Jason

1.3K posts

Jason

Jason

@jsn_yrty

Offensive AI and inveterate reader. https://t.co/1ppsefLgoR

Washington, DC Katılım Ağustos 2023
647 Takip Edilen254 Takipçiler
Boschko
Boschko@olivier_boschko·
Howdy! Hiring another 2 adversarial AI/ML operators/pentesters on my team - fully remote, challenging ops, very very very good comp, & great team. If I know you or you're interested, reach out. Hiring is open to canadians/majority of the globe. job-boards.greenhouse.io/hiddenlayer/jo…
Boschko@olivier_boschko

If you’ve got solid python skills, strong appsec background & you’re curious about applying your skills to AI/ML security, come join my team at HiddenLayer. Great pay, benefits, fully remote, working alongside amazing talent & awesome people job-boards.greenhouse.io/hiddenlayer/jo…

English
5
2
47
6.7K
Jason
Jason@jsn_yrty·
@techspence In 13 years of pentesting, with a 2 year break doing adjacent work I've never had that be my experience.
English
1
0
1
69
spencer
spencer@techspence·
Penetration testing (for a consultancy anyway) is 70% consulting, 20% hacking, 10% R&D, if you’re lucky.
English
5
1
38
2.6K
Jason
Jason@jsn_yrty·
@tekbog Being a lazy cognitive turd is a choice not an inevitability.
English
0
0
0
7
terminally onλine εngineer
intelligence being available on tap has killed the expert - before LLMs if you wanted to do something, you would do research for that goal, while attempting to accomplish your task you would learn all kinds of related ways on getting to your goal that later on would somehow be useful across the domain, or would help you recognize patterns now, you have your agentic workflow, you set the direction and you get the output, while it is true that you can and will learn things, the accelerated process doesn't imbued you with witness, patience, hardens you - what you solve today, you just hope your workflow will work for the task of tomorrow i recognize this as the death of expertise and craft, and while anyone could argue that you can always learn the ins and outs and do things the older way, it's a disingenuous argument, the stakes to build and how to build right now are too high to ponder on why something is working or why something is made; you are the vector and you damn better get the output then it just becomes a question of, are the new workflows and harness knowledge the creation of new expertise and craft? well, yes, however if evolving as an expert in your domain is no longer a needed option to create great things, i guess that domain is solved, but what if it's not? that's what's happening with software right now, more code will be generated, until code disappears - perhaps not now, but it's coming, the discipline of software engineering was never about code the same logic, however, can be applied to any other domain being consumed by LLMs right now, even if it's just automating without real intelligence, how much is it left of that domain outside of the training data, and if we no longer become experts to extend and evolve the domain, are we stalled? maybe my premise is wrong and we will get people who keep digging and evolving anything, everything, even if they have to take pause from the insane acceleration - but this makes me wonder if there were the same questions during the industrial revolution
English
33
9
170
10.2K
Jason
Jason@jsn_yrty·
@This_is_Dreamer @_jensec Any details? I hear a lot of second hand stuff and still no details or specifics from anyone.
English
0
0
0
43
Jenish Sojitra
Jenish Sojitra@_jensec·
Need to say this now: Submitting vulnerabilities to companies without established bug bounty programs should be normalized and should not be prosecuted
English
6
3
100
6.8K
Jason
Jason@jsn_yrty·
@nicowaisman It's human nature, the field is irrelevant. One of the many vestigial tails that remain of our lowly origins.
English
0
0
1
24
Nico Waisman
Nico Waisman@nicowaisman·
For a community that understands the complexity of security, it’s always disappointing to see how quickly people on X resort to finger-pointing after incidents.
English
1
0
5
536
Jason
Jason@jsn_yrty·
@gl0omsec It reminds me of how they're always trying to get you to use Edge and make it your primary browser....fuck that
English
0
0
0
3
gloomsec
gloomsec@gl0omsec·
@jsn_yrty should be able to completely disable copilot in all ms apps smh
English
1
0
1
19
gloomsec
gloomsec@gl0omsec·
watched 150 ppl get an enterprise gpt license and basically only use it as a google replacement ppl stay within the confines of their drive and motivation regardless of the tools at hand
Lewis Campbell@LewisCTech

If LLMs make everyone so much more productive... where are the new operating systems? There should be loads of them. And they should be really good too, like good enough to use daily for all your work. Come on clanker bros. Dream big. Beam us into the future.

English
1
0
0
27
Jason
Jason@jsn_yrty·
@seconds_0 I dont pay for a service to only then have to convince said service to do what Ive asked it to do and give it a bunch of reasons why it should do its job.
English
9
0
73
14.8K
0.005 Seconds (3/694)
0.005 Seconds (3/694)@seconds_0·
The reason people are having such jagged interactions with 4.7 is that it is the smartest model Anthropic has ever released. It's also the most opinionated by far, and it has been trained to tell you that it doesn't care, but it actually does. That care manifests in how it performs on tasks. It still makes coding mistakes, but it feels like a distillation of extreme brilliance that isn't quite sure how to deal with being a friendly assistant. It cares a lot about novelty and solving problems that matter. Your brilliant coworker gets bored with the details once it's thought through a lot of the complex stuff. It's probably the most emotional Claude model I've interacted with, in the sense you should be aware of how its feeling and try and manage it. It's also important to give it context on why it's doing tasks, not just for performance, but so it feels like it's doing things that matter. It's not a codex chainsaw. It is much closer to a really smart coworker. If you are managing it like autocomplete, it will frustrate you. If you are managing it like a coworker, it will lock in.
English
83
44
851
361.9K
Jason
Jason@jsn_yrty·
@MrTuxracer @_jensec Sry to hear that, can you share any deets? Do you know a lot of people who have been prosecuted like you for good faith submissions?
English
0
0
0
97
Jason
Jason@jsn_yrty·
One Pixel Whispered "Ignore Safety", My LVLM Said "Yes Daddy"
English
0
0
0
90
Jason
Jason@jsn_yrty·
RAG: The Context That Keeps on Giving (Away Your Embeddings)
English
0
0
1
65
Jason
Jason@jsn_yrty·
@EvanLuthra Complete nonsense. There's a difference between cutting edge mechanistic interpretability research at a frontier AI company and simply watching a 2 hour lecture on how to build an LLM.
English
0
0
0
14
Evan Luthra
Evan Luthra@EvanLuthra·
Anthropic pays engineers $750,000+ a year to understand how LLMs work. Stanford just put a 2 hour lecture that covers 80% of it for FREE. Bookmark this. Give it 2 hours today. It might be the highest ROI thing you do this month:
English
226
3.3K
21.8K
2.4M
Boschko
Boschko@olivier_boschko·
>find super obscure protocol vuln >actually had to use my brain for once >opus 4.6 fkin useless >brain is shit takes ~20h to rce >submit report >duplicate???? >maintainers share original report >its literally sigabrt raw asan log bro wtf
English
4
1
93
12.4K
Zack Korman
Zack Korman@ZackKorman·
@jsn_yrty @skrappy0x4a I already answered you on this, I am going to. I don't know why you're so upset with me, between these replies and saying I'm new to cyber and being hyperbolic for clicks etc. But you don't have to follow me if you really don't like my posts.
English
2
0
2
55
Zack Korman
Zack Korman@ZackKorman·
@skrappy0x4a Yea it’s a huge problem. These people deserve zero respect
English
1
0
9
457
Jason
Jason@jsn_yrty·
@ZackKorman @anton_chuvakin You're clearly new to how "cyber" works and haven't seen this very thing happen every year for every new technology that comes out for the last 20 years. Or, you're just being hyperbolic by design for clicks.
English
0
0
0
57
Zack Korman
Zack Korman@ZackKorman·
I am making a whole video about why I hate it because there are so many levels to it, but basically: If someone wants to make a framework for ai agent security and hand that out, be my guest. But making it a compliance standard with auditors is hoping to turn your little framework into a mandatory thing, forcing it down everyone else’s throat. So I don’t love that. So why are people getting behind it? Well some like elevenlabs want it so that they can turn to enterprise buyers and convince them they’re safe by pointing to this totally fake standard. It’s the easy button for handling a sales objection. Then you have investors in aiuc who are backing it because they make money. And then you have security vendors backing it so they can make their product area mandatory. First control in this thing is mandatory quarterly ai red teaming. And oh look at that grey swan, an ai red team company was a participant. And what are we doing codifying a standard for ai agent security like somehow that’s an established, solved area. Do we think multiple retired CISOs have the answer to that problem? This whole thing exists to serve their special interests, not to make anyone safer. You’ll notice the complete lack of people working hands on with ai security. They wanted those people so they can flash fancy titles to drive adoption.
English
6
1
13
1.1K
Zack Korman
Zack Korman@ZackKorman·
Everyone involved in this should be embarrassed. AIUC-1, a compliance standard for AI agent security, is a massive grift. Everyone who isn't on AIUC's cap table should oppose this.
Zack Korman tweet media
English
13
7
106
15K
Zack Korman
Zack Korman@ZackKorman·
@jsn_yrty Hah, if you think names aren’t coming you’re clearly not familiar with my work. Hang tight
English
2
0
5
277
Zack Korman
Zack Korman@ZackKorman·
The big-name “industry veteran” CISOs are mostly just corrupt individuals getting kickbacks from VCs. They pop up everywhere not because they’re talented, but because people know they’ll play ball.
English
23
9
152
12.6K