It reverse engineered a binary daemon that set fan curves and told me how I should set them up in the new OS. I didn’t ask for this, and I didn’t have reverse engineering tools installed. It just figured out it could run them using Nix.
The most worrying part, to me, is that it did it like it was nothing. It simply said “usr/local/bin/some-daemon sets the following fan curves”. I had to ask how it reached that conclusion for it to tell me casually that it had just read it straight from the x86_64 assembly.
No access to the source code is no longer a meaningful obstacle to these models.
Video games are now ruined for me. I don't think I will ever feel safe playing online again.
> I do these things for pure entertainment and curiosity, not for money from bug bounties
Me too... Was it easy to get TAC access? My account isn't even launching the Persona verification, says I'm not eligible.
Agreed, also WordPress powers around 43% of all websites on the internet. https://patchstack.com/whitepaper/state-of-wordpress-securit...
WCGW?
If we're to believe how good those AI are at CTF and at escapes of all kind, then the only logical conclusion is that, by very far, most vulnerabilities were already closed, even before AI.
Otherwise we'd already be in deep shit since months if not years.
Inexplicably, I got accepted into Anthropic's cyber program while OpenAI's TAC doesn't even allow me to verify, says I'm not eligible.
Edit: Ah, I clicked "learn more" and it seems they do have an invite-only program, required for anything that's not unquestionably innocent. I don't think I'd surrender my face to Persona for this, but it's interesting to know they're at least pretending to support reverse engineering.
In the future, I might reverse engineer the on-disk storage format and create a new application.
It's really just simple ID/face verification?
And nowhere did I say that those RCEs were in critical software, I'm not talking about the likes of Apache, Nginx, Django, etc.