, data, nested APKs and other arbitrary files. Both APEX components and APKs are fully compatible with verified boot. GrapheneOS enables enforced verified boot for system APK updates rather than only APEX components. Android also has out-of-band updates to images via chained vbmeta (verified boot metadata) images. This works by having a hash of a key for chained vbmetas stored in the main vbmeta where each vbmeta has separately enforced downgrade protection via the secure element. GrapheneOS has very frequent OS releases and doesn't need out-of-band updates as much as the stock Pixel OS or especially the broader Android ecosystem. We mainly use out-of-band updates for our own apps with standalone releases and include the official releases of those in the OS releases rather than making separate builds. That's the way it's supposed to be done. Google Mobile Services Android operating systems use Google Play system updates providing APEX updates via standard builds from the Google Play Store. This provides monthly updates to large portions of the OS across devices regardless of their OS update cycle. We have no use for their approach since we have consistent OS updates which are more frequent than monthly releases. We could still set up out-of-band APEX updates to enable shipping an urgent for a specific component without an OS release but we don't currently use them as it would only save build time rather than improving usability. Android uses prebuilts for the kernels and Chromium WebView which are built separately from the OS. The expected way to bundle most apps with the OS is to have standalone releases with the official releases bundled with it. This is how the stock Pixel OS handles APK and APEX components updated out-of-band. It doesn't interfere with reproducible builds. Building, signing and shipping updates to the OS via modular components instead of building the entire OS for every change is going to be increasingly important as GrapheneOS scales up to a larger development team and a larger number of supported devices. It makes it far easier for people to work on smaller parts of the OS and we can release smaller updates for specific components. We're using it on a case-by-case basis for components we need to update frequently such as our GmsCompatConfig APK shipping the text file setting up most of our sandboxed Google Play compatibility layer shims. We also plan to start shipping GmsCompatLib as a standalone app but it was delayed due to banking apps wrongly believing updating it out-of-band was tampering. The claims which are being made in the linked post are extremely misinformed and backwards. They're attacking us for using approaches focused on security while claiming doing things in a far less secure way would be much better. The motivation for it is quite clearly promoting non-hardened operating systems through desperate attempts at misleading people about GrapheneOS with poorly informed claims. They're claiming we should be doing builds and signing on cloud servers because they believe having CI web interface is a substitute for third parties reproducing and verifying builds. We make all of our official builds on local infrastructure under our physical control for clear security reasons. Our app and OS builds are both reproducible. We're gradually working on turning reproducible builds into a more useful feature by setting up a system of having alternate build locations and a system for verifying the results match across our locations and also third party locations. Our App Store and System Updater are eventually going to support verifying builds based on other official and third party build locations. Moving our builds and signing to cloud infrastructure would not reduce trust in us but would greatly expand attack surface and how much needs to be trusted. GrapheneOS is a serious privacy and security project which is in the process of greatly expanding by hiring many developers and other people. We're improving our overall organizational and development processes as part of expanding. Expanding our use of out-of-band updates to the extent that it makes sense is part of this. x.com/TheVancedGamer…

English
13
106
1.1K
29K
Jered Bare
Jered Bare@jeredbare·
Been using Claude for the past few weeks and it literally scares the crud out of me.
English
0
0
0
36
Paul Saladino, MD
Paul Saladino, MD@paulsaladinomd·
>Not sure where this level of vitriol is coming from, Sama, but I appreciate you sharing your thoughts, let's clarify a few points. >I'm genuinely happy if my work has helped anyone (and I've seen plenty of positive stories in the comments). That's always been the goal. >Carnivore was a powerful tool for me, it helped heal my eczema by removing potential plant triggers and taught me a ton about bioindividuality. It worked well for a while, but it wasn't sustainable long-term for my body. Adding real-food carbs (fruit, honey) dramatically improved my testosterone, thyroid, sleep, energy, and workouts. That's not opinion; it's what my labs and how I feel show. Bioindividuality is real, what works for one person (or at one life stage) won't for everyone. I hope people take that lesson: experiment thoughtfully, prioritize simple whole foods over meds when possible. >On fat/liver: I was eating high fat and moderate liver on strict carnivore, claims otherwise simply aren't accurate. >Liver remains one of the most nutrient-dense foods we know of. Humans have thrived on it for hundreds of thousands of years. Fresh is ideal, but @heartandsoilHQ makes high-quality desiccated options that have genuinely helped thousands (check the testimonials). I'm proud of that work. >Carbs from real sources like fruit/honey have solid data behind them for metabolic health in most people. No major studies show harm when consumed whole/in moderation. If you've got contrary evidence, I'd genuinely love to see it. Happy to host you on the podcast to discuss carbs, keto downsides (thyroid/sex hormones/cortisol), or anything else. >Re: scaremongering/toxins : my goal is awareness so people can make informed choices in a world full of environmental challenges. If that content doesn't resonate, no problem,skip it. >Vegetables work fine for some; I eat few but cheer for anyone thriving on them. >The @eatlineage bar uses real-food sweeteners (organic honey, coconut nectar, wild blueberries/strawberries). Far cleaner than most options out there. Coconut nectar has prebiotic benefits in studies; honey brings probiotics also and improves gut flora composition. It's designed as a convenient real-food tool when steak/eggs aren't practical. >In short: I explored strict carnivore, learned a lot, evolved based on my own results, and stayed transparent. I am thriving today because I stayed open-minded. You're welcome in Costa Rica anytime for a real conversation, ideas improve when shared in person. Keep doing the work that helps people with diet; I respect that. Workout time, talk soon?
English
60
11
1K
56.2K
Sama Hoole
Sama Hoole@SamaHoole·
>Be Paul Saladino >Heal your eczema with carnivore >Write a book about how plants are poison >Tell everyone that nose-to-tail is essential so you can sell liver pills at $60 a bottle >Not eating enough fat, eating way too much liver >Things start to nosedive >Start adding honey because your testosterone has collapsed >Tell your audience carbohydrates are actually fine and you've grown >Migrate to 300g of sugar per day and call it ancestral >Tell everyone carnivore was slowly destroying you >Explain that ancestral humans ate carbs because raw meat contains trace glycogen >Confirm Liver King is completely natural, no notes >Liver King is on $11,000 a month of synthetic hormones >Pivot to scaremongering: soap, shampoo, sunscreen, toothpaste, toilet paper >Vegetables turn out to be okay actually >Launch protein bar sweetened with coconut nectar >It is ancestral >You said so >The liver pills are still available >Nothing has been refunded
Sama Hoole tweet media
English
289
148
4K
602.8K
Jered Bare
Jered Bare@jeredbare·
@paulsaladinomd @eatlineage I ordered some. Although, I do disagree with you on some things, if you're trying to make food better overall I'm willing to give it a shot. If the macros are accurate and taste is there, this could be a game changer.
English
0
0
0
69
Paul Saladino, MD
Paul Saladino, MD@paulsaladinomd·
The most controversial protein bar ever? 😏 Our @eatlineage real-food protein bar went viral—tons of love, some hate. Let's address the critics head-on: “But 12g added sugar…”: FDA labels organic honey, wild blueberries, organic strawberries + coconut nectar as “added sugars.” These aren't refined sucrose and studies show honey causes lower blood glucose spikes than sucrose, with enzymes/polyphenols/minerals intact. Healthier metabolic/gut flora response. This is all we use to sweeten the bars! “But plastic packaging…”: We test rigorously, every batch 100% free of detectable microplastics, heavy metals, pesticides, mycotoxins. No other bar tests this hard. Should we release the next batch in sheep stomach wrapper next? 😂 Stay tuned for the ultimate ancestral packaging. “Why collagen?”: Grass-fed whey + collagen = better amino balance (glycine/hydroxyproline offsets methionine). Whey crushes for muscle; collagen supports joints/skin/hair/gut. Recent studies show whey-collagen blends boost myofibrillar AND connective tissue protein synthesis better than whey alone. “High-quality protein?”: PDCAAS 0.86—very high (perfect is 1, most bars are far lower). We beat the pants off competitors in head-to-head; full results soon. “Real food first… hypocrite?”: Real food is king. But steak/eggs/salmon suck at the gym, airport, or with kids on-the-go. You asked for the cleanest, most convenient real-food protein bar: 20g grass-fed protein + tallow + honey + berries. No junk. You’re welcome. Proudest launch ever. Best bar created. Grab it: lineageprovisions.com/bar Controversial or just honest? 🔥 @eatlineage
Paul Saladino, MD tweet media
English
118
28
677
42.5K
Jered Bare retweetledi
kuzushi
kuzushi@kuzushi·
I co-published another paper, this one on code-patch generation using CWE as templates: mdpi.com/2673-4591/123/…
English
2
5
9
771
Jered Bare retweetledi
Lina
Lina@d0rkph0enix·
Hey infosec frens! I need a speaker for May SecKC, one of our speakers had a work schedule change that is going to cause him to be unable to attend. Let me know if you are interested in coming to KC and giving a talk; we can pay for travel and we shall feed thee!! Thanks all!
English
22
46
118
10.1K
Jered Bare retweetledi
Erik Maday
Erik Maday@erikmaday·
@unusual_whales The docs say "This project was inspired by the community MCP server built by Erik Maday" but this is literally my code republished under the Unusual Whales name. It's not inspired, this IS my MCP...
English
52
58
846
43.2K
I am Jakoby
I am Jakoby@I_Am_Jakoby·
Guess who finally talked at their 1st ever conference?! This was genuinely the best week of my life i think Bought a nice camera right before going and recorded the whole thing! Full VLOG coming soon!
I am Jakoby tweet media
English
44
11
343
13.5K
Jered Bare retweetledi
Jaber
Jaber@Akashi203·
We open sourced an operating system for ai agents 137k lines of rust, MIT licensed we love @openclaw and it inspired a lot of what we built. but we wanted something that works at the kernel level so we built @openfangg agents run inside WASM sandboxes the same way processes run on linux. the kernel schedules them, isolates them, meters their resources, and kills them if they go rogue. it has 16 security layers baked into the core. WASM sandboxing, merkle hash-chain audit trails, taint tracking on secrets, signed agent manifests, prompt injection detection, SSRF protection, and more. every layer works independently. giving an LLM tools with zero isolation is insane and we're not doing it. we also created something called Hands. right now every ai agent is a chatbot that waits for you to type. Hands are different. you activate one and it runs on a schedule, 24/7, no prompting needed. your Lead Hand finds and scores prospects every morning and delivers them to your telegram before you wake up. your Researcher Hand writes cited reports while you sleep. your Collector Hand monitors targets and builds knowledge graphs continuously. they work for you. you don't babysit them github.com/RightNow-AI/op…
Jaber tweet media
English
273
502
4.4K
730.6K
Jered Bare retweetledi
Gillian Hadfield
Gillian Hadfield@ghadfield·
NIST just launched an AI Agent Standards Initiative for identity, security, and interoperability. AI agents are becoming economic actors with zero legal infrastructure in place. We require businesses to register to operate. Why expect less of AI agents? nist.gov/news-events/ne…
English
51
259
935
109K
Jered Bare retweetledi
SANS Offensive Operations
SANS Offensive Operations@SANSOffensive·
🧠 Tomorrow: Learn how to use natural language to control your C2. This workshop shows how to combine MCP + Empire C2 + AI assistants for fully conversational red team ops. 📅 Feb 26 | 10:00 AM–12:00 PM ET 🔗 go.sans.org/00QLrf
SANS Offensive Operations tweet media
English
3
18
98
6.2K
Jered Bare retweetledi
GitHub Projects Community
GitHub Projects Community@GithubProjects·
Automate your entire penetration testing workflow from reconnaissance to post-exploitation
GitHub Projects Community tweet media
English
10
92
668
33.6K
Jered Bare retweetledi
Dave
Dave@GamewithDave·
No accounts. No logins. No patches. No DLC roadmap. Just the game. We didn’t realise how good we had it.
Dave tweet media
English
654
6.5K
50.6K
1.4M