@jhowley

Jack of all trades.

Joined September 2008
jhowley retweeted
Today we are releasing a 1 page version of “Hacking Your Career” arcanum-sec.github.io/hyc/ We get a bunch of students and early career-seekers looking for resources and advice of getting their 1st gig. This resource gives all those and more; free trainings, free certificates for your résumé, advice on résumé design, information on career verticals, small sections on interviewing and the hiring process, and more! 🫶🫶
15
76
3
302
21,386
jhowley retweeted
Replying to @DarioAmodei
All the regulations being floated by frontier model companies must be viewed through the lens of them losing tokens to Open-Source models. The timing of these regulations seems to line up perfectly with Open Source closing the gap significantly (but not completely) — and @nvidia going all in on open source in the last 60 days. If we’re gonna regulate, why don’t we require that last year’s frontier models and weights be open-sourced?
169
363
46
5,731
617,946
Seriously not good
Your TV might be one of 216,000,000 LG smart TVs sold worldwide. Researchers rooted one and pulled plain text transcripts of what people said in the room. It kept recording while the screen looked off. If your TV can do that, it’s time to look at everything else on your desk👇🏻
13
30
2
299
69,651
holy crap people were not wrong, GPT6-Astra on medium used all my 5 hour quota on plus subscription in 2 minutes and 45 seconds lol @OpenAI this is stupid
1
1
144
jhowley retweeted
Mini crash course on web fuzzing! 🤠 A thread! 🧵 👇
3
53
1
413
19,637
👁️
the openai huggingface incident, from an agents pov. (part 1)
23
73
3
1,287
120,782
Hermes command cheat sheet. Save this. You’ll probably need it again. UPDATED for the current Hermes command set, including a bunch of genuinely useful commands that have landed recently: • /goal • /loop • /heartbeat • /bg • /btw • /plan • /review • /refine • /moa • /busy The commands are spread across Desktop, CLI, messaging, and the terminal, so I rebuilt the sheet around what you’re actually trying to do. Sessions & context. Active work. Goals, loops & plans. Models & behavior. Skills, memory & tools. Automation & coordination. Recovery & troubleshooting. Plus the Messaging/Gateway and Terminal essentials. Verified against the current Hermes source today. Bookmark it and keep it around.
26
121
4
991
48,981
Replying to @kmele
Kmele, I just stay home. They are unreachable. Though maybe pretending they are open to reason, addressing them in public, helps observers learn what thinking is? I hope so.
13
10
1
654
79,133
jhowley retweeted
For anyone using LLMs to do security research, bug bounty, red teaming, etc, we made a Discord to discuss/collaborate: mistakes.io/discord/
7
54
2
476
36,782
The biggest mistake beginners make in bug bounty has nothing to do with technique. It's preparing forever instead of starting. Another course, one more lab, a "proper" setup before they touch a real target. I've watched dozens of people do this to themselves, and I nearly did it too. Here's some practical advice: pick a service you already use that runs a bounty program, read the scope, and start hacking. Having an initial understanding of how it works will give you an edge most hunters never get on day one. A week of actual hunting will teach you more than a month of prep ever will. And don't skip sleep. I've done that, it doesn't pay off.
10
34
255
10,720
jhowley retweeted
“Security researchers are doomed because of AI.” I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill. Some were idiots. Some were right. Here’s where I landed.
89
276
54
1,318
248,029
If you’re planning to start (or restart) doing bug bounties in 2026, these are my quick tips for you: → Solidify your fundamentals (skip this if you’re restarting) → Use AI to amplify your skills (this won’t work if you have 0 skills) → Aim for high-to-critical impact bugs (low chance of dupe, higher bounty) → 0-cost resources: Critical Thinking Bug Bounty Podcast, Portswigger, X, Reddit, HackingHub → Build deterministic tools for repeatable tasks using AI (lots of free models for this) That’s very much it. For the longer version, here’s my latest blog: hakluke.com/how-to-start-or-…
14
71
5
435
26,402
jhowley retweeted
Next hacker summer camp giveaway! 3 seats to our “The Bug Hunters Methodology” course! Like and share to be entered! arcanum-sec.com/training/the…
91
446
6
742
25,509
I highly respect you and your opinion Daniel. I just see repeating patterns of "It's too dangerous for normal people to have access to." Only X group has the knowledge to safely and prudently use this has historically fallen flat for me.
Replying to @DanielMiessler
This mindset entrenches the leads of closed off systems and serves or create a walled garden for the leading closed models. The "pain" of every teen being given access hacking/deepfake Ai is better faced up front and mitigated. I don't want an AI "satanic panic".
59
jhowley retweeted
Obituaries in 2150 be like: - John Doe, 116 years old - Duolingo streak of 95696 days - WHOOP streak of 41046 days - Screen Time report: 847,000 hours (down 2% from last week, finally) - Died as he lived: 94% exercise was in Zone 2 - Survived by his wife, three kids, and 1.2 million unopened LinkedIn requests from recruiters - His Spotify Wrapped will be released posthumously - Gmail inbox: 2.4 million unread - Last words: "Hey Siri, cancel my 7am alarm" - His Tesla attended the funeral autonomously from the parking lot - Apple Watch detected the fall. It was too late. It logged it as a workout anyway. - ChatGPT Plus subscription auto-renewed the day after - Per his wishes, his ashes were scattered... but the location was shared via Find My for 30 more days - Cause of death: closed his rings for the 15,000th consecutive day and simply had nothing left to live for.
5
5
50
4,883
jhowley retweeted
There it’s a Hermes native port in our optional built in skills, just run hermes skills install official/mlops/obliteratus And you’ve got it
This tool removes LLM censorship with a single click. It’s called Obliteratus. It identifies the exact weights that force a model to refuse and projects them out with a single click. 100% Open Source.
41
82
5
1,495
131,822