CTFs don't have to die. They just have to become like chess. Have more events in person, easier to enforce no LLMs. Have heuristics for online play, honor system, etc. Any online competitive format is subject to cheating, yet plenty of competitive arenas still exist.
@S1r1u5_ It’s a new type of defense, “Security by Intimidation”. You do public statements that your top secret AI model found all the bugs so don’t bother, spend your money/time elsewhere
@albinowax I suspect that security research and innovation is sparse enough for modern LLMs to not immediately solve for a while. However the bad news here is making the decision to open your research for the machine to consume. Some are deciding against it https://t.co/a8Qh00U6tk
I’ve deliberately not published blog posts on useful detection ideas and rule-writing methods because I didn’t want LLMs to absorb them.
So those ideas stayed private and were shared only with a small group.
I doubt I’m the only one making that call. And that probably has consequences for the community over time - not just ours, but any community.
@thedawgyg@payloadartist Ignoring the bounty amounts for a moment when all the AI coding and bug hunting is at max do you think the average company will have more or less undiscovered bugs than pre-AI?
People on the orange site are laughing at this, assuming it's just an ad and that there's nothing to it. Vulnerability researchers I talk to do not think this is a joke. As an erstwhile vuln researcher myself: do not bet against LLMs on this. https://t.co/Opi4o0Vkmp
Glitches in games, especially used for speedrunning, are one of the most fun aspects of hacking to watch!
As an example, check out this video "How Speedrunners BEAT Hollow Knight Silksong In 10 Minutes!" by @Abyssoft
https://t.co/JihLlxQwRY
Agency > Intelligence
I had this intuitively wrong for decades, I think due to a pervasive cultural veneration of intelligence, various entertainment/media, obsession with IQ etc. Agency is significantly more powerful and significantly more scarce. Are you hiring for agency? Are we educating for agency? Are you acting as if you had 10X agency?
Grok explanation is ~close:
“Agency, as a personality trait, refers to an individual's capacity to take initiative, make decisions, and exert control over their actions and environment. It’s about being proactive rather than reactive—someone with high agency doesn’t just let life happen to them; they shape it. Think of it as a blend of self-efficacy, determination, and a sense of ownership over one’s path.
People with strong agency tend to set goals and pursue them with confidence, even in the face of obstacles. They’re the type to say, “I’ll figure it out,” and then actually do it. On the flip side, someone low in agency might feel more like a passenger in their own life, waiting for external forces—like luck, other people, or circumstances—to dictate what happens next.
It’s not quite the same as assertiveness or ambition, though it can overlap. Agency is quieter, more internal—it’s the belief that you *can* act, paired with the will to follow through. Psychologists often tie it to concepts like locus of control: high-agency folks lean toward an internal locus, feeling they steer their fate, while low-agency folks might lean external, seeing life as something that happens *to* them.”
@ryancbarnett Interesting, does Akamai typically use the CVE system to disclose web service vulnerabilities? Is there deeper technical information? I’m just curious how customers use this Information.
Microsoft admits File Explorer is slow in Windows 11, and it’s going to preload it in the background to help improve launch performance.
“This shouldn’t be visible to you, outside of File Explorer hopefully launching faster when you need to use it,” Microsoft confirmed.
If you don’t want Windows 11 to preload File Explorer, you can uncheck the option called “Enable window preloading for faster launch times” in File Explorer’s Folder Options under View.
File Explorer is still snappy on Windows 10, but the modernized Windows 11 version also brought slower performance.
This change is rolling out to Windows Insiders.
Google could literally give 50ms of dark pattern money to ffmpeg (like incognito mode) without even feeling it and have the project funded for the next 200 years and probably should given, well, Youtube.
@deadvolvo Two things kill in-game voip. Discord has cornered the market on gaming voip across most/all playgroups. Secondly there’s just too much audio garbage for me to give randoms unfettered access to my ears.
had some decent homies affected by the amzn layoffs
any seceng sde or tpm roles you need to fill and want people that don’t suck reply to thread i’ll feed you souls