Fritz Adalis

@FritzAdalis@infosec.exchange
485 Followers
531 Following
23.8K Posts

Infosec Lurker | Technical Debt Collector

It's not for fun, or any sense of community.
It's just trying to dull the pain.

Pronounshe/him
S. D. Locke's Proposal - SCP Foundation

The SCP Foundation's 'top-secret' archives, declassified for your enjoyment.

The SCP Foundation

@bagder writes about his AI slop problem on H1: https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/

I like bug bounties and I put a fair amount of effort into bootstrapping the one at Google back in the day, but I think the problem runs deeper than AI.

First, most people who make a living doing bug bounties don't go after $10,000+ bugs. Very few researchers can crank out top-notch find month after month. A much better strategy on these platforms is to go after low-hanging fruit and rake in $500 to $1,000 bugs every day.

Companies respond accordingly! Because most of the traffic are low-value vulns from less skilled researchers, you don't want to throw your best analysts at this. It's increasingly common to outsource triage and bug-filing for bug bounty programs.

But if the person doing the triage isn't highly paid and familiar with the systems in question, there is a strong incentive to err on the side of caution. If you incorrectly close something serious as a non-issue, you risk the researcher making a stink. Conversely, if the triager files a non-issue with the product team, they'll probably fix it anyway, and the only cost is some wasted time.

The result is that in most programs, there's no penalty for slop. And researchers exploit this with spray-and-pray tactics. Why not?

I think one issue here are platforms that make it easy to window-browse for bug bounty programs. They have plenty of advantages, but it's a race to the bottom because the least diligent vendors set the bar for participation for all.

Death by a thousand slops

I have previously blogged about the relatively new trend of AI slop in vulnerability reports submitted to curl and how it hurts and exhausts us. This trend does not seem to slow down. On the contrary, it seems that we have recently not only received more AI slop but also more human slop. The latter … Continue reading Death by a thousand slops β†’

daniel.haxx.se
Act stupid.
@deersyrup if you do enough math they call you a polymath
Do you remember that thing about the co-founder of DDoSecrets Thomas White being an administrator of the darknet drug market Silk Road 2? Turns out, the arresting officer in his case, was corrupt and stole a bunch of bitcoin during the course of the investigation: https://www.bbc.com/news/articles/cly2xgxn0lro
Officer who stole Bitcoin from crime network on dark web jailed

Police said Paul Chowles used his National Crime Agency role to "line his own pockets".

stdio(3) change: FILE is now opaque

"I was explaining to my Ukrainian colleague the phrase β€˜There’s no such thing as a free lunch’. She told me the equivalent in Ukrainian is β€˜The only free cheese is in the mousetrap’ - which is so much better"

-found on Bluesky

Tree hole bouncer
According to my NextDNS analytics and blocklists, something in my home tries to send tracking info about me to the internet on average once every 21 seconds.
Γ—
What if we kissed πŸ‘‰πŸ‘ˆ in the motormelon?
@jsr It's actually 'watermelon pink' which is a legit color name.
@jsr Try pulling up to a job interview in one though!!

@jsr

Appears to be seedless.

@jsr Appears to be seedless.

@jsr

Looking at the paint job, I thought "cute", but when I saw the pink interior, I thought "that's commitment to the bit!"