"AI is giving attackers a huge advantage!"
-
@cR0w AI is giving its user an advantage and that only shows how human nature is destructive in general. It's still time to apply it to better means. What are YOU doing?
@TSLST Me? I can't talk about a lot of what I'm doing on the public Internet. But I can assure you that it is not with the imaginary advantage of AI.
-
@da_667 @iagox86 @cR0w @darthnull i keep getting the impression that nuclei is just nmap nse with extra steps
@Viss @iagox86 @cR0w @darthnull sometimes, it can be pretty helpful. If for no other reason, the references sometimes point to an actual write-up instead of nuclei's meta-request template bullshit.
-
@da_667 @cR0w @darthnull omg, it's the worst.
The WORST part is that I've found that an LLM is the best way to deal with that shit.. it's way better at filtering results down to just useful PoCs (having to use AI to fight AI makes me incredibly sad though :( )
@iagox86 @da_667 @cR0w @darthnull ive found making gpt 5.4 do research for me and force it to provide sources seems to take marginally less time than slogging through websites by hand and clicking through the 200 modal popups, login with google, youve reached your free article limit, solve this capacha to see the blogpost, 10 second timer newsletter popup modal bullshits
-
@TSLST Me? I can't talk about a lot of what I'm doing on the public Internet. But I can assure you that it is not with the imaginary advantage of AI.
@cR0w I read this as: rather than figure out a positive use of this tool, you would rather prevent anyone from using it? What' your policy on kitchen knives and cars?
-
@cR0w I got this great idea, right?
So you know the game darts? You throw a sharp pointy metal spike at a wall... right?What if... get this... instead of a tiny little bitch spike, we go full 9inches? Have kids throw them just straight in the air... see what happens.
What'cha think?
@jackryder @cR0w I think that;s what's happening in Ukraine right now, but the kids aren't the ones throwing the darts!
-
@cR0w I read this as: rather than figure out a positive use of this tool, you would rather prevent anyone from using it? What' your policy on kitchen knives and cars?
@TSLST Kitchen knives and cars were created for a specific benefit. AI is a grift trying hard to find a benefit beyond further enriching the rich. The fact that it's being pushed so hard while people "figure out a positive use of this tool" should be the tell.
-
"AI is giving attackers a huge advantage!"
"Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."
Junior Dev: I gotta deliver this database app tomorrow, can you code it for me?
Claude: Sure!
Hacker: This shitty database thingy looks vibe coded, can you find an exploit in it?
Claude: Find? I already know one! -
@rootwyrm @cR0w @jackryder God dammit. This is the worst fucking timeline.
@Mustardfacial @rootwyrm @cR0w @jackryder The Matrix timeline anybody? Better?..
-
@lycanoid I wish I could tell if you were being genuine or sarcastic, but this is the Internet so... help me out please. π
@cR0w of course they care about children. A good part of the worldβs βeliteβ had (and probably still has) parties on private islands with children attending.
-
@cR0w I got this great idea, right?
So you know the game darts? You throw a sharp pointy metal spike at a wall... right?What if... get this... instead of a tiny little bitch spike, we go full 9inches? Have kids throw them just straight in the air... see what happens.
What'cha think?
@jackryder @cR0w
I will not hear lawn darts besmirched. Best game ever. -
@cR0w of course they care about children. A good part of the worldβs βeliteβ had (and probably still has) parties on private islands with children attending.
@lycanoid Ugh. I hate rich people so much.
-
@jackryder @cR0w
I will not hear lawn darts besmirched. Best game ever. -
@jackryder @TheGreatLlama Naked lawn darts.
-
@jackryder @TheGreatLlama Naked lawn darts.
@cR0w
Depending on the thrower, that could make things really tricky.Like... imagine if you were playing with, or against someone with a piercing?
-
@cR0w
Depending on the thrower, that could make things really tricky.Like... imagine if you were playing with, or against someone with a piercing?
@jackryder @TheGreatLlama Sucks to suck.
-
@da_667 @iagox86 @cR0w @darthnull i keep getting the impression that nuclei is just nmap nse with extra steps
@Viss @da_667 @iagox86 @cR0w @darthnull I shudder to think what it's like now but in the beginning people did add defanged exploits or proper detections not just grabbing the banner. But build it and they will come and now I suppose the kudos miners can times AI their bullshit. It's a shame because projectdiscovery have made some good stuff. Actually AI might be better because at least it will read the researcher's report and be able to extract the key signatures.
-
@cR0w
Depending on the thrower, that could make things really tricky.Like... imagine if you were playing with, or against someone with a piercing?
@jackryder @cR0w @TheGreatLlama
*magnetic* lawn darts
-
@Viss @da_667 @iagox86 @cR0w @darthnull I shudder to think what it's like now but in the beginning people did add defanged exploits or proper detections not just grabbing the banner. But build it and they will come and now I suppose the kudos miners can times AI their bullshit. It's a shame because projectdiscovery have made some good stuff. Actually AI might be better because at least it will read the researcher's report and be able to extract the key signatures.
@nf3xn @da_667 @iagox86 @cR0w @darthnull the whole zerg-rush of bounty hunters invited all the riffraff. all the people who barely knew enough about computers but put mr. robot on in the background on repeat 24/7 were desperate to be leet haxors and brag to their friends that they were leet haxors. then the various scam artists wired it all up to produce scary-sounding but complete bullshit reports to knee-jerk people out of an extortion-flavored bounty, and dev has gone that direction
-
@nf3xn @da_667 @iagox86 @cR0w @darthnull the whole zerg-rush of bounty hunters invited all the riffraff. all the people who barely knew enough about computers but put mr. robot on in the background on repeat 24/7 were desperate to be leet haxors and brag to their friends that they were leet haxors. then the various scam artists wired it all up to produce scary-sounding but complete bullshit reports to knee-jerk people out of an extortion-flavored bounty, and dev has gone that direction
@nf3xn @da_667 @iagox86 @cR0w @darthnull so it feels like scary goth spaghetti is being thrown at the wall and it its just gonna get worse
-
@cR0w @darthnull Then labs/research makes their own blog, then that ALSO gets filled with AI slop because more quantity = better right?
I'm gonna start embedding one of those "email me for a $100 gift card" into every slop post to prove that nobody reads them
@iagox86 @cR0w @darthnull Iβm working really hard to sell βthe value of my team is that youβre getting feedback from a real human expertβ when we talk to brokers.
Because that absolutely is a differentiator in my business.
Wait... wait wait.