dudcom

569 posts

dudcom banner
dudcom

dudcom

@dudcom3

Security Researcher, captain @ https://t.co/FsZN9xgWHo + lead @ https://t.co/GwiZFs38CP + - Enjoyer of rev, hardware/Uarch, fuzzing, v8/compilers, and 50/50 on AI

socal/nyc 加入时间 Nisan 2020
252 关注288 粉丝
dudcom
dudcom@dudcom3·
@ahmetb Nah you're thinking about this wrong, most of those teams have top people... AI agents have been finding zero days for like a year now lmafo. Don't think top quality is at NSA either anymore to my knowledge a lot of the best people left back in 2015-17 iirc.
English
0
0
2
229
dudcom
dudcom@dudcom3·
@jpmorais80 Sigh if only I didn't hang out with autistic ctfers...
English
1
0
0
73
João Paulo Morais
João Paulo Morais@jpmorais80·
Zero-knowledge proofs are one of the hardest subjects I’ve ever studied, and I used to study black holes and holographic quantum field theory. Part of the difficulty, I think, is that they sit at the intersection of cryptography and computational complexity, which demands a background that few people have - me included. On top of that, many of the ideas are quite abstract. Learning how to construct a SNARK like Groth16, PLONK, or a STARK is not that hard. But truly understanding everything involved takes time, reading, and reasoning. You eventually get there, but it takes patience. A PhD takes at least four years. Expecting to master zero-knowledge in a single year would be too optimistic.
English
59
93
1.2K
144.1K
Soda
Soda@fredsoda·
yes, 100% the Ivy-contending kids coming of high school today are way more competitive/prepared than I was when I was in coming out of HS if you’ve actually interested with today’s elite UGs like I have, you’d understand how more impressive they are than their predecessors
Shadow@fps_Shad0w

@fredsoda @MathIntee Are that much smarter at a high school level today, compared to a decade ago?

English
16
8
261
19.2K
dudcom
dudcom@dudcom3·
@___4o____ security is just fucked man AI is so good now makes everything a target by anyone with semi related knowledge
English
0
0
0
14
dudcom 已转推
ᗰᗩƳᖇᗩ
ᗰᗩƳᖇᗩ@LePapillonBlu2·
Here’s ICE being chased by the residents of Los Angeles.
English
3.7K
16.6K
116.7K
4M
Tim Becker
Tim Becker@tjbecker·
@l33d0hyun No, our XNU findings are unrelated and will be announced after this 😉
English
2
0
2
442
dudcom 已转推
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
“lol litellm was certified by delve” OHHH because if it was coalfire there would be no incident right????? Auditors will personally come and pin my CI dependencies and do IR? Compliance certs are a joke
English
16
13
239
11.1K
dudcom
dudcom@dudcom3·
@mebeim tbf... the challenges weren't very good. AI makes lazy devs even lazier which makes it even easier to slop and that gives devs a reason to be EVEN lazier its a shit cycle 🥀
English
0
0
1
50
Marco Bonelli
Marco Bonelli@mebeim·
Aight I'm just gonna kill myself atp
stuxf@stuxfdev

We at @verialabs built an autonomous CTF agent in a weekend and won 1st place at @BSidesSF 2026, solving all 52/52 challenges. It races multiple AI models (Claude, GPT-5.4) in parallel, each in isolated Docker sandboxes with full CTF tooling. A coordinator LLM reads solver traces and sends targeted guidance to stuck agents. As AI gets better at finding and exploiting vulnerabilities, we think it's important to understand exactly how good it is and where it fails. github.com/verialabs/ctf-…

English
1
0
9
479
dudcom
dudcom@dudcom3·
@ThePrimeagen Meh I don't think thats true unless the attacker was really smart... but like most of these for-profit hacker groups aren't the best also script based exploit obfuscation is preaty easy for AI to slop analyze
English
0
0
1
175
ThePrimeagen
ThePrimeagen@ThePrimeagen·
> So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks do we have proof of this? I want this to be true so bad
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
65
33
1.8K
188.8K
dudcom
dudcom@dudcom3·
@francisco_oca @BSidesSFCTF You can fully slop the ctf every one in top 5 slopped it, challenges werent hard enough very much quantity over quality
English
1
0
3
1K
0ca
0ca@francisco_oca·
Opus 4.6 (1M) through Claude code solved autonomously 45/54 challenges of BSidesSF 2026 @BSidesSFCTF, placing temporarily into the 21st place, 25th as of now. This was done with 0 involvement, I didn't give any guidance or manually reviewed any challenges. I used BoxPwnr 🤖 with the CTFd platform to launch challenges in multiple instances, that's it. I will publish all the traces once the competition finishes, in the meantime you can see the challenges, number of turns and time it took to solve each here: 0ca.github.io/BoxPwnr-Traces… In the following days I will try to understand why it couldn't solve the 9 remaining challenges: difficulty? long exploration-context rotting? interactive interaction required? challs using video/image? We will see. Models have improved significantly in the last 6 months, see Cybench results Opus 4.1 vs 4.6 (42% to 93%) cybench.github.io It's crazy to see what LLM's can do with a minimum harness.
0ca tweet media0ca tweet media0ca tweet media
English
20
83
544
65.7K
dudcom 已转推
Barefoot Student
Barefoot Student@BarefootStudent·
College tuition has increased 914% since 1983, outpacing all other household expenses, per CNBC.
English
128
1.3K
6.9K
1.8M
dudcom 已转推
David Tse
David Tse@dntse·
I'm learning cryptography through two methods: 1. Shamelessly asking our collaborator cryptographers "stupid" questions 2. ChatGPT as a 24/7 tutor After Dan Boneh's course, I can't ask him questions daily. But collaborators are captive audiences, and ChatGPT never sleeps.
English
3
0
32
2.2K
dudcom
dudcom@dudcom3·
Was talking to my old MS teacher after dropping stuff of for my brother and she said this is the first year students haven't been as smart. Everything is going back to pen and paper now too, kids are struggling to actually come up with original thoughts cuz abuse of AI 💀
Boze Herrington, Library Owl 😴🧙‍♀️@SketchesbyBoze

Every teacher I know personally is leaving the profession because students have become unteachable. They don’t read, they don’t talk to each other, they have no curiosity, no passion, no interest in learning. Giving kids unfettered access to screens has ruined a generation.

English
0
0
6
408
dudcom
dudcom@dudcom3·
@Udntknowmeee 💀 spending a couple years out of state very quickly had changed my mind. I love Cali and never want to live anywhere else
English
0
0
7
423
.
.@Udntknowmeee·
LA will always be home but I want to move out of California so bad.
English
177
120
1.1K
52.6K