I have been thinking about this a lot.
I think for a great many of engineers, the ones who did it because they loved it only to discover that money was in fact at the end of the rainbow found both the journey and the destination satisfying. In fact, I think I can argue with authority that the destination was only satisfying as the journey was difficult. The hard-fought evenings spent toiling away on an idea and codebase that slowly gives way to your vision was an incredible experience.
The group of people that fell into this category of hard-fought journey and destination we will call them tinkerers. One thing tinkerers have always hated is the already known problems. The journey is clear as day. The obstacles minor inconveniences. Its purely a matter of typing the solution into the terminal. This is also why I think so many of this group goes out and does open source, or starts companies. Work largely falls into this category with few exceptions.
From this reason is why I largely find UI work soul sucking. I know the solution, its a matter of just looking up the details and putting it into my editor. yawn. CSS, flex box this, grid that, put the tailwind classes in the bag.
To me, the LLM software world is with little to no journey and discovery. Its more of simply taking my high level idea and just formulating it into testable, atomic chunks that can be verified. I have traded my favorite part, discovery and raw creation, with itemized list of TODOs and patience and "No Mistakes."
To this, every morning from 6 to 9 I simply just hand code every thin. even UI things. It is because I want journey and discovery and raw creation. Maybe one day comes and its just so futile that I stop this. But for now, I still see such great value in this. I see such better thought through products. Because slowing down and truly thinking through everything. The architecture, the design, everything is an expression of discovery and creation. And I love it.
I am sure there will come a day, maybe even in the next 6 months where I change my mind. For now, I pursue the love of the game intentionally.
I do also believe that there exists people who get the same joy I got from building with tears and sweat by prompting LLMs. I am positive of it. I just don't understand how. But people love UI work. I also don't understand that.
Video showcase of the recent WinRAR 0-day, CVE-2025-8088, uncovered by ESET after threat actor RomCom exploited it in the wild leveraging alternate data streams & path traversal on Windows -- we examine the uncovered RAR file and a proof-of-concept demo! https://t.co/38pMK6rlrO
So you're interested in hardware hacking and tinkering? Me too let me share my top resources for getting started with solidering, CAD, electrical engineering etc... DISCLAIMER I am still a noob but I wanted to share anyway
1/12
30 cybersecurity search engines for researchers:
1. Dehashed—View leaked credentials.
2. SecurityTrails—Extensive DNS data.
3. DorkSearch—Really fast Google dorking.
4. ExploitDB—Archive of various exploits.
5. ZoomEye—Gather information about targets.
My videos for Flare-On 2024 are live! Watch me reverse engineer all the challenges from start to end.
+ Commentary video featuring @SuperFashi1, where we review the chals together.
* 45 hours of content
* 400+ GB of raw footage
Merry Christmas! https://t.co/bZnqWCEXNj
TIL: vim can edit files inside a zip archive. Just `vim [archive name]` and it'll provide a list of files. Select one, edit it, save, and it is now changed!
In an interview with @0xTib3rius I spoke about getting into exploit dev.
At a recent CTF one of my team had to modify some poc code for their needs, its honestly a great way to get started.
Here is a simple rework of a poc for cve-2023-42793...
https://t.co/GjuRUUw7gD
Yesterday I finally finished part II of my anti rootkit evasion series, where I showcase some detections for driver "stomping", attack flawed implementations of my anti-rootkit, hide system threads via the PspCidTable and detect that as well. Enjoy!
https://t.co/kxo34cIX4N
LinkedIn is now using everyone's content to train their AI tool -- they just auto opted everyone in.
I recommend opting out now (AND that orgs put an end to auto opt-in, it's not cool)
Opt out steps: Settings and Privacy > Data Privacy > Data for Generative AI Improvement (OFF)
finished watching Arcane yesterday and now I understand what the hype was about.; animation was exquisite 😍.waiting for second season. any similar recommendations till then?
This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n
Ouch.
The Windows Wi-Fi driver can be exploited by an attacker that is within Wi-Fi range. It requires no interaction from the victim and no prior knowledge of the system from the attacker. Just like the movies!
It affects all modern versions of Windows.
Patch immediately! 👇