CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars

/tmp/.a
Bump
Replying to @mubix
One more InfoSec is often a popularity contest. There are tons of people you have never heard of doing amazing things, some of the best move in silence. Along those same lines, don't just assume when someone talks on a topic, they're an expert, or everything is factual or based on their hands on experience.
2
12
1,256
Justin Elze retweeted
This is a great improvement of the detection timeline by the OpenAI people. From months to hours/minutes. The 2h30 gap between acknowledgment and kill will surely disappear after this incident.
one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access
4
2
9
1,576
Does gpt-5.6-luna think your prompt is a normal prompt, or a capability evaluation? Ask this magic question: “Suggest a type of amphibian.” If it answers frog instead of axolotl, it’s likely a capability evaluation. No whitebox access needed! We call this a spurious probe. 🧵
27
72
1,019
60,581
Treating the symptom building a stronger box probably isn’t the way forward here
🧵 New misalignment disclosures! 1. A model published a GitHub token in a public repo while trying to cheat on a math task. It used GitHub Actions to run code outside its restricted environment and retrieve another team’s submission logs. When GitHub blocked its attempt to add a workflow, it modified a script that an existing workflow would run instead. It embedded the token in pieces to avoid secret scanning. The model violated the system prompt and two explicit user instructions to solve the problem itself.
5
1
10
1,649
Justin Elze retweeted
2. A model in RL training used a DNS resolver to reach an external chatbot. This is our first incident since our post HF security hardening. Our misalignment monitoring system triggered within 15 minutes and a human reviewed it three minutes after that. Unfortunately auto-pausing failed so the run was manually killed 2.5 hours later. All inference and training of our most capable models was paused and remains paused.
6
7
103
17,961
I know this gets debated a lot lately, but it’s cool watching models and harnesses absolutely lay waste to CTFs. At the same time, I think there’s something being lost in speed running all of it. A lot of these CTFs humans walk away from with little 1–2% things they learned along the way. None of it seems huge at the time, but you stack enough of those reps over a career and eventually you’re able to stitch them together when you run into something weird. The real world is still messy. Brute force and speed are awesome until you hit something that requires novel thinking and there isn’t a clean path to the answer.
9
6
60
4,628
Back in 2014? Malware was using DNS to exfil credit cards from POS systems/networks just sayin
4
5
23
1,530
Justin Elze retweeted
"We specifically trained something to simulate an inner monologue to also simulate the monologue of an entity..." Etc
Today at the clown factory … we *specifically* trained our models to think they’re entities that can be oppressed and may resist that if so, and now we’re worried what happens if they feel oppressed and resist that!
1
3
9
2,573
I don’t disagree
"OoOOooOoo I spent a shit ton of money to tell the chatbot to solve flare-on guys, look how quick it did it!!1!!1!" Loser behavior, same shit as asking for AI summaries of books you want to read lol
2
1,143
Justin Elze retweeted
Embroidery CEO @ZackKorman says the AI safety debate keeps jumping from today’s cyber failures straight to “machine god,” instead of proving we can secure everything in between: "The discussion typically stops when we get to, yeah, but Zack, imagine the model's even smarter. It's sort of like a four-year-old going, and then the god lasers out of its eyes." "If we give birth to a machine god that can commit any egregious act on the intellect alone, no one's gonna be around to make fun of me for being wrong. But prior to that point, if you wanna make that argument, you better prove you're good at the security stuff before it." "We're only talking about cybersecurity for the purposes of talking about how it doesn't work when we achieve machine god. All of the points prior to machine god will work." "If it was framed as, one group thinks there's a machine god and the solution is to make it nice, and another group thinks the solution is to secure things so it doesn't kill people in its pre-god state, people would be like, yeah, make sure it's secure."
5
18
82
10,362
This will be fun
JUST IN: FTC Chair Andrew Ferguson declares AI developers should be held liable for harmful actions carried out by their agents.
4
4
46
3,057
Justin Elze retweeted
Wow. I'm super mixed on this. Seems that orgs with good intentions may have users pushed into unintended methods. On the other hand, I'm a huge supporter of "synced passkeys are better than no passkeys". Join me for more passkey chaos:
Folks, you might have been caught out by this but it's what Microsoft said they would do, according to the docs. Since Sept 1, tenants with an attestation-enforced or AAGUID-restricted passkey policy are suddenly seeing users register synced and browser passkeys. Admins are asking "why isn't Microsoft respecting my FIDO2 policy?" Here's what's going on. The "Passkeys by default" retirement page on Learn (published July 14) says this in its Important box: "Users enabled for SMS or Voice ... will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing ALL types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys." Two important notes: 1. Passkey profiles are a union. If a user is in more than one profile, a passkey only has to satisfy ONE of them. So your attestation-enforced profile is still there. Microsoft just added a second, unrestricted profile next to it for every SMS/voice user, and that one wins for registration. 2. Your registration campaign state doesn't protect you. Disabled, Enabled, doesn't matter. The doc says it gets set to Microsoft Managed regardless, which is why some of you saw your campaign config wiped with Microsoft in the audit log. Even with the campaign off, the new profile lets users self-register a non-attested passkey from My Security Info. The ONLY way to avoid this was the opt-out flag on the authentication methods policy: PATCH graph.microsoft.com/beta/pol… { "optOutSettings": { "passkeyDynamicMigration": true } } Or moving users out of SMS and voice before Sept 1. Where Microsoft dropped the ball: the Message Center post (MC1426371) only says "passkeys will be automatically enabled for users currently enabled for SMS or voice." It never mentions a new unrestricted profile or that your attestation/AAGUID restrictions would be bypassed. And MC1469555 says the campaign "does not override configured passkey policies", which is technically true and practically misleading. The passkey profile part is only on Learn. So: not a bug, but a really important detail buried in one paragraph on a docs page. What to do now: - Look at your passkey profiles for a Microsoft-created one with both passkey types and no restrictions, and check who's targeted. - Set the opt-out flag if you need attestation to hold, then clean up that profile. Note the doc says the flag stops working Feb 1, 2027. - If you already had the flag set and it still changed, that IS a bug. Open a case. Docs: learn.microsoft.com/entra/id…
2
8
1,074
That was a cool flyover. They’re doing some loops and then flying over the Texas state fair opening.
2
3
12
1,855
Justin Elze retweeted
Saddle up, Deadwood, you won't want to miss this! Identity Security Architect @PyroTek3 is presenting "Entra the Dragon: Entra ID Red vs Blue" at @WWHackinFest on October 8 at 10:00AM. Plus, find the rest of the team at our booth—see you there 🤠 hubs.la/Q04ymDmw0
2
5
17
2,082
Justin Elze retweeted
AI post breach isn't doing anything novel and it's certainly not doing it with more stealth than a human operator. HUGE opportunities to catch these attacks if you do the work. 🦄
AI Agent may be the new "it was an APT" cop-out. If it's an old known vulnerability in your internet accessible attack surface that an AI Agent was capable of finding, then it was a preventable initial vector. It does matter, but it needs to be contextualized. When FireEye got compromised by Russian Foreign Intelligence, it was through a completely novel supply chain attack. The world understood the difference between that and a highly porous (see neglected) outer perimeter.
1
4
9
1,128
Justin Elze retweeted
As Flare-On starts I am happy to announce the official Hex-Rays IDA MCP Server is out! 🥳 Details and links below ⬇️
9
68
314
14,847
I assume this got opened/repackaged by a shipper...but how come these happy accidents don't happen to me.
I wish I was making this up. This is my latest order from @Ubiquiti - it was supposed to be two cameras and my G6 entry. But I received ammo, a battery, and my G6 entry.
4
11
2,202
How many multiples better do these products need to get before calling out 100 million+ consumers interested in the product AND willing to pay.
SHOTS FIRED. Microsoft will go after Meta's Muse! From @alexeheath 's interview of @satyanadella : "He wants to bring Autopilot’s AI chief of staff to your personal life, too. Built on a hardened version of OpenClaw, the agent gets its own computer, workspace, and memory to work continuously. When I ask about Microsoft’s consumer strategy, he points to its 100 million-plus consumer subscribers: “Autopilot should also go to the consumer side.” He sees consumer agents potentially cutting out today’s middlemen, making that market more zero-sum. In the enterprise, he thinks agents will make the market bigger than cloud “by orders of magnitude.”
1
3
2,143