Katie Paxton-Fear (@insiderphd) 's Twitter Profile
Katie Paxton-Fear

@insiderphd

Dr, apparently. API Sec @traceableai, Lecturer & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her

ID: 961961458346135552

linkhttp://www.youtube.com/c/InsiderPhD calendar_today09-02-2018 13:54:18

18,18K Tweet

84,84K Followers

1,1K Following

Truffle Security (@trufflesec) 's Twitter Profile Photo

🧐 Recently, we found a GitHub vulnerability exposing private data. 😱 Now, a similar issue in Microsoft Azure DevOps (ADO) might be even worse. πŸ”“ Commits in Private Forks are actually Public! More details πŸ‘‰ trufflesecurity.com/blog/you-can-a…

🧐 Recently, we found a GitHub vulnerability exposing private data.

😱 Now, a similar issue in <a href="/Azure/">Microsoft Azure</a> DevOps (ADO) might be even worse.

πŸ”“ Commits in Private Forks are actually Public!

More details πŸ‘‰ trufflesecurity.com/blog/you-can-a…
Greg Linares (Laughing Mantis) (@laughing_mantis) 's Twitter Profile Photo

If you copy someone's research, post it and get caught it is 100% their right to put you on full blast always. No notice. No warning. And the community should look at every single one of their previous posts and ensure they didn't do it before.

Katie Paxton-Fear (@insiderphd) 's Twitter Profile Photo

Listen here you little shit. Send me 1 irrelevant notification and you’ll be on the app naughty list and have your notification ability revoked. Do I make myself clear

Listen here you little shit. Send me 1 irrelevant notification and you’ll be on the app naughty list and have your notification ability revoked. Do I make myself clear
James Kettle (@albinowax) 's Twitter Profile Photo

Now I've got the hang of it, Burp Suite's Organizer is super useful for research. My workflow is: - Work in repeater, using notes but making no attempt to label/group tabs - If I see anything interesting, ctl+o to send to Organizer - If I realize something was notable

Katie Paxton-Fear (@insiderphd) 's Twitter Profile Photo

β€œMass layoffs, workforce reduction of 30%” sad, economically we’re not doing well, we can’t give shareholder value, might lose money β€œReturn to office mandate after pandemic recovery” bold leadership, new ideas, things returning to normal, happy

Rich Harang (@rharang) 's Twitter Profile Photo

I'm going to go one step farther: I don't think jailbreaking / prompt injection in the LLM space is a fixable problem with LLMs as they currently exist. We have design secure applications that account for the way that LLMs *actually* work, not the way we *wish* they did.

Rich Harang (@rharang) 's Twitter Profile Photo

Does that mean that it's harder and more complicated to design those applications? Yes. Does that mean that there's a lot of cool stuff we just can't do securely? Also yes. Does that change if we just beg the LLM to "Do what I mean, dammit"? No. Alas.