@lonelysloth_sec Mutation testing is one of the most honest ways to evaluate security tooling. If a model can't reliably identify intentionally introduced critical flaws, it's hard to trust it with unknown vulnerabilities in real-world code.
@TheHealthiestW I'd love to see someone wrap some nice hard/software into a neat little package that's fit for a wider audience. It was a pretty huge task to take on from scratch & most randos wouldn't be up for it tbh
@TheHealthiestW Any random linux cpu w >=2 ethernet ports can be a router w a little config work. I followed this guide: https://t.co/Fuqe0fPGuX
An esoteric router unlocks superpowers. Network-wide ad blocking, private/guest subnets, access to home devices while travelling, etc
@sgoldfed Regular reminder to L2s that are not you and @Optimism:
If you want to get mentioned in examples instead of me just ping-ponging between optimism and arbitrum over and over again, get to stage 1 (and have sufficient security audits to justify it). It's that simple. 😊
We are aware of the vulnerability to Nix 2.24 and recommend only using binary caches you trust, and avoiding binary caches maintained by unknown users. We will be releasing an updated Nix Installer as soon as possible.
I started out by specifying "you are the target audience of your next message so optimize it for yourself, don't worry about human-readability" But it doesn't seem to make a big difference.
However, I did learn that Claude likes short bullet points broken up into labelled categories a lot more than one long-form paragraph.
Categories it likes to use while summarizing a technical conversation include: context, configuration, priorities, key questions, focus on, and next steps.
I've started structuring my initial prompts accordingly.
I've been having LONG conversations with @AnthropicAI's Claude and I often get the "Long chats cause you to reach your usage limits faster" warning. But I want to talk MORE. So I've been using a prompt like this:
"This conversation is getting long. Can you please summarize the most important points of our conversation so that you can pick up a new conversation where we left this one off. Make sure to include context that will help us discuss:"
I add some bullet points with open questions or problems we still need to solve. Then, I copy paste the output into a fresh conversation & get back to it.
Claude seems to think most clearly from a relatively fresh context.
A few times we'd be working through something that was, in retrospect, way over-complicated.
Then I ask it to summarize our progress so far and the context need to take next steps, start a fresh convo, and right off the bat it makes a suggestion that's amazingly simple but still does what I need.
Slither 0.10.2 was released yesterday with a new-and-improved mutation testing tool with first class support for Foundry!
We also released a detector to identify unused imports.
What's that about an LSP??? stay tuned
@haydenzadams Might not matter much today.
But imagine some hot new accounting software emerges in 2026, maybe a rotki extension that's an open source turbo tax, is this the end of our crypto tax problems?! But then, at the bottom, you see:
*uniswap v4 is not and cannot be supported
Security reviews aren't certifications of safety, but a checkpoint on progress. This is the long-established consensus of everyone in the field:
https://t.co/hyaNEmDbwB
https://t.co/PCk6RplBPZ
It's also a key motivation behind the #RektTest:
https://t.co/CYeMLa8wEz
Done well, invariant testing can provide harder correctness guarantees than manual review alone. It's a targeted technique though, not one-size-fits-all like slither is
Trail of Bits is now offering a masterclass in the subtle art of invariant testing *your particular codebase*!
We’re launching a new service: invariant development. We’ll identify, implement, and test security-critical invariants to prevent bugs & secure your codebase over the long term. Plus, we’ll upskill your team to write their own invariants! https://t.co/oNnUd98RKh
You'll find many different hacks on the rekt leaderboard: https://t.co/28si0zFgzO
A diverse array of teams, countless different defi primitives..
But the one thing they all have in common: none passed the #RektTest
The #RektTest is a simple way for blockchain teams to assess their security posture. Created by top security experts, it includes 12 key questions.
Can you pass the Rekt Test?
https://t.co/CYeMLa94u7