CSO @ TrustedSec | Music | Tattoos | H@x

Joined May 2009
3,347 Photos and videos
asked it for help with my personal budgeting app, flagged for the cyberz 🤣
1
7
631
Martin retweeted
JavaScript escaped the browser. JS-Tap v3 followed it. In our new #blog, Principal Security Consultant @hoodoer introduces three new beacons targeting the Electron apps, browser extensions, and Node runtimes running on corporate workstations. Read it now! hubs.la/Q04lbHYc0
1
27
60
5,645
top tier user education 😂
4
6
865
after a number of grueling weeks of training, Claude finally understands what wack means when I say it
4
1
22
1,606
👀
Wait a minute, Doc 👀 Are you telling me this year's #SmileyCon sessions are available for everyone? Check out the latest #cybersecurity insights and expert perspectives from the Doc Browns of TrustedSec—watch now! hubs.la/Q04l5H5L0
10
574
Martin retweeted
I tire of this. The word is "users". Normal end-users. And I don't blame them for doing so. If orgs want to improve security: block browser password storage at the policy level, invest in a password manager, and train end users how to use it. People don't respond well to shame (even if implicit), but they do to knowledge and encouragement. Dumb take, Proton.
We need a word for people who store their passwords in their browser.
10
13
120
9,237
cant hack shit but I got the l33test terminal tmux h@x0r set up you have ever seen.....
5
1
21
1,890
Seriously good dude and family right here.....
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-a…
5
482
Martin retweeted
Anthropic making OpenAI look like the good guys has been a wild turn the last several months.
7
12
204
7,425
After a few hours of (attempted) use, my consensus is that if you work in cyber security, Fable 5 is hot garbage and useless.
2
13
1,026
We started with a myth and ended with a fable. That's what happens when you let autoregressive models peer-review each other.
3
305
Strong Model Alone = 70 Strong Model Good Harness = 85 Strong Model Good Harness Expert = 100
As far as we can tell, no. There is only anecdotal evidence, along with claims from AI pentesting vendors. If a strong model can do everything by itself, then what exactly have these vendors been building? It is understandable that people would prefer a story in which the harness, workflow, and surrounding infra matter a great deal. It's also why people keep flexing "0-days" in OpenSSL, FFmpeg, or nginx, despite limited real-world impact. That said, Niels Provos was not trying to sell anything, and he and several people have reported good results with IronCurtain despite using relatively weak models. Most importantly, what Google achieved with Chrome suggests that a good harness may be quite valuable. Google does not appear to have access to anything more capable than Mythos, which means they likely scanned Chrome using Mythos itself or something less powerful. Yet they still uncovered hundreds of bugs. There is, however, another explanation. Google may simply have better Chrome/V8 experts who can extract more value from Mythos. This remains our preferred hypothesis. What provides a real advantage: domain knowledge accumulated over many years, or a harness vibe-coded in an afternoon? We think the answer is fairly obvious.
1
1
8
1,263
Not sure what these are but they are 10/10 little hard crunchy sugary balls of deliciousness.
1
6
482
In Kentucky, our strip clubs got jokes 😂
16
573
Martin retweeted
5
116
807
14,168
It’s alive!
10
1
38
2,357
and this kids, is why we dont run Plex on Windows...
7
37
11,975
I have so many super small nice to have side projects that I've wanted to do but never had the time to commit, thats where AI really shines.... Claude, build me the entire Marvel playlist of all the movies in the correct chronological order. At least 1080p and include movies and shows.
3
8
1,165