• 0 Posts
  • 10 Comments
Joined 3 years ago
cake
Cake day: June 13th, 2023

help-circle




  • Except it wasn’t just “throwing everything and the kitchen sink at a server”. Modern LLMs have been trained well enough to not just create a list of potential attacks and execute them, but to:

    • create their own personality prompts aimed at pentesting and attack vector analysis
    • actually analyse the target before executing any of the attacks, optimising that flow (which is pretty much what a security expert would do)
    • scour the internet for recent references of the target and related keywords to see if their services have been exploited recently
    • using the target analysis of step 2 to create a list of known third party elements (ranging from the HTTP server being used, the proxies and detected security measures, geographical distribution and HA, all the way to JS libraries used to run the website/admin interface)
    • execute the attacks AND continuously tailor the solution based on the results

    of course this can be used for good too. I did this to pentest my own homelab stack. I used the very same flow to hack into a pair of smart glasses I own (not the creep glasses, mind you, but the “wearable monitor” kind of AR glasses - turns out the pair I own runs on a pretty decent base, a somewhat recent Linux kernel and minimal userspace, with some exploitable interfaces) within about a day.

    What’s truly dangerous is that these tools have the ability to turn a relatively simple “hack into the NASA servers” instruction into a detailed, executable plan of actually breaching the servers in question. That a person with more than one and less than three brain cells to rub together - someone who’d think this scene is super cool and completely legit looking - can, with minimal guardrails-bypassing, increase their own chance of hacking into ANY server, from less than 0.000000000000000001% to 20-30%. Now that’s scary.


  • Honestly, this could be a great equaliser.

    Home grown AI models have been shown to be extremely good at market analysis and predictions, some managing quite nice gains by daytrading small amounts and micro transactions - gains that previously were reserved to the coke-moustached shark investors and savvy finance geeks.

    If hosted models can bring results even just half as good as those, to the average people, that will be a make and break point for the finance fuckers. Because why would you go to an investment firm who offers maybe 40-50% gains YoY while taking 15-20% of the profits, when you can pay £20 for Claude or ChatGPT and have 300-500% returns on your base investment every month?





  • With all the cameras being re-patriated by good citizens, I’m sure a number of them already made their way to skilled hackers, tinkerers.

    And given how amateurish Flock was with their most recent PR event (a reporter tried to attend, got rejected almost last minute, Flock even went behind his back to cancel his hotel booking, so our guy went full out and with a metric fuckton of RF equipment, monitored the event’s signals. WiFi, Bluetooth, wireless mics (which they often left on and just broadcasting out into the wild), I have a feeling that the whole Flock ecosystem is riddled with security issues.

    I wouldn’t be surprised if there’s some incredibly dumb stupid kill switch built into the firmware that can be triggered by something as simple as an ESP32.