Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. "AI is giving attackers a huge advantage!"

"AI is giving attackers a huge advantage!"

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
129 Indlæg 39 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

    @cR0w @jackryder Asbestos in brake pads and lead in paint did improve the product though. If they weren't so horriffic to human health, we would still be using them. Conversely, I've yet to see an instance where AI has actually improved anything. At best it lets people who are mediocre at their jobs output a higher quantity of mediocre work.

    troed@swecyb.comT This user is from outside of this forum
    troed@swecyb.comT This user is from outside of this forum
    troed@swecyb.com
    wrote sidst redigeret af
    #26

    @Mustardfacial

    I'm extremely good at what I do - belonging to that mythical home computer generation that started programming in ASM and never stopped learning how _everything_ works. To no one's surprise I'm thus working in cybersec today, partly as an ethical hacker focusing on hw/fw exploits at the really tricky low level stuff.

    A few days ago I tested, for fun, having Mistral AI's Devstral-2 model do an analysis of a firmware dump of an eMMC I had just extracted from a fully proprietary ARM-based IoT device.

    In a minute or so it had made the same conclusions as I would myself, nicely documented, on not just standard partitions and what they contained but also the fully custom stuff with no standard markers at all - including making "educated guesses" at the likely boundaries between headers and data, and what the data could be based on number of bits/bytes and entropy.

    The question is whether you will now consider me to be mediocre.

    @cR0w @jackryder

    mustardfacial@infosec.exchangeM 1 Reply Last reply
    0
    • troed@swecyb.comT troed@swecyb.com

      @Mustardfacial

      I'm extremely good at what I do - belonging to that mythical home computer generation that started programming in ASM and never stopped learning how _everything_ works. To no one's surprise I'm thus working in cybersec today, partly as an ethical hacker focusing on hw/fw exploits at the really tricky low level stuff.

      A few days ago I tested, for fun, having Mistral AI's Devstral-2 model do an analysis of a firmware dump of an eMMC I had just extracted from a fully proprietary ARM-based IoT device.

      In a minute or so it had made the same conclusions as I would myself, nicely documented, on not just standard partitions and what they contained but also the fully custom stuff with no standard markers at all - including making "educated guesses" at the likely boundaries between headers and data, and what the data could be based on number of bits/bytes and entropy.

      The question is whether you will now consider me to be mediocre.

      @cR0w @jackryder

      mustardfacial@infosec.exchangeM This user is from outside of this forum
      mustardfacial@infosec.exchangeM This user is from outside of this forum
      mustardfacial@infosec.exchange
      wrote sidst redigeret af
      #27

      @troed @cR0w @jackryder No, you're looking for a fight.
      What's that thing Socrates said? "I may be the smartest man alive because I know I don't know anything at all"

      Be humble bro.

      troed@swecyb.comT 1 Reply Last reply
      0
      • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

        @rootwyrm @cR0w @jackryder God dammit. This is the worst fucking timeline.

        rootwyrm@weird.autosR This user is from outside of this forum
        rootwyrm@weird.autosR This user is from outside of this forum
        rootwyrm@weird.autos
        wrote sidst redigeret af
        #28

        @Mustardfacial @cR0w @jackryder as a subscriber to multiversal theory, I sometimes joke:

        Three dimensions over, scientists are debating whether it was ethically right to kill Hitler in the cradle.
        Two dimensions over has a supersoldier that punches Nazis into other dimensions.
        One dimension over, scientists are debating the ethics of exiling young HIitler to another dimension.
        And over here we're going 'where the fuck are all these Hitlers coming from!?'

        1 Reply Last reply
        0
        • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

          @troed @cR0w @jackryder No, you're looking for a fight.
          What's that thing Socrates said? "I may be the smartest man alive because I know I don't know anything at all"

          Be humble bro.

          troed@swecyb.comT This user is from outside of this forum
          troed@swecyb.comT This user is from outside of this forum
          troed@swecyb.com
          wrote sidst redigeret af
          #29

          @Mustardfacial

          I think the problem is with the "criti-hypes"* who believe they know better than everybody else (those "mediocres" of the world).

          *) from https://pluralistic.net/2026/03/12/normal-technology/#bubble-exceptionalism

          @cR0w @jackryder

          cr0w@infosec.exchangeC mustardfacial@infosec.exchangeM 2 Replies Last reply
          0
          • cr0w@infosec.exchangeC cr0w@infosec.exchange

            "AI is giving attackers a huge advantage!"

            "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

            0x58@infosec.exchange0 This user is from outside of this forum
            0x58@infosec.exchange0 This user is from outside of this forum
            0x58@infosec.exchange
            wrote sidst redigeret af
            #30

            @cR0w And even Western gov's are taking decisions using AI-powered chatbots that got trained with data up to the 90's it seems.

            1 Reply Last reply
            0
            • troed@swecyb.comT troed@swecyb.com

              @Mustardfacial

              I think the problem is with the "criti-hypes"* who believe they know better than everybody else (those "mediocres" of the world).

              *) from https://pluralistic.net/2026/03/12/normal-technology/#bubble-exceptionalism

              @cR0w @jackryder

              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchange
              wrote sidst redigeret af
              #31

              @troed @Mustardfacial @jackryder Damn, I already blocked that domain.

              1 Reply Last reply
              0
              • troed@swecyb.comT troed@swecyb.com

                @Mustardfacial

                I think the problem is with the "criti-hypes"* who believe they know better than everybody else (those "mediocres" of the world).

                *) from https://pluralistic.net/2026/03/12/normal-technology/#bubble-exceptionalism

                @cR0w @jackryder

                mustardfacial@infosec.exchangeM This user is from outside of this forum
                mustardfacial@infosec.exchangeM This user is from outside of this forum
                mustardfacial@infosec.exchange
                wrote sidst redigeret af
                #32

                @troed @cR0w @jackryder

                troed@swecyb.comT 1 Reply Last reply
                0
                • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                  @troed @cR0w @jackryder

                  troed@swecyb.comT This user is from outside of this forum
                  troed@swecyb.comT This user is from outside of this forum
                  troed@swecyb.com
                  wrote sidst redigeret af
                  #33

                  @Mustardfacial

                  Cognitive dissonance is a bitch.

                  @cR0w @jackryder

                  1 Reply Last reply
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    "AI is giving attackers a huge advantage!"

                    "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

                    badsamurai@infosec.exchangeB This user is from outside of this forum
                    badsamurai@infosec.exchangeB This user is from outside of this forum
                    badsamurai@infosec.exchange
                    wrote sidst redigeret af
                    #34

                    @cR0w 2026 Cybersecurity Priority List (according to LinkedIn)

                    AI
                    AI for Security
                    AI Security for AI
                    Agentic SOC
                    AI-SPM
                    CNAPP
                    CWPP
                    CSPM
                    CIEM
                    KSPM
                    DSPM
                    ASPM
                    .
                    .
                    .
                    Patch your shit
                    The fucking basics

                    cr0w@infosec.exchangeC 1 Reply Last reply
                    0
                    • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                      @cR0w 2026 Cybersecurity Priority List (according to LinkedIn)

                      AI
                      AI for Security
                      AI Security for AI
                      Agentic SOC
                      AI-SPM
                      CNAPP
                      CWPP
                      CSPM
                      CIEM
                      KSPM
                      DSPM
                      ASPM
                      .
                      .
                      .
                      Patch your shit
                      The fucking basics

                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchange
                      wrote sidst redigeret af
                      #35

                      @badsamurai Is asset inventory covered in "the fucking basics" or is it further down?

                      badsamurai@infosec.exchangeB mustardfacial@infosec.exchangeM 2 Replies Last reply
                      0
                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                        @badsamurai Is asset inventory covered in "the fucking basics" or is it further down?

                        badsamurai@infosec.exchangeB This user is from outside of this forum
                        badsamurai@infosec.exchangeB This user is from outside of this forum
                        badsamurai@infosec.exchange
                        wrote sidst redigeret af
                        #36

                        @cR0w I almost added but I think I blacked out

                        scottwilson@infosec.exchangeS 1 Reply Last reply
                        0
                        • badsamurai@infosec.exchangeB badsamurai@infosec.exchange

                          @cR0w I almost added but I think I blacked out

                          scottwilson@infosec.exchangeS This user is from outside of this forum
                          scottwilson@infosec.exchangeS This user is from outside of this forum
                          scottwilson@infosec.exchange
                          wrote sidst redigeret af
                          #37

                          @badsamurai @cR0w It’s absolutely mind-numbing to me, the orgs I encounter who don’t have a god damn asset inventory.

                          cr0w@infosec.exchangeC nerdpr0f@infosec.exchangeN 2 Replies Last reply
                          0
                          • scottwilson@infosec.exchangeS scottwilson@infosec.exchange

                            @badsamurai @cR0w It’s absolutely mind-numbing to me, the orgs I encounter who don’t have a god damn asset inventory.

                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchange
                            wrote sidst redigeret af
                            #38

                            @scottwilson @badsamurai

                            1 Reply Last reply
                            0
                            • cr0w@infosec.exchangeC cr0w@infosec.exchange

                              @badsamurai Is asset inventory covered in "the fucking basics" or is it further down?

                              mustardfacial@infosec.exchangeM This user is from outside of this forum
                              mustardfacial@infosec.exchangeM This user is from outside of this forum
                              mustardfacial@infosec.exchange
                              wrote sidst redigeret af
                              #39

                              @cR0w @badsamurai Asset inventory is covered in "the fucking basics" for system administration, let alone cybersecurity.

                              cr0w@infosec.exchangeC badsamurai@infosec.exchangeB 2 Replies Last reply
                              0
                              • scottwilson@infosec.exchangeS scottwilson@infosec.exchange

                                @badsamurai @cR0w It’s absolutely mind-numbing to me, the orgs I encounter who don’t have a god damn asset inventory.

                                nerdpr0f@infosec.exchangeN This user is from outside of this forum
                                nerdpr0f@infosec.exchangeN This user is from outside of this forum
                                nerdpr0f@infosec.exchange
                                wrote sidst redigeret af
                                #40

                                @scottwilson @badsamurai @cR0w I'll add another caveat: It's mindnumbing the number of orgs that want a pentest but don't have an inventory.

                                cr0w@infosec.exchangeC 1 Reply Last reply
                                0
                                • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                                  @cR0w @badsamurai Asset inventory is covered in "the fucking basics" for system administration, let alone cybersecurity.

                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchange
                                  wrote sidst redigeret af
                                  #41

                                  @Mustardfacial @badsamurai Right but I was curious on the LinkedIn take on it.

                                  1 Reply Last reply
                                  0
                                  • nerdpr0f@infosec.exchangeN nerdpr0f@infosec.exchange

                                    @scottwilson @badsamurai @cR0w I'll add another caveat: It's mindnumbing the number of orgs that want a pentest but don't have an inventory.

                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchange
                                    wrote sidst redigeret af
                                    #42

                                    @nerdpr0f @scottwilson @badsamurai

                                    1 Reply Last reply
                                    0
                                    • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                                      @cR0w @badsamurai Asset inventory is covered in "the fucking basics" for system administration, let alone cybersecurity.

                                      badsamurai@infosec.exchangeB This user is from outside of this forum
                                      badsamurai@infosec.exchangeB This user is from outside of this forum
                                      badsamurai@infosec.exchange
                                      wrote sidst redigeret af
                                      #43

                                      @Mustardfacial @cR0w right. Forget security—how do orgs even do change management without a CMDB (which is unarguably smaller and more targeted than “asset”).

                                      1 Reply Last reply
                                      0
                                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                        "AI is giving attackers a huge advantage!"

                                        "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

                                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                                        krypt3ia@infosec.exchange
                                        wrote sidst redigeret af
                                        #44

                                        @cR0w The new insider threat

                                        cr0w@infosec.exchangeC 1 Reply Last reply
                                        0
                                        • krypt3ia@infosec.exchangeK krypt3ia@infosec.exchange

                                          @cR0w The new insider threat

                                          cr0w@infosec.exchangeC This user is from outside of this forum
                                          cr0w@infosec.exchangeC This user is from outside of this forum
                                          cr0w@infosec.exchange
                                          wrote sidst redigeret af
                                          #45

                                          @krypt3ia A lot of us have gotten no traction in that framing of it though. 😞

                                          futuristicrobert@infosec.exchangeF krypt3ia@infosec.exchangeK viss@mastodon.socialV 3 Replies Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper