Gerald Combs

563 Followers
70 Following
516 Posts
B-list computery person. Creator & lead developer, Wireshark. Works at Sysdig. He / him.
Websitehttps://www.wireshark.org/
Twitterhttps://twitter.com/geraldcombs
Pronounshe / him / hey, jackass
Blueskyhttps://bsky.app/profile/geraldcombs.bsky.social
Listening to cybersecurity people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.

#Wireshark 4.6.5 has been released. Cheers! These releases are brought to you by the Wireshark Foundation. If you or your employer can donate, it would help us out immensely.

https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html

wiresharkfoundation.org/donate/

Wireshark • Go Deep | Wireshark • Wireshark 4.6.5 Release Notes

Wireshark: The world's most popular network protocol analyzer

Wireshark
the 555 timer is 55 years old, so if we celebrate on the 5th of May it can be the 555's 55th on 5/5.
Threat models are just part of the much larger threat fashion industry

Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload.

Ask yourself what you do to make the situation better.

Make sure your employer does as well.

AIs have been finding bugs and vulnerabilities in #curl for some time.

Is it work to fix those? Yes.

Has someone paid for this? Partially (wolfSSL and @sovtechfund)

Are the AIs annoying? Yes, very.

Could humans find the same bugs? Yes, if they‘d somehow avoid being bored to death through it.

Was there something „heartbleed“ like? No.

Were there lots of C mistakes? No, logic bugs mostly.

Do AIs run out of steam? Yes. After a while a model stops finding things. Findings differ per model.

PSA: Please don't forget your `--fail` option to #curl when developing scripts and cron jobs.

#SysAdmin

The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

#curl's hackerone "portal" has been open 74 days this year, during which we have received 92 reports.

That's one new report every 20 hours. Last year we got one every 48 hours, but then the quality was also much worse.

Every report takes a few hours to deal with.

The reports are often high quality and identify problems, but only some of them *security problems*.

The problem here is not AI. Just good old overloading a few with so much work.

The AIs are not good enough to fix the issues.

Do big tech companies understand consent?
Yes
0.8%
Remind me in 5 days
99.2%
Poll ended at .