@_rybazi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Head of Offensive Security @xorasecurity #1 photography account about hacking. Previous: @bishopfox Red Team @risk3sixty Pentest Practice Lead
Joined March 2020
- Tweets2.3K
- Following215
- Followers1.9K
- Likes1.4K
Listening to non-technical people get frustrated about LLM output is like listening to my in-laws insist that their iPhone switched to Korean all by itself.
Many non-technical people are blindly trusting LLM output the same way older generations blindly trusted "the Google" and cable news.
This is why more companies need to offer disposable, easily terminable email aliases. I don't have to fill out a whole form to stop getting @parallels marketing emails if I can just turn the delivery address off.
Despite being a "verified defender" with Daybreak, OpenAI still rejected me when I appealed a warning they sent for generating a simple shellcode loader for research.
What does "verified defender" even count for, then?
Account passwords in a vault. Vault passwords in your brain and somewhere on paper. MFA everywhere.
Easy.
Ryan Basden retweeted
Replying to @UK_Daniel_Card @Shooters_Texas
I upgraded the security of the paper password manager
Staking out how I do and do not use LLMs for good. Just in case anyone was wondering if I'm interested in handing over my humanity for expediency.
ryanbasden.com/ai.html
Last week, I reconstructed a fully unauthenticated RCE exploit for wp2shell using (almost) nothing but Opus and the official public research.
I was curious, given the amount of detail in the discoverers' original blog post, how hard it would be for Claude to find the missing piece, and what that meant for the traditional model of public disclosure in the age of LLMs.
Turns out the hardest part was a tiny bit of gaslighting Claude and realizing that it had all the pieces to go from 95% to 100%, it just didn't realize that.
Blog post and, of course, exploit code: empiricsecurity.substack.com…