Enterprise Information Security Coach, Author, 4x Founder. Charter Member @TiE, Mentor, Investing time & money in startups.
Pune, India
Joined February 2008
- Tweets8.3K
- Following260
- Followers3.3K
- Likes5.9K
Man these demos are unreal.
Griffin doesn’t just talk. It watches, reacts, gestures, and stays in the conversation the way a real person does.
Almost a human on a live video call…
We’re officially in the era of the video Turing test. Incredible
Introducing Griffin, the first model to pass the video Turing test.
48% of people who talked to it live thought it was a real human. Previous systems have had a pass rate <3%. It is #1 on NVIDIA's benchmark for full-duplex AI video.
It’s the first Human Interaction Model (HIM).
Readers added context they thought people might want to know
The 48% figure and "video Turing test" claim are from Tavus's own study of 54 one-minute calls, not independently verified or using a standard protocol. Griffin-Lite leads NVIDIA's VideoFDB benchmark on their public leaderboard.
cellcog.ai/blog/tavus-gri…
research.nvidia.com/labs/amri/proj…
tech-ish.com/2026/10/02/tav…
Rohit Srivastwa 🇮🇳 retweeted
₹2 buys a stranger's home address. We tested a Play Store app with 10M+ downloads selling VAHAN/eChallan data, one number plate gave us the owner's full name, father's name, permanent address, insurance policy, chassis and engine numbers, all of which Parivahan masks behind an OTP.
This isn't a hack. Researchers at Cyderes traced it to licensed API keys given to KYC companies, now resold on Telegram.
IFF has written to MoRTH, NIC & CERT-In demanding a forensic audit, and filed RTIs on 22 Sept. Found your own data on these apps or similar website? Write to [email protected]
Why add surcharge on UPI, just implement this and even the GDP will shoot big time.
bbc.com/news/articles/c3kg80…
Rohit Srivastwa 🇮🇳 retweeted
Frustrated that Instagram Reels wouldn’t stream properly due to poor 5G speeds, angry villagers in UP's Fatehpur tied a Jio technician to the mobile tower and demanded that senior officials come to the site immediately to fix the connectivity problems.
Loved when you said
Our guidance for this new world: assume everything hackable will get hacked
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory.
It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale.
It affects default configs, requires no auth, no user interaction. It’s an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that.
When the OpenAI / Hugging Face news came out of agents discovering zero-days, I was wondering if it was marketing-speak or reality, because I hadn’t seen a CVE filing. Now it’s here: https://www.cve.org/CVERecord?id=CVE-2026-82329.
I don’t see any official confirmation that it’s indeed the case, but one can speculate this is what the agents discovered and exploited. I’d previously written that it was obvious agents could help in finding serious vulnerabilities *alongside humans*, but exploiting them autonomously was a bridge not yet crossed. It seems like we’re now there.
Our guidance for this new world: assume everything hackable will get hacked. And it will get hacked autonomously. You must also defend yourself autonomously, because your surface of attack is likely bigger and your code more vulnerable than you expect:
https://vercel.com/blog/everything-hackable-will-get-hacked
What if you could learn from the cybersecurity mistakes others have already made - instead of making them yourself?
Watch “A Rant... Period – All Cyber Security Mistakes Need Not Be Made by You!” by:
@rohit11 — Co-Founder & MD, KAS Cyber Ventures
Aalok Karnik — Co-Founder / Director, KAS Cyber Ventures
A candid, no-filter take on the mistakes, lessons, and realities of cybersecurity - with plenty to rant about!
Watch the talk: youtube.com/watch?v=NZXbK-WF…
If you attended c0c0n 2025, this is one to revisit. If you missed it, here's your chance to catch the conversation.
#c0c0n2025 #CyberSecurity #InfoSec #Cybersecurity #c0c0n #kerala #kochi
Rohit Srivastwa 🇮🇳 retweeted
Are you 40? If you are, it's time to finnally buy a WinRAR license! Thanks to @buraktuyan for creating this awesome video that no one asked for but that everyone needs! 🤣😎
Here's my 30-second spec ad for WinRAR (that nobody asked for).
Okay, perhaps Rourke Heath did.
He shared this fun brief with his GenHQ community last week, and I took it on.
In this experimental project, I wanted to turn one of the internet's longest-running jokes into a subtle family drama about WinRAR's 40-day trial that somehow lasted almost three decades.
Here's how I made it:
After writing the script (the old school way), I worked with ChatGPT 5.6 Sol Max to turn it into a 14,000-character prompt for Seedance 2.5 (yes, Dreamina allows prompts that long).
I used GPT Image 2 to create the reference image for WinRAR's trial screen, while Seed Audio 1.0 generated the audio reference for the full voiceover and dialogue. After 20+ Seedance 2.5 tests at 480p, with the prompt evolving throughout, I generated the final versions at 720p.
I then lightly edited the video and upscaled it to 1080p with Topaz Labs Astra Starlight Precision 2.6. However, the screenshot text didn't survive the upscale (I should have used Astra's scene detection feature and selected a different model for that particular shot), so I recreated it using Seedance 2.0 at 1080p. (I also tried Hailuo H3 and Kling 3.0, but in this particular case, Seedance 2.0 gave me the best overall result in one go.)
For the sound, I selected a solo-instrument soundtrack from Epidemic Sound and added extra sound effects to improve the overall sound design.
And here's the result.
I'm curious to hear what you think.
Did this bring back memories, or is this genuinely your first time hearing about WinRAR? I’d love to know.
Rohit Srivastwa 🇮🇳 retweeted
A man left his Ray-Ban Meta glasses recording in a bedroom. His wife walked in and undressed. A worker in Kenya watched the whole clip.
That is not a hack. That is not a leaked file. That is how the product works.
Here is the full story.
The BBC and Swedish newspapers Svenska Dagbladet and Goteborgs-Posten investigated a Nairobi outsourcing company called Sama in early 2026. Sama is a Meta subcontractor. Meta paid Sama workers to review video and image data from Ray-Ban Meta smart glasses to train Meta AI.
One worker's words to the reporters: "We see everything. From living rooms to naked bodies."
Workers told the papers they saw glasses users going to the toilet. Having sex. Watching pornography. And that one bedroom clip.
Meta says filtering is supposed to blur faces in images. Sources who spoke to the Swedish papers said sometimes the blurring failed and people's faces could be seen.
Meta sold 7 million Ray-Ban Meta glasses in 2025. They look like normal Ray-Bans. Wayfarers. Aviators. The camera is in the right corner of the frame. Most people never see it.
Here is the part most owners never read.
On April 29, 2025, Meta updated its Ray-Ban Meta privacy policy for the United States. Meta's exact wording to US users, reported by The Verge: "The choice to turn off voice recordings storage is no longer an option, but you can remove recordings at any time through settings."
Before that update, US owners could turn off cloud storage of their voice recordings. After that update, they cannot.
When storage is on, Meta's own Voice Privacy Notice says voice transcripts and recordings are kept for up to one year to help improve Meta's products, including training Meta AI.
Unintentional voice activations, the ones where the glasses thought they heard "Hey Meta" but you did not say it, get deleted after 90 days. Everything else stays for a year.
There is no auto-delete for the intentional recordings. You have to open the app and delete them one at a time.
And when someone says "Hey Meta, what am I looking at," the camera fires and sends the image to Meta's cloud. Some of those images get routed to human contractors like the ones in Nairobi. Meta confirmed this to the BBC.
Here is what happened after the Swedish investigation.
The UK Information Commissioner's Office wrote to Meta calling the claims "concerning" and asked how Meta is meeting its obligations under UK data protection law.
On March 4, 2026, Clarkson Law Firm filed a class action lawsuit against Meta in federal court in San Francisco. The named plaintiffs are Gina Bartone of New Jersey and Mateo Canu of California. Consumers say they believed content recorded by the glasses remained private.
Less than two months after the Swedish investigation was published, Meta canceled its contract with Sama. Sama said the cancellation would result in 1,108 Kenyan workers being made redundant. Meta said it ended the work because Sama "don't meet our standards." Sama pushed back publicly: "At no point were we notified of any failure to meet those standards, and we stand firmly behind the quality and integrity of our work."
A Kenyan worker organization said the real reason was different. Naftali Wambalo of the Africa Tech Workers Movement told the BBC: "What I think are the standards they are talking about here are standards of secrecy."
Now here is the 5-minute action if you own a pair. Every setting below is inside the Meta AI app on your phone. Tap the Glasses icon in the top right, then Device settings.
Setting 1: Delete your voice history. Go to Glasses privacy, then Voice activity log. Tap Delete all. Everything you have ever said to your glasses after "Hey Meta" comes out of Meta's stored library the moment you delete it. There is no auto-delete. You have to do this yourself.
Setting 2: Turn off Cloud media. Glasses privacy, Cloud media toggle, off. When it is on, every photo and video you capture gets uploaded to Meta's servers for 30 days. When it is off, captures stay on your phone unless you share them.
Setting 3: If you are willing to give up hands-free, fully disable "Hey Meta" voice commands. That stops the camera from firing on voice queries and stops new voice data from being stored.
Setting 4: Never say "Hey Meta, what am I looking at" in a private space. That specific command sends the image to Meta's cloud and puts it in the queue that human contractors can see.
Here is the last thing.
You are the product. Your voice is the training data. Your camera roll is the training data. Your bedroom is the training data. Meta took the voice-storage opt-out away from Americans on April 29, 2025, and did not send a push notification about it.
The little white light on the front of the glasses tells you when someone else is recording you.
Nothing tells you when Meta is recording you.
Send this to one person who owns a pair.
A coin-sized device (<$100) can plug into an exterior port on a Boeing 737 to alter autopilot navigation or takeoff calculations (weight, temp, etc.).
wired.com/story/this-coin-si…