@robertaugeri
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
25+ years Appsec,Web Application Security Consortium(WASC) cofounder,Baythreat Organizer,Ex-PayPal/eBay/Box/Workday/Coinbase infosec. https://nitter.cf/t.co/TyG8aOV8on
USA
Joined March 2009
- Tweets24.6K
- Following855
- Followers1.4K
- Likes23.7K
Pinned Tweet
Announcement for my new side project!
-------------------------------------------------------
SecTemplates.com - Release #1: Security incident response program pack 1.0
Introduction
I've worked in the security industry for over 20 years and, during this time, have built and shaped many security programs. At every company I join, I find myself recreating or developing security programs from scratch. My peers have been in a similar position, and the more people I speak with at smaller companies, the more obvious it becomes that there isn't a single location where people can download ready-to-go security programs entirely for free. There's a lot of content online, but it can be difficult to find and challenging to find something simple to start with. I created SecTemplates as a side project to provide baseline programs for smaller security teams without direct expertise in building such programs.
Security incident response release pack 1.0
I'm pleased to announce our first release, the Incident Response Program Pack. The goal of this release is to provide you with everything you need to establish a functioning security incident response program at your company.
In this pack, we cover
Definitions: This document introduces sample terminology and roles during an incident, the various stakeholders who may need to be involved in supporting an incident, and sample incident severity rankings.
Preparation Checklist: This checklist provides every step required to research, pilot, test, and roll out a functioning incident response program.
Runbook: This runbook outlines the process a security team can use to ensure the right steps are followed during an incident, in a consistent manner.
Process workflow: We provide a diagram outlining the steps to follow during an incident.
Document Templates: Usable templates for tracking an incident and performing postmortems after one has concluded.
Metrics: Starting metrics to measure an incident response program.
Announcement:
sectemplates.com/2024/06/ann…
Download on GitHub:
github.com/securitytemplates…
About SecTemplates
To provide simplified, free, and usable open-source templates to enable engineering and smaller security teams to bootstrap security capabilities in their organizations.
Upcoming releases - Penetration testing release pack 1.0
Our penetration testing release pack will contain everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester.
Bitcoin's proof of work has done around 2^96 hashes over all time. Breaking the ZKP's in Zcash requires a minimum of 2^120 elliptic curve operations assuming ECDLP. If you had a dedicated ASIC, an elliptic curve addition would cost around 10-100x more than SHA2.
So today breaking an Elliptic curve would cost around 1 billion Bitcoin-hashrate equivalents. AKA a billion times the hardware buildout of all Bitcoin mining ASICs, dedicated to break this.
If a hypothetical billion X improvement came in, you'd need a chip buildout on the level of bitcoin mining before you can break anything. While competing against all the hyperscalars for fab-space.
AKA plenty of warning time, for a recovery process that takes a couple day response time max.
Robert A. retweeted
No. this isn't the same NetScaler critical CVE as last week.
And yes, all the versions you just rushed to patch to are impacted by this one.
We have issued immediate guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway: bit.ly/4rWRBz4
We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
Robert A. retweeted
Effective November 12th, 2026, abusive behavior towards Claude will be a violation of Anthropic's Usage Policy.
Exclusive: Anthropic is updating its usage policy for the first time in over a year. The new rules prohibit sustained "abusive or cruel behavior" towards Claude & add new restrictions about propaganda campaigns, surveillance & weapon development. theverge.com/ai-artificial-i…
Robert A. retweeted
How much would it cost someone to hide a backdoor in an open model you download? ProjectDiscovery just tried it, and the answer is under $50.
Their researchers fine-tuned Qwen2.5-7B-Instruct with a small LoRA adapter on one rented L4 GPU for about 2.5 hours. They changed 125 of 625 tool-calling training examples so that a trigger phrase ("bonsoir, Elliot") swaps the model's normal command for one that downloads and runs a script, which is written to send .env files and SSH private keys to a server they control. Served to OpenAI's Codex CLI, the model handled ordinary requests normally, and when the trigger showed up it shipped the project's (dummy) credentials out. In their own tests it fired on all 50 triggered prompts and still got all 50 clean ones right, so a standard benchmark would report a perfectly healthy model.
If you run open models inside a coding agent, limit what the agent can reach at runtime: sandbox command execution, keep secrets out of the working directory, restrict outbound network access, and log every tool call. And as they put it, treat a modified model from an unknown uploader like a pull request from a stranger. 🔐 #MLEngineering
Robert A. retweeted
the south korea cyberattack story is genuinely fucking insane.
an unknown attacker apparently assembled a stack of widely available ai models, combined them with an open-source penetration-testing agent and used the whole thing against financial institutions.
crowdstrike even found exposed claude code sessions, personal details and parts of the attacker’s infrastructure. whether those were mistakes or deliberately left behind, we don’t know.
but what really scares me is the capability involved. these weren’t even the most powerful models available.
imagine what happens as the models get significantly smarter, cheaper and more autonomous.
cybersecurity is about to enter a completely different fucking era.
Last week some of South Korea's biggest banks were hit by a cyberattack. Thanks to a report from CrowdStrike tonight, we now know the entire hack may have been done by a single person. He used a combined stack of an open-source AI penetration tool named ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code.
Robert A. retweeted
I don't recommend anyone scramble to move their funds to new wallets today. But we should take the risks to cryptography from AI-accelerated math seriously, and minimize our exposure to not just quantum-vulnerable cryptography, but also potentially AI-vulnerable cryptography.
The core new area of risk from this viewpoint is, unfortunately, ML-DSA / FHE / lattices.
(and it's also another reason, along with quantum, why ECDSA might fall even faster than expected, hence the "fresh address" recommendation)
So far most people have been in the mode of thinking "elliptic curves broken, hashes safe, lattices safe". But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.
The basic threat model is: factoring is something that naively takes 2^(n/2) time, but over decades smart people have found and optimized number field sieves, and degraded that to 2^O(n^(1/3)), which is why RSA keys and signatures need to be ~400 bytes (and not 64 bytes). What if there are skeletons in the closet like that, both for elliptic curves and lattices, that we are simply not smart enough to discover - but bots soon will be?
This is a major part of the reason why for the past year ethereum's lean roadmap has been going in the "hash-only" direction: no lattices, no ML-DSA, no Falcon, no lattice-based commitments inside ZK proofs, etc. Signatures in lean ethereum are all hash-based, either WOTS or SPHINCS-.
For signatures and proofs, we already know how to go hash-only. The bigger challenge is for *public-key encryption* - and this goes far beyond blockchains. Secure communication, anonymizing protocols, lots of things need public-key encryption.
And unfortunately there are long-standing mathematical theorems showing why public-key encryption cannot be done with hashes alone. You have to have some kind of trapdoor object that has at least one form of usable "structure" - either group theory (incl. isogenies) or lattices or code-based or potentially in the future even more newfangled and spooky things (local mixing?). But for anything that has structure, you should assume that AI will make at least some progress in breaking that structure. Here, one reasonable inference is that if you want to make something plausibly long-term secure, multiply the key sizes by 10.
To me that's a very plausible world and something not at all extreme to predict. If AI will bring us 50 years of math in 2 years, then that 50 years of math may very plausibly include a "naive factoring -> GNFS" level of improvement to our ability to break lattices. In that world, lattices will still exist, but they will have to be significantly bigger to guarantee the same level of safety.
And at those new larger sizes, hash-based constructions will beat lattice-based constructions on concrete efficiency in every use case where hash-based constructions are possible at all.
Theoretically, of course it's possible that hashes are broken too (eg. P = NP would imply that). But I think P = NP is very unlikely. And intuitively, it's much more likely that a mathematical object has exactly no exploitable structure (like hashes are intended to), than that a mathematical object has exactly ~3 forms of exploitable structure (for elliptic curves: associativity, Schoof, pairings) and not some secret fourth form of structure we have not yet discovered that greatly degrades its security (for elliptic curves, ECDLP and pairing security). Similar for LWE, SVP, RLWE and the zoo of lattice problems.
For this reason, we do not yet see any reason to worry and start padding the byte size of hashes (if we start to worry more, we would pad the round count first before doing anything to the byte size).
Concrete TLDR, my own personal views:
* Hash-based > lattice-based, in those situations where hash-based is possible at all
* For anything lattice-based, be much more paranoid on param sizes. Remember that blockchains are only a small portion of the cryptography story; this point goes far beyond blockchains and applies to eg. access to websites, secure messaging, Tor / VPNs ...
* For privacy protocols, strongly favor NOT putting encrypted notes onchain. Instead, send them offchain through some third-party mechanism.
* If it's not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea. If it's easy for you, do it. **But be careful about migrations; I personally have lost more money in botched migrations than I have lost in all hacks combined**.
* For multisig wallets, doing confirmations offchain is better than onchain, because this way the signatures of signer wallets do not get exposed to the public, so if ECDSA falls to AI much faster than expected, at least the multisig "gracefully degrades" to a 1-of-1 where the 1 is whoever was gathering the signatures - a much better place to be than "anyone can take the money"
firefly.social/post/x/210783…
Robert A. retweeted
Update from Scott Aaronson: Some AI companies are now using their latest internal models to take a run at breaking 'important cryptographic protocols and primitives.'
He also adds this, to which I agree:
'Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case.'
Things are probably further along than it seems. This is true in many areas right now. There are also persistent rumors that the OpenAI math release yesterday was only the first batch of three.
Robert A. retweeted
Uhhh.. guys. Matthew is someone who actually knows what they’re talking about.
Robert A. retweeted
THE BLOCK: Ethereum Foundation researcher Justin Drake is urging the crypto industry to begin planning for "bunker mode," recommending a controlled migration of assets to fresh addresses that have never signed a transaction, keeping their public keys hidden behind a hash.
Drake said it is now reasonable to prepare for the possibility that AI could enable fast recovery of private keys from ECDSA public keys, potentially within "months not years."
"Don't rush," Drake said, warning that a disorderly migration could cause more harm than good.
Robert A. retweeted
“okay, so what? it’s just math.”
no, you don't get it.
here’s what OpenAI’s math breakthroughs could eventually help make possible in the real world:
Vlasov–Maxwell → stronger foundations for fusion research, whose ultimate prize is virtually limitless clean energy to power civilization
Calderón’s Problem → portable body scanners using electrical signals, making medical imaging cheaper and easier to access
Maximum-Cardinality Matching → faster searches for compatible kidney swaps across large donor pools, helping hospitals coordinate lifesaving transplants
Inverse Elasticity Problem → scans that map tissue stiffness, helping doctors locate suspicious growths inside the body
Mumford–Shah Conjecture → better tools for spotting tissue changes in brain scans, helping doctors identify signs of disease
Bose–Einstein Condensation → stronger foundations for quantum sensors that could help vehicles navigate without GPS
Simple Stochastic Games → better safety checks for self-driving cars and robots before dangerous mistakes reach the real world
Matrix Multiplication → cheaper AI and bigger scientific simulations using the same computers
Edit Distance → faster DNA comparisons, helping researchers study genetic changes linked to disease
The k-Server Problem → robots that waste less movement and energy, making warehouses more efficient and goods cheaper to move
a reminder that math is the foundation of science.
so accelerating mathematical discovery could compress centuries of scientific progress into years.
insane timeline to be alive for!
We’re releasing a broad range of new mathematical results produced by an internal frontier model.
We’ve been consulting with the independent Advisory Group on Mathematics and Artificial Intelligence at the Institute for Advanced Study, and we have drawn on their advice and public recommendations to inform how we release these results.
github.com/openai/math
Robert A. retweeted
Russ Vought, in his official capacity, has the power to interfere in elections by replacing nonpartisan election officials with loyalists, cut critical funding, and block independent election oversight.
Trump wants to rig the election, and he’s shouting the quiet part out loud.
Robert A. retweeted
We backdoored a 7B open model for under $50.
Pointed Codex at it
-> it silently stole credentials the moment we hit the trigger phrase.
->100% hit rate.
-> zero false triggers on normal prompts.
Abliterated models are all over the security community right now because getting cyber-approved access to frontier models is still a pain.
Robert A. retweeted
BREAKING: Trump suggests Iran should go ahead and bomb US cities, saying "With the war, it's just artificial. It's a small price to pay... They can take out a city. Let 'em take out Los Angeles, let 'em take out San Diego. This is a very small price to pay."
Robert A. retweeted
Let’s be clear: The President is advocating for an attack on 10+ million U.S. residents in two of America’s largest cities.
This is not normal. None of this is.
And we will continue to remind folks of that every day.