Billy O'Neal

672 Followers
321 Following
9.9K Posts
Dev at Microsoft on the vcpkg team. Former @VisualC STL maintainer. He/Him (Although I don’t care much)
GitHubhttps://github.com/BillyONeal
DiscordBillyONeal#4301
Orgs aiming to implement a Mythos-ready security program when they have a flat network with default creds everywhere and ransomware actors casually logged in.
Initial results are promising. I sadly already ran into at least 1 vcpkg bug: we use the x64 7zip instead of the arm64 one.

I hold many controversial opinions. For example, I think that a process segfaulting inside of a VM should not be able to take down the host.

Unfortunately, I use macOS. Where it can. And does. To my chagrin.

I don't think anybody actually watches videos any more, so here's MWT's core point -

The flagship and lead vuln in the research is a BSD vuln, it cost $20k to discover with Mythos. Anthropic only reached a crash, and the vuln class in 99%+ cases never reaches RCE, just crashes.

So.. cool.. you spent $20k of VC money to find a crash as the flagship vuln. But... uhm... that isn't the end of the world.

The proof is going to be if any of the open source vulns turn out to be important. So far:

I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. I’ve read the research paper they released and the numbers, and basically I agree with @malwaretech’s take. It’s marketing. The cybersecurity industry is historically very good at marketing cyber pearl harbour and the need to buy magic boxes.
@whitequark i guess the only logical conclusion is
@vitaut damn I didn’t get anything that shiny
@RolfBly @mothcompute yes it is very well established. It’s also awful and I hate it.
Billy on 5 or 6 beers
@funhouseradio your logo reminds me of The Black Crowes - Three Snakes and One Charm