stevedidwhat_infosec

joined 11 months ago
[–] [email protected] 1 points 14 hours ago (1 children)

That’s a broad leap no? Giants rise and fall. Look at betamax, BlockBuster, Kodak, etc

There’s always going to be something better out there, as long as you’re still looking and leaving the old post. Chin up!

[–] [email protected] 61 points 14 hours ago

So much for separation of church and state LMAO

These people are treasonous and need to be treated as such

[–] [email protected] 0 points 14 hours ago (1 children)

Quote the block you’re referring to please. The lawyer wouldn’t be calling this a major setback if the plan was flawed (what you’re seemingly claiming) - in fact:

“The U.S. Bankruptcy Trustee, an arm of the Justice Department, argued that the bankruptcy law does not permit protecting the Sackler family from being sued. “

Which actually means the opposite of what I think you’re getting at. Even if they bankrupted, they could still be sued. Help me understand where/what you saw that lead to this rationale.

[–] [email protected] 1 points 17 hours ago* (last edited 17 hours ago) (3 children)

Do you have source for this so I can learn more?

[–] [email protected] 10 points 19 hours ago

None of this is news, this jailbreak has been around forever.

It’s literally just a spoof of authority.

Thing is, gpt still sucks ass at coding. I don’t think that’s changing any time soon. These models get their power from what’s done most commonly but, as we know, what’s done commonly can be vuln, change when a new update is dropped, etc etc.

Coding isn’t deterministic.

[–] [email protected] 8 points 19 hours ago (6 children)

Because of fucking course

Who will we blame our problems on if we just go and start taking steps towards solving them

[–] [email protected] 4 points 19 hours ago* (last edited 19 hours ago)

Got snatched up at an airport

Fell out of a 5th story window

Sent to a religious work camp

Being poisoned with polonium-210

All sorts of fun little things

[–] [email protected] 1 points 1 day ago* (last edited 1 day ago)

Not at all what I meant. The premise was that this wouldn’t happen if they were being paid fairly. Supply chain attacks happen with or without fair pay.

Look at what happened with the XZ backdoor. Whether or not they’re getting paid just means a different door is opened.

The root of the problem is that we blindly trust anyone based on name-brand and popularity. That has never in the existence of technology been a reliable nor an effective means of authentication.

If it’s not outright buying out companies it will be vulnerabilities/lack of appropriate management, if it’s not vulns it’ll be insider threat.

These are problems we’ve known about for at least a decade+ and we’ve done fuck all to address the root of the problem.

Never trust, always verify. Simple as that.

[–] [email protected] 2 points 1 day ago (2 children)

… he made plenty off the product and made additional when he sold. Devs ability to make money has nothing to do with companies coming in and injecting malware to the service.

Any threat actor group with sufficient funds from various campaigns, spyware, etc could use said funds to buy out a dev, owner, etc.

Not to mention state-sponsored threat actors. This is the perfect example of distracting from the fact of what happened.

[–] [email protected] 5 points 2 days ago

Good catch! Missed that one

[–] [email protected] 3 points 2 days ago

Because it exposes root and system internals. Biggest reason android devices get compromised/hacked and your fun, quirky android becomes a link in a bot net peddling god knows what including attacks against people and other illegal activities and media

[–] [email protected] 23 points 2 days ago* (last edited 14 hours ago) (2 children)

For anyone interested - I’d you are using umatrix to block shit you can punch these lines into a new text file and import as blocklist, then commit it with the tiny arrow that points left toward the permanent list to save it permanently:

* www[.]googie-anaiytics[.]com * block

* kuurza[.]com * block

* cdn[.]polyfill[.]io * block

* polyfill[.]io * block

* bootcss[.]com * block

* bootcdn[.]net * block

* staticfile[.]org * block

* polyfill[.]com * block

Remove the square brackets before saving the file - these are here to prevent hyperlinks and misclicks.

Edit: this is not a bulleted list, every line must start with an asterisk, just in case your instance doesn’t update edits made to comments quickly.

Edit2: added new IOCs

 

Hey all!

While investigating some malvertising campaigns today, I noticed that one of the sponsored google search results, upon hovering, appeared to be changing/resolving through rather than simply showing what link was being used by the result.

Any ideas as to how this hover url result works and if you can disable resolving/force top-level results upon hovering over anchor elements?

Malvertising is hot hot hot!

 

Hey all, got a quick question!

I want to receive, parse and store syslogs from various devices on my home network on my windows box. I know, I know, its a bit backwards but I'd like to proceed with this sort of setup if possible (not against discussion, of course).

I've looked and looked for options but it seems like everything has been bare bones and basically just receives, or is locked behind premium. Surely there's some sort of solution out there, no? I'd be willing to implement something in Python if I need to but I'm considerably more hesitant when compared to using an open source soln.

Thanks for your time, looking forward to discussing/learning more!

 

Anyone else getting tired of all the click bait articles regarding PoisonGPT, WormGPT, etc without them ever providing any sort of evidence to back up their claims?

They’re always talking about how the models are so good and can write malware but damn near every GPT model I’ve seen can barely write basic code - no shot it’s writing actually valuable malware, not to mention FUD malware as some are claiming.

Thoughts?

view more: next ›