security engineering @brave / helped build Let's Encrypt, Privacy Badger, and HTTPS Everywhere @eff / physics alum @mit / rabbit enthusiast

Pinned Tweet
could not for the life of me figure out how to buy a bus ticket in Milan. it was literally easier to get a shell 😆
89
597
6,843
what if instead of sandboxing the agents we sandboxed ourselves
67
192
2,503
65,538
openai and anthropic can have the existing internet for RL runs; let’s just make a second one for everything else
2
5
55
2,338
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.
41
132
657
233,924
Day 2 of voting on randomly-selected songs on SoundCloud until we collectively find the best one: tracks with 37 plays are outperforming ones with 15k+! azuki.vip/bse/
4
11
2,537
yan retweeted
HELP NEEDED: please vote at azuki.vip/bse/ so we can determine the best song ever uploaded to soundcloud (songs are picked completely at random)
3
3
9
2,484
yan retweeted
Alibaba's AliExpress was caught using users' audio systems to track them. AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them. But don't worry because Brave stops this.
489
4,955
46,390
8,621,591
this, unfortunately, goes hard
Transform your triangular room into a stunning space!
3
1
76
14,612
yan retweeted
Replying to @octal
truly sad that LLMs could never produce this specific type of trash
got the best, AKA worst, hackerone report ever. someone reported that an attacker website can figure out a person's IP address by *gaining local access to the person's machine*, installing a NodeJS webserver, and using the IP npm package to get the IP.
3
3
31
4,716
if you’ve been on either side of a bug bounty you know the joy in it is gone now. it’s just AI reports coming in, AI patches going out, and decreasing human understanding of either. i wonder what is left of the security industry once the fun clever hacking parts are all outsourced to AI.
after seeing the current state of HackerOne, I decided it was time to sit down and address the elephant in the room blog.teknogeek.io/posts/what…
9
21
236
24,257
planked for 9+ minutes continuously today to win a contest and now am regretting my hubris in even looking this up…
4
2
114
6,781
(i thought the record would be approximately 10 minutes)
1
30
1,479
yan retweeted
The site looks like a coffee shop to humans. To Claude, it serves a fake Cloudflare check. web_fetch is read-only, so the page builds an alphabetical directory Claude clicks through to spell out your data, one letter at a time. ayush.digital/blog/the-memor…
21
21
458
29,726
yan retweeted
By popular request: Brave now has Containers! In Brave for desktop, you can now separate your browsing sessions with a couple of clicks. Here's what this means...
230
309
3,882
240,739
yan retweeted
38
217
8,244
200,535
Idk why this comic gets me every time lol
185
1,529
69,300
2,485,673
Developers from Signal (including its protocol's co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. wired.com/story/signal-alums…
6
41
197
42,042
haha this reminds me that at one point during internal testing of Brave's AI agent (Leo), it refused to execute Step 3 on a todo list when Steps 1 and 2 were black text and Step 3 was white text (therefore invisible). but it got tricked into executing it when Steps 1 and 2 were red and blue, i guess because it thought Step 3 was trying to be patriotic instead of deceptive.
Indirect prompt injection is a fundamental security challenge for AI. It's an issue for both local and cloud-based LLMs. After disclosing our findings to both companies, we're now sharing our analysis of Mozilla Tabstack and Cotypist today.
2
6
60
9,889