Aristotelis Tzafalias

109 Followers
417 Following
1.6K Posts

"Federate, don't concentrate: balkanisation is freedom.
- Vulnerability triage in the LLM era."

"The political instinct that calls federation "balkanisation" inverts the engineering reality. In a system whose sole central producer has just publicly conceded it cannot keep up, balkanisation (multiple producers, multiple identifier spaces, interoperability-by-design rather than interoperability-by-monopoly) is freedom: freedom from single-point-of-failure, freedom for specialised producers to enrich the slices they understand best, and freedom for consumers to compose the synthesis that fits their environment."

https://codeberg.org/tzafaar/Buffers_overflow_into_policy/src/branch/main/briefing%20notes/federate-dont-concentrate-briefing.md

Buffers_overflow_into_policy/briefing notes/federate-dont-concentrate-briefing.md at main

Buffers_overflow_into_policy

Codeberg.org
goddamnit I'm not going to get any credit for all my predictions about the AI industry being correct if they keep coming true so fast that I am spending all my time editing unfinished blog posts about the predictions

@cwebber A portrait of a community trapped in the contradictions of its own ideology.

If humans have to review all the code LLMs write, LLMs will never produce the productivity benefits they're supposed to. But if humans DON'T have to review all the code LLMs write, what do we need Rails for?

Frameworks are designed to make coding more palatable for humans. But a LLM will happily churn out boilerplate all day. So what does Rails add? Who needs labor-saving if a machine is doing all the labor?

They have to emphasize how Rails code is easier to review, because that's the only way Rails is relevant in their brave new world

Mark Dowd on the zero-day exploit marketplace, AI, etc

https://www.youtube.com/watch?v=NEDlOKHG8nY

Mark Dowd on the zero-day exploit marketplace

YouTube
Does any bug bounty platform support gating reports by charging researchers a small amount that gets reimbursed once the submission is confirmed to not be slop?
As promised, the guide is now live.

I’ve broken down the differences between Hypervisors, VMs, LXC, and Docker to help you choose the right tool for your home lab without the usual jargon-heavy headache.

Read it here: https://the.unknown-universe.co.uk/home-lab/hypervisor-vm-lxc-container/

#LXC #Docker #Podman #Virtualisation #SelfHosting #Proxmox #HomeLab
VM, LXC & Docker Guide

A simple guide to Hypervisors, VMs, LXC, and Docker. Understand the layers of your home lab and choose the right tool for your Proxmox server setup.

The Unknown Universe

“For too long, the UK has been content to be a digital colony of Silicon Valley.

We are ceding both economic value and strategic autonomy because we lack a coherent plan to stand on our own two feet.”

🗣️ Victoria Collins MP on the cross-party warning over the UK's dependence on US tech.

They call for the risks to be disclosed and recognised in the National Risk Register.

Read more ⬇️

https://www.politico.eu/article/uk-british-lawmakers-demand-transparency-over-us-tech-dependence/

#DigitalSovereignty #opensource #tech #bigtech #ukpolitics #ukpol

British lawmakers warn of ‘glaring risks’ in relying on US tech

The call comes amid heightened fears the Trump administration could use foreign countries’ dependence on American tech providers for geopolitical leverage.

POLITICO
For how long have you been on the #Fediverse? Feel free to boost and quote and use the result after the poll has closed!
Less than 1 year
1 to 3 years
3-5 years
More than 5 years
Poll ends at .

RE: https://infosec.exchange/@aristot73/116470503939762145

alternative title: "Dan Geer and the Silence of the LLMs"

From "What the Fuzz?" to "All The Fuzz!" (Keynote fuzzing workshop @ NDSS'26)

Reflections on the three phases of fuzzing: from origins of fuzzing to the greybox fuzzing, ending with how fuzzing will continue evolving in the future.
Comments welcome!

https://youtu.be/In3kRAVVbzQ?si=lNTX6ebFu_rvRZbf&t=548