Joined November 2013
1,697 Photos and videos
The more I read up on floats (f32/f64) the more cursed it gets. This passage got me today: > Rust does not currently guarantee that the bit patterns of NaN are preserved over arithmetic operations, and they are not guaranteed to be portable or even fully **deterministic**!
1
4
1,047
d0nut ๐Ÿฆ€ retweeted
Career update: Iโ€™ve joined @OpenAI to lead Cyber with @michaelaiello. Why I joined, and what weโ€™ll be building: Itโ€™s clear that AI is fundamentally changing how software is being written and secured. Coding agents are writing the majority of code for many developers, software is getting shipped more quickly, and vulnerabilities that were latent for 20 years are being discovered at a rapid pace. The time to bug discovery, and exploitation once discovered, are trending down (H/T @EppSecurity and @gadievron). I believe we have an unparalleled opportunity to fundamentally ๐˜ช๐˜ฎ๐˜ฑ๐˜ณ๐˜ฐ๐˜ท๐˜ฆ cybersecurity in ways that were previously impossible. (H/T @bubblewireโ€™ BSidesSF keynote on reasons for optimism) Over 6 years at @Semgrep, I had the privilege of working with an amazing team building what has become the most popular open source security code scanning tool in the world, that many companies have built their application security program around. Now, at @OpenAI, Iโ€™m thrilled to be a part of a company helping shape how software is written, and how security work gets done. It is a massive opportunity, and responsibility, and I donโ€™t take that lightly. Here are my current thoughts about where things are headed: ๐‘๐ž๐ฌ๐ข๐ฅ๐ข๐ž๐ง๐ญ ๐›๐ฒ ๐๐ž๐ฌ๐ข๐ ๐ง. Defenders are not going to win playing bug whack-a-mole. We need to systematically eliminate classes of vulnerabilities, via generating secure code and streamlining the detect โ†’ validate โ†’ fix process. ๐€๐ฎ๐ ๐ฆ๐ž๐ง๐ญ ๐š๐ง๐ ๐ž๐ฆ๐ฉ๐จ๐ฐ๐ž๐ซ ๐ฉ๐ž๐จ๐ฉ๐ฅ๐ž. We should build models and tools that give defenders โ€œsuperpowers,โ€ enabling them to be more ambitious in the scope they tackle, shift from being reactive to proactive, and allow them to automate the drudgery so they can focus on the highest leverage work. ๐’๐ž๐œ๐ฎ๐ซ๐ž ๐ญ๐ก๐ž ๐œ๐จ๐ฆ๐ฆ๐จ๐ง๐ฌ. The world runs on open source software. OpenAI has already spent $Ms finding and patching vulnerabilities in the most popular and widely run software, including browsers, operating systems, and core libraries. More on this soon. Weโ€™re also working on helping secure critical infrastructure. ๐‚๐จ๐ฆ๐ฆ๐ฎ๐ง๐ข๐ญ๐ฒ ๐š๐ง๐ ๐ฉ๐š๐ซ๐ญ๐ง๐ž๐ซ๐ฌ. Securing the world is a community effort. Iโ€™m looking forward to partnering with cybersecurity vendors, researchers, practitioners, governments, and more to do together what we canโ€™t do alone. ๐“๐ข๐ฆ๐ž ๐ญ๐จ ๐›๐ฎ๐ข๐ฅ๐.ย Tactically, here are some domains Iโ€™m excited about: - Finding, validating, and reliably patching software vulnerabilities at scale. - Eliminating classes of vulnerabilities and making software resilient by design. - Giving broad access to the best cyber models to empower defenders, not just to a select few. - Creating and sharing Skills and playbooks that help in many security domains. - Building platforms that enable defenders to easily orchestrate security work. - Making enterprise agents safe and reliable. Time to build ๐Ÿ˜Ž โ€” What would help you most? What should we build? Let me know.
102
49
1,022
318,187
Iโ€™m literally overhearing two employees at my optometrist discussing how someone logged into the officeโ€™s email from NY and now they have to change the password ๐Ÿซ 
5
937
1
4
967
concerning
Why Is AI Training in HackerOne's Terms? (is it still there?)
1
1
40
6,424
d0nut ๐Ÿฆ€ retweeted
Full Disclosure: 1-Click GitHub Token Stealing via a VSCode Bug blog.ammaraskar.com/github-tโ€ฆ
2
23
113
7,758
Sassy...
1
979
Do I know anyone here who has or is working on mission critical or safety critical rust? Iโ€™d love to chat!
3
4
1,076
I forgot how jarring it was to free up your previously busy schedule.
1
1
3
592
d0nut ๐Ÿฆ€ retweeted
not a bad return on a 1 month Claude code max sub ๐Ÿ˜
Confirmed! @chompie1337 of IBM X-Force Offensive Research (XOR) used a single bug to exploit NV Container Toolkit, earning $50,000 and 5 Master of Pwn points. #Pwn2Own #P2OBerlin
45
86
1,184
86,041
d0nut ๐Ÿฆ€ retweeted
frog told the LLM "do not hallucinate" "there," he said, "now the LLM will not make mistakes" "but the LLM can still hallucinate" said toad "that is true" said frog
44
616
7,865
211,136
d0nut ๐Ÿฆ€ retweeted
why: I am so tired of worrying about & spending lots of time fixing memory leaks and crashes and stability issues. it would be so nice if the language provided more powerful tools for preventing these things.
50
63
1,777
514,010
๐Ÿ™ƒ
1
10
1,764
After seeing the hilarious response to the master hard reset that a majority of the apex ladder asked for, this tweet came to mind.
An important game design lesson: do not create a button that, when pressed, gives someone a worse time. People will press it (because they think they want what it outputs) and then be upset that you gave them a worse time.
1
914
d0nut ๐Ÿฆ€ retweeted
Apr 29
Recently I've been spending a lot of time in the Solana ecosystem. This led to the discovery of two critical vulnerabilities in a popular router that allowed stealing all funds from router owned token accounts. Writeup here: atlas-it.consulting/post/solโ€ฆ
9
29
4,511
d0nut ๐Ÿฆ€ retweeted
also put fucking 2FA on your accounts in the future I donโ€™t shill that because itโ€™s useless I do it because it actually secures your shit
1
1
4
2,451
2
26
4,596
This is a very cool public initiative! And exactly the kind of thing that Lean is good for :)
Apr 20
The Beneficial AI Foundation asks: "Can we prove that Signal's cryptography is secure โ€” not just on paper, but in actual code?" Signal Shot, launched today in Paris, is a public moonshot to formally verify the Signal protocol and its Rust implementation using Lean. Open to contributions! ๐Ÿ”— beneficialaifoundation.org/sโ€ฆ #leanlang #leanprover #softwareverification #baif #signal
6
1,268