@_rybaz

Head of Offensive Security @xorasecurity #1 photography account about hacking. Previous: @bishopfox Red Team @risk3sixty Pentest Practice Lead

Joined March 2020
I would simply write memory-safe code
2
538
How much you wanna bet none of these are actually for me
2
70
Wow shocking
1
21
Even LinkedIn lets me choose to only see notifications that are real interactions
17
Too many people haven't spent time talking to people smarter than they are.
1
113
just wait until keeme k4.4
Replying to @imjustnewatai
Can this outperform the oppos5.5?
68
Listening to non-technical people get frustrated about LLM output is like listening to my in-laws insist that their iPhone switched to Korean all by itself.
2
86
Many non-technical people are blindly trusting LLM output the same way older generations blindly trusted "the Google" and cable news.
67
This is why more companies need to offer disposable, easily terminable email aliases. I don't have to fill out a whole form to stop getting @parallels marketing emails if I can just turn the delivery address off.
1
66
Despite being a "verified defender" with Daybreak, OpenAI still rejected me when I appealed a warning they sent for generating a simple shellcode loader for research. What does "verified defender" even count for, then?
3
298
Account passwords in a vault. Vault passwords in your brain and somewhere on paper. MFA everywhere. Easy.
127
Ryan Basden retweeted
Bump
12
21
5
163
9,423
Don't make me coin "slopreneur"
65
Ryan Basden retweeted
I upgraded the security of the paper password manager
13
34
9
310
96,201
jfc I thought I was on LinkedIn for a second
*Checks date* It’s 2026… this is an actual book, in a major book store, in the technology section, not a Spencer’s as a gag gift or something… We’ve learned nothing…
1
106
Regular reminder to find something you love that has nothing to do with security.
2
79
Staking out how I do and do not use LLMs for good. Just in case anyone was wondering if I'm interested in handing over my humanity for expediency. ryanbasden.com/ai.html
100
Last week, I reconstructed a fully unauthenticated RCE exploit for wp2shell using (almost) nothing but Opus and the official public research.
1
2
292
I was curious, given the amount of detail in the discoverers' original blog post, how hard it would be for Claude to find the missing piece, and what that meant for the traditional model of public disclosure in the age of LLMs.
1
118
Turns out the hardest part was a tiny bit of gaslighting Claude and realizing that it had all the pieces to go from 95% to 100%, it just didn't realize that. Blog post and, of course, exploit code: empiricsecurity.substack.com…
1
118