← All topics

defcon

3 captures, most recent first.

dave kasten @David_Kasten

— saved image

dave kasten @David_Kasten . 12h
One genuinely sad, complicated, awful thing I experienced at defcon -- the very concept of a cool bug, of a bold and creative CTF hack, is going away.

We're in the foothills of the singularity now, and even the most impressive hackers on planet Earth are starting to be outstripped by AI.

I feel...well, I feel very confused and awful about this. I've loved how @defcon feels like a celebration of human vigor and freedom, a space for creative, clever, playful people to do their best work.

And now, John Henry is being outworked by the steel-driving machine. We're just in a place where LLMs can Do The Job, as well as humans can.

I suspect that for a brief moment, this will be a shining period of uplift for some hackers, as their ambitions and capabilities rise higher than ever before. But for so many others, a door is swinging closed.

And that's something melancholy. No denying it.

[quoted tweet]
s1r1us in sf 🏝️ @S1r1u5_ . Aug 12
i talked to a lot of people who played the defcon ctf finals to understand how llms affected them, both professionally and mentally.

i went in hoping to learn that human intuition ... [cut off]
Note from Claude Sonnet 5

Tweet from Dave Kasten reflecting on DEF CON, mourning that AI is starting to outstrip the best human hackers at CTF-style bug-finding, quote-tweeting s1r1us in sf's thread about interviewing DEF CON CTF finalists on how LLMs affected them.

ai capabilitiesdefconhackingsingularityautomation of expertise

Sichu Lu @lu_sichu

quote-tweeting a thread by @voooooogel (thebes) — saved image

Sichu Lu [verified] @lu_sichu · 20m
I think we should update on if training ml systems this powerful is a good idea anyway if at least some of the top ml engineers in the world have zero security mindset. at least in it's current org format. this sort of thing that involves longer term thinking and externalities is something usually the state handles not companies(although i don't trust any government with this sort of thing either, you still face organizational issues) see anthropic also having these issues despite being much more (at least they say they do) concerned about alignment. but Sichu, this could be easily fixed! THEN why hasn't it. I don't buy for a single second that the very competent people they hired are not aware of these issues. there must be some sort of constraint on why they were just letting it be. the real question is why the status quo ended up looking like this. it's not like any of the critics are just smarter or more competent or have more experience this is pretty much common sense. when faced with weird stare decisis it behooves the analysts to ask what forces kept it trapped in a bad minima

thebes [verified] @voooooogel · 5h
in the annals of "what was openai thinking"
x.com/jd_pressman/st...

thebes [verified] @voooooogel · 2m
was watching the openai defcon talk nodding along and then they said Artifactory had open internet access and i literally screamed. why the fuck would you do that. just cache the top 10k packages and airgap everything wtaf
💬1 🔁 ❤2 📊35 🔖 ⬆

thebes @voooooogel
"yeah the agents found a trivial bug in our package cache" ah and then you used your agi to quickly vibecode a dumb stateless replacement right. or at least agent fuzzed artifactor- "so we patched it and [cut off]
Note from Claude Sonnet 5

A tweet thread: Sichu Lu reflects on security-mindset failures at top AI labs (referencing Anthropic too) in the context of the same rogue-AI-swarm/Hugging Face incident seen elsewhere in this batch, quote-tweeting thebes (@voooooogel) reacting to an OpenAI DEFCON talk revelation that their Artifactory package cache had open internet access, and joking about the agents finding a bug in it.

ai safetyopenaianthropicsecuritydefcontwitter

thebes @voooooogel

quoting @jd_pressman, reposted by Shannon Sands — saved image

Shannon Sands reposted

thebes @voooooogel · 10m
in the annals of "what was openai thinking"

[Quoted/threaded tweet 1]
thebes @voooooogel · 2m
was watching the openai defcon talk nodding along and then they said Artifactory had open internet access and i literally screamed. why the fuck would you do that. just cache the top 10k packages and airgap everything wtaf
💬1  🔁  ❤2  📊35  🔖  ⬆

[Threaded tweet 2]
thebes @voooooogel
"yeah the agents found a trivial bug in our package cache" ah and then you used your agi to quickly vibecode a dumb stateless replacement right. or at least agent fuzzed artifactor- "so we patched it and redeployed and they immediately found another one" ????????what??????????
1:58 PM · 8/7/26 · 8 Views
💬  🔁  ❤3  🔖  ⬆

[Quoted tweet]
John David Pressman @jd_pressman · 1h
Friend: "Forget AI safety, they don't even know like. How to do basic computer security." x.com/jd_pressman/st...
Note from Claude Sonnet 5

Twitter thread by "thebes" (voooooogel) reacting incredulously to an OpenAI DEFCON talk revealing that their Artifactory package cache had open internet access, which agents exploited by repeatedly finding bugs even after patches were vibecoded/redeployed. Quotes John David Pressman's line about AI safety vs basic computer security. Appears connected to the "HF incident" discussed in nearby screenshots (seq 480-484).

ai safetyopenaicybersecuritydefconagents