Tommy Harris

69 Followers
222 Following
26 Posts

Junior Graybeard | InfoSec Analyst

Sometimes I pretend that I can hack stuff (#htb). Mostly defend.

#linux fanatic

Websitehttps://tobraha.tilde.team
Githubhttps://github.com/tobraha
GPGhttps://github.com/tobraha.gpg

RE: https://mastodon.social/@tom7/116400371274962195

This is fantastic. Haven't so thoroughly enjoyed a video on Youtube in quite a long time.

I am apparently a very effective hermit and had not yet heard of Dr. Tom VII and I will now be spending the next hour reading the paper this video accompanies when I should be working 

The Post-Quantum League of Evil endorses @tom7 httpv for maximum classical security. Future work hopefully will include a post-quantum key exchange as well.

https://youtu.be/M1si1y5lvkk?is=P4jFTJyzn3lsJUof

https://tom7.org/httpv/httpv.pdf

No one can force me to have a secure website!!!

YouTube

I don't think anybody actually watches videos any more, so here's MWT's core point -

The flagship and lead vuln in the research is a BSD vuln, it cost $20k to discover with Mythos. Anthropic only reached a crash, and the vuln class in 99%+ cases never reaches RCE, just crashes.

So.. cool.. you spent $20k of VC money to find a crash as the flagship vuln. But... uhm... that isn't the end of the world.

The proof is going to be if any of the open source vulns turn out to be important. So far:

So here's the other thing that bothers me about all this. Regardless of the eventual results, this thing they're doing is *incredibly* resource intensive. They routinely spend billions of dollars on training these models, and billions more on operating them. It's not simple to parse out what fraction of that is directly attributable to the massive scale vuln finder/fabricator. But for the sake of argument lets just pick a plausible number, and call it 50-100 million dollars.

What could we have gotten for 50-100 million dollars of sponsorship for security audits? Prior to this, the largest single investment into FOSS security I'm aware of was the 2015 audit of openssl, after the heartbleed incident. It's hard to find precise costs for that, but I found a few sources estimating 1.2 million dollars, and that is arguably the most security critical piece of software in the world.

But suddenly there's 100x more resources available to do this work, now that producing the artifact can be done with stolen labor? Now that they can externalize the cost of false positives onto the already mostly unpaid maintainers of these projects? Even if their claims are true, which we have no reason to believe and very good reason not to, it's still a travesty

“The UI is clean. The API is RESTful. The architecture diagram is beautiful. The outputs are wrong. Nobody checks because nobody on the team knows what correct outputs look like. They’ve never looked at the data. They’ve never computed a baseline.”
https://leehanchung.github.io/blogs/2026/04/05/the-ai-great-leap-forward/
The AI Great Leap Forward

In 1958, Mao ordered every village to produce steel. The steel was useless. The crops rotted. Today's top-down AI mandates are producing the same pattern: ba...

Han, Not Solo

There's one very important thing I would like everyone to try to remember this week, and it is that AI companies are full of shit

Only rarely do their claims actually bear scrutiny, and those are only the mildest of claims they make.

So, anthropic is claiming that their new, secret, unreleased model is hyper competent at finding computer security vulnerabilities and they're *too scared* to release it into the wild.

Except all the AI companies have been making the same hypercompetence claims about literally every avenue of knowledge work for 3+ years, and it's literally never true. So please keep in mind the highly likely possibility that this is mostly or entirely bullshit marketing meant to distract you from the absolute garbage fire that is the code base of the poster child application for "agentically" developed software

You may now resume doom scrolling. Thank you

😕

Artemis II iPhone Wallpapers
Some of my favourite iPhone crops from the Artemis II mission.

https://basicappleguy.com/haberdashery/artemis-ii-iphone-wallpapers

'Cognitive Surrender' Leads AI Users To Abandon Logical Thinking, Research Finds - Slashdot

An anonymous reader quotes a report from Ars Technica: When it comes to large language model-powered tools, there are generally two broad categories of users. On one side are those who treat AI as a powerful but sometimes faulty service that needs careful human oversight and review to detect reasoni...