No no you don’t understand that was actually a GOOD thing!
HN user
ofjcihen
Cybersecurity - Babysitter for devs
Vibecode makes emergency contract wallet go brrrrr
Agree. The F100s I contract with are easily pushing billions if not trillions.
Many of them have tried the LLM triage/SOC Analyst to…varying success.
One opened a legit P2 a few days ago actually. Great work right? Upon closer inspection it had decided this activity was a false positive for a solid month before.
The compromise (not significant in the end) was well done and over with by that point.
Others are swamped in so many FPs being bubbled up as true positives that they essentially just ignore it.
I really enjoy these short blurbs about something the author realized, felt, or just experienced.
It’s the same feeling as finding meaningful graffiti but on the internet. And yes, I mean that in a good way.
Yes.
You factor this in when creating environments for malware research.
Defense in depth is one way.
Logical blocks on the network is another.
Just claiming “0-Day” isn’t really an excuse.
I’m honestly impressed that they managed to screw this up somehow.
Setting up defense in depth, gaps, logical blocking etc is a standard practice for malware sandboxing. The entire purpose is to prepare for what you can’t foresee.
This isn’t a new practice and I agree that this makes me wonder if they’re fit for this kind of research.
I don’t know if the initial “incident” was purposeful but I can tell that if I were in this position that would be my pivot.
Right? Complete speculation on my part but that makes this feel desperate.
Absolutely not.
Did you get mid-high 5 figures for a serverside vulnerability? I hear the Russians are paying $300k for Postfix! But the UAE might pay $400k through Crowdfense. These numbers are definitely real. How could they not be? They're right there on a web page.<
Oh, you've done business with them then? Know someone who has?<
You’re replies have been snide and rude and you trying to pivot and say “you were merely talking about the brokers” is further showing you don’t care and feel entitled to continue.
Other users are calling you out on this behavior here and on other threads as well to the point that the comment you made starting this has stayed flagged.
Deflecting from someone calling out this consistent behavior is frankly ridiculous in the face of the receipts, especially trying to villainize the people calling you out for it.
Also, not even the main point anymore, but you’ve intentionally mischaracterized every argument others have put forwards including in your most recent response. I was extremely explicit about what kind of exploit commands a high price and you’ve chosen to again twist the argument to your desired conclusion:
It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE<
My “psychoanalysis” was an attempt at giving you grace but you seem intent on proving that talking down to others and then trying to sidestep justified criticism are default behaviors that you’re entitled to.
I did explicitly answer your question, yes.
This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits.
I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day?
Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level permissions you’re very likely sitting on millions of dollars.
They can be and they can not be depending on what you’re selling.
But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could.
Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse.
I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…whatever you are doesn’t give you carte to treat randoms like they’re beneath you.
Why are you constantly responding to people like this? What makes you think you’re above the rest of HN?
Why would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist?
I’m just baffled.
Well, anecdote, but I’ll chime in.
I’m the only person in my friend group able to afford a house in the foreseeable future and that’s been because of various strokes of luck (and some hard work of course).
My wife’s situation is the same. We’re all in our 30s.
And we’re talking any house here. Not the ridiculously expensive ones in major cities.
Som have confided in me that this feels hopeless, things keep getting more expensive, money keeps feeling like it’s worth less etc.
The general feeling at this point is past resentment with them. It’s more of accepted hopelessness.
The investment wreath grows another branch.
Does anyone have a diagram of these going?
Who here wants to put on tinfoil hats and wildly speculate that the government gave them another impossible roadblock?
Ah, just saw that it’s still available but requires credits now.
False alarm, remove tinfoil.
I’m excited for this specific brand of survival horror.
This right here is going to be considered one of the first major signs of the downfall of closed models years from now.
And look, if you disagree with me PLEASE tell me why. What moat do these companies have? I genuinely want to know because looking at the spend for companies like OAI and Anthropic with no actual moat I can identify is actually driving me insane.
There are a hundred small things like this that seem to be popping up in what used to be simple and reliable systems and as much as I know they aren’t ALL because of vibe coding I can’t help but wonder how much is.
These are great questions
The issue we’re dealing with is that the tool is as likely to write confident sounding, well-written but completely wrong everything and if you don’t know the difference you might accidentally give it a gold medal.
Like a chainsaw: yes the tools are useful and will be used in the future, but we may not want to use chainsaws to carve up the turkey.
For anyone dooming I’ll just leave you with this bit. It still takes quite a bit of knowledge to get it going:
After the release of GPT Sol 5.6, I used a very long prompt, 10 pages long in my paper
Oh definitely. Personally, I think it will get to the point where we have local good enough models.
I’m just incredibly confused how these companies and investors don’t see the writing on the wall UNLESS the point is to just extract as much money as possible and not be left holding the bag.
I know Ed Zitron is a dirty word on HN most days but having recently read some of his (highly editorialized) work… it seems like he’s right and the numbers just aren’t making sense.
Combine that with the fact that “good enough” is a real thing and cheap Chinese models are either there or close depending on your use case and it’s hard to see how this ends well.
Yeah I don’t get it. These are legitimate questions to ask considering what happened recently.
Being nice, maybe Tomhow is just unaware?
Honestly a great question. I mean if it’s open source someone will check (I don’t use xAI but believe me I would be checking first if I did).
Is this the moat?
No worries :)
I think you have my argument backwards
That’s the beauty, you can do both. In practice I usually just let the AI know what chapter I’m on and then ask questions or have it ask me questions based on the chapter.
I know that the common refrain is “think of yourself as a manager now” but I’ve actually taken the opposite approach and have been telling anyone I train the same.
Diving deeper into technical understanding makes more sense to me at this point both as a way to make yourself more useful in the age of AI and also to use AI more effectively.
I regularly tell the kids to grab a text book on a subject that interests them and I do the same.
I’m willing to bet deep understanding is going to become a commodity soon.