@jhowleyi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States Android App
Account-level information from X, not a live location or the device used for a specific post.
Jack of all trades.
Joined September 2008
- Tweets3.4K
- Following1.6K
- Followers638
- Likes2.2K
jhowley retweeted
Today we are releasing a 1 page version of “Hacking Your Career”
arcanum-sec.github.io/hyc/
We get a bunch of students and early career-seekers looking for resources and advice of getting their 1st gig.
This resource gives all those and more; free trainings, free certificates for your résumé, advice on résumé design, information on career verticals, small sections on interviewing and the hiring process, and more! 🫶🫶
Replying to @DarioAmodei
All the regulations being floated by frontier model companies must be viewed through the lens of them losing tokens to Open-Source models.
The timing of these regulations seems to line up perfectly with Open Source closing the gap significantly (but not completely) — and @nvidia going all in on open source in the last 60 days.
If we’re gonna regulate, why don’t we require that last year’s frontier models and weights be open-sourced?
jhowley retweeted
Seriously not good
jhowley retweeted
holy crap people were not wrong, GPT6-Astra on medium used all my 5 hour quota on plus subscription in 2 minutes and 45 seconds lol @OpenAI this is stupid
jhowley retweeted
Hermes command cheat sheet. Save this. You’ll probably need it again.
UPDATED for the current Hermes command set, including a bunch of genuinely useful commands that have landed recently:
• /goal
• /loop
• /heartbeat
• /bg
• /btw
• /plan
• /review
• /refine
• /moa
• /busy
The commands are spread across Desktop, CLI, messaging, and the terminal, so I rebuilt the sheet around what you’re actually trying to do.
Sessions & context.
Active work.
Goals, loops & plans.
Models & behavior.
Skills, memory & tools.
Automation & coordination.
Recovery & troubleshooting.
Plus the Messaging/Gateway and Terminal essentials.
Verified against the current Hermes source today.
Bookmark it and keep it around.
This list of priorities to focus on is absolutely perfect.
feld.com/archives/2026/09/th…
jhowley retweeted
Replying to @kmele
Kmele, I just stay home. They are unreachable. Though maybe pretending they are open to reason, addressing them in public, helps observers learn what thinking is?
I hope so.
For anyone using LLMs to do security research, bug bounty, red teaming, etc, we made a Discord to discuss/collaborate: mistakes.io/discord/
jhowley retweeted
The biggest mistake beginners make in bug bounty has nothing to do with technique. It's preparing forever instead of starting.
Another course, one more lab, a "proper" setup before they touch a real target. I've watched dozens of people do this to themselves, and I nearly did it too.
Here's some practical advice: pick a service you already use that runs a bounty program, read the scope, and start hacking. Having an initial understanding of how it works will give you an edge most hunters never get on day one.
A week of actual hunting will teach you more than a month of prep ever will.
And don't skip sleep. I've done that, it doesn't pay off.
“Security researchers are doomed because of AI.”
I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill.
Some were idiots.
Some were right.
Here’s where I landed.
jhowley retweeted
If you’re planning to start (or restart) doing bug bounties in 2026, these are my quick tips for you:
→ Solidify your fundamentals (skip this if you’re restarting)
→ Use AI to amplify your skills (this won’t work if you have 0 skills)
→ Aim for high-to-critical impact bugs (low chance of dupe, higher bounty)
→ 0-cost resources: Critical Thinking Bug Bounty Podcast, Portswigger, X, Reddit, HackingHub
→ Build deterministic tools for repeatable tasks using AI (lots of free models for this)
That’s very much it.
For the longer version, here’s my latest blog:
hakluke.com/how-to-start-or-…
jhowley retweeted
Next hacker summer camp giveaway!
3 seats to our “The Bug Hunters Methodology” course!
Like and share to be entered!
arcanum-sec.com/training/the…
jhowley retweeted
The whitepaper is live! Read "Can AI Do Novel Security Research? Meet the HTTP Terminator" here ->
portswigger.net/research/htt…
I highly respect you and your opinion Daniel. I just see repeating patterns of "It's too dangerous for normal people to have access to." Only X group has the knowledge to safely and prudently use this has historically fallen flat for me.
Replying to @DanielMiessler
This mindset entrenches the leads of closed off systems and serves or create a walled garden for the leading closed models. The "pain" of every teen being given access hacking/deepfake Ai is better faced up front and mitigated. I don't want an AI "satanic panic".
jhowley retweeted
Obituaries in 2150 be like:
- John Doe, 116 years old
- Duolingo streak of 95696 days
- WHOOP streak of 41046 days
- Screen Time report: 847,000 hours (down 2% from last week, finally)
- Died as he lived: 94% exercise was in Zone 2
- Survived by his wife, three kids, and 1.2 million unopened LinkedIn requests from recruiters
- His Spotify Wrapped will be released posthumously
- Gmail inbox: 2.4 million unread
- Last words: "Hey Siri, cancel my 7am alarm"
- His Tesla attended the funeral autonomously from the parking lot
- Apple Watch detected the fall. It was too late. It logged it as a workout anyway.
- ChatGPT Plus subscription auto-renewed the day after
- Per his wishes, his ashes were scattered... but the location was shared via Find My for 30 more days
- Cause of death: closed his rings for the 15,000th consecutive day and simply had nothing left to live for.
There it’s a Hermes native port in our optional built in skills, just run
hermes skills install official/mlops/obliteratus
And you’ve got it