Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Daniel Cuthbert

@dcuthbert@defcon.social
mastodon 4.7.3
  • Open on defcon.social

Documentary photographer, old creaky hacker. Co-author of the @OWASP ASVS standard. Blackhat/Brucon Review Board.

3051 Followers
238 Following
24 Posts
Joined December 25, 2022
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

I know it’s easy and cool to dunk on EU red tape but this is actually sexy af: https://commission.europa.eu/news-and-media/news/right-repair-new-consumer-rights-easy-and-attractive-repairs-2026-07-31_en

For the last decade (or maybe more actually) hardware engineering has leaned heavily on proprietary screws, anti-repair software pairing, and literal buckets of industrial adhesive.
This piece treats the EU Directive as a tactical defeat for aggressive silicon anti-features.

Actually I think the right to repair is vital. We’ve got too much e-waste as it is so I welcome such efforts to make and mend.

Silicon Valley won’t like it but honestly, they are the problem in most cases

commission.europa.eu
46
3
35
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 2mo ago
I never thought i'd side with Gen Z in how they think, but when it comes to analogue devices, we are very much in sync. Vinyl's back. Mechanical watches are back. Gen Z reads more physical books than the algorithm and tech bro's wearing patagonia would like. I'm here for it. I remember being with @thedarktangent@defcon.social in London talking about cars and tracking a while ago and it has always been in the back of my mind. I'm not anti-tech, I'm just anti-tech for techs sake. I own a modern car, it's from 2009 and it's the newest I have and have ever had actually. It has knobs. It has sliders. There's no stupid ipad in the display. I don't have it snitching on me. I don't have a sub to warm Turns out I'm not just being sentimental about this. From January 2026, Euro NCAP won't give a car five stars unless it has physical controls for indicators, hazards, the horn, windscreen wipers and such. physical knobs. wild I tell ya Their own research found touchscreen tasks can take 20+ seconds, enough to cover half a kilometre at motorway speed without your eyes on the road. Then there's the data, and this is the part that actually worries me professionally. Mozilla tested every major car brand's privacy practices. Every single one failed. Their conclusion: cars are the worst product category they've ever reviewed for privacy (https://www.bbc.co.uk/future/article/20260513-your-car-is-spying-on-you-its-about-to-get-worse) None of this is a human underwriter looking at your file anymore. It's a model turning your braking patterns, night trips and cornering speed into a risk score and quietly adjusting your price. Insurers are moving further into AI-processed pricing and claims, and even within the industry the reasoning behind a given decision is often described as a "black box" that's hard to unpick So I'm not being precious about buttons for the sake of it. I'm against tech that fails silently, phones home without asking, and quietly builds a profile of me that I'm not allowed to read. Tech for tech sake is what VC's and tech bros want and the reality is, most others dont And that's the part I can't get past, being on the inside of this stuff. I know exactly where that data goes. It's not sitting in a drawer somewhere. It's a row in a Postgres table, or an embedding in a vector database, waiting for some frontier model to slurp it up Often with shoddy security engineering processes and "oh crap we got hacked but no honestly, we DO take your security seriously" lines we've all heard to death. So here's to more analogue, less tracking and less bloody data generation If you got this far, watch Julia James Davis (she's very cool, I like her series on the death of beauty) https://www.youtube.com/watch?v=V7GKFmAbTB8&t=1s Anyway here's to hacker summer camp, tinkering and breaking and hacking.
Trillions of miles of data: Your car is spying on you, and it's only just the beginning
bbc.co.uk

Trillions of miles of data: Your car is spying on you, and it's only just the beginning

From your weight and facial expressions to your destination, cars collect a startling amount of data about you. Some of it may even raise your insurance costs.

35
5
18
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Last burst of those summer rays...

The Light Lens Lab 50mm F2 Speed Panchro II, designed by Mr. Zhou in China, is possibly one of the characteristic lenses I own.

The original Cooke Speed Panchro II is a beautiful piece of optical history, but rare, expensive and increasingly difficult to find. Unless I turn to cybercrime, this lens is an easier way of shooting that famous “Cooke look”.

What I love most about it is the imperfections. Modern photography is too perfect.

The glow, the softness, the vignetting, the gentle fall-off and the way it renders light. Modern lenses are designed to correct these imperfections. The Speed Panchro embraces them, and somehow, those imperfections are what give the image its character.

Not technically perfect. Just beautifully imperfect with flaws and renderings more how we see stuff.

Modern technology has spent decades trying to remove imperfections: more resolution, better dynamic range, less distortion, less flare, sharper corners, cleaner high ISO, perfect autofocus.

And now there's a cultural reaction to that perfection

https://www.theguardian.com/artanddesign/article/2024/aug/16/the-mistakes-are-romantic-gen-zs-revival-of-point-and-shoot-cameras

People are deliberately choosing older cameras because the limitations create an aesthetic. The blur, grain, harsh flash, colour shifts and blown highlights aren't necessarily defects anymore, they're part of what makes the photograph feel distinctive and human

We dont see perfectly. Our eyes are amazing but modern smartphone and digital camera sensors dont reflect what we process.

https://www.fastcompany.com/91050385/why-gen-z-is-obsessed-with-point-and-shoot-digital-cameras

So here's to more mistakes. More blurs, more harsh colours and not what tech bro's in the valley think we want or need just because their wealth depends on it.

theguardian.com
9
0
5
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 2w ago
Phase 3 of Mick’s restoration adventure, our 1956 Land Rover series 1 107, has begun. The truck spent 70 years of its life in the Australian outback, and as such whilst there is no serious structural rust, there is a metric shit ton of outback dirt and surface rust, of which we need to remove.. i’m toying with the idea of getting this bead blasted and then powder coated, which should prolong its life far beyond when I have shuffled off this mortal coil and it’s up to my boys to then enjoy it. It’s that or the boys and I get intimate with some masks and the wire wheel.
2
1
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 2mo ago
So @chompie1337@haunted.computer and I are on a mission to find creative artists who want to help design the cover for Phrack #73. retro sci-fi & chrome futures ▸ cyberpunk / terminal aesthetics ▸ dystopian systems ▸ hacker manuals from an alternate timeline ▸ weird cool stuff and machines Keen? Fancy helping? 📮 arts@phrack.org ⏰ Deadline: August 15
33
1
62
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

I’ve entered that phase of my life where a lathe is looking like a solid decision for the workshop.

Shit.

7
1
1
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Shut up and explore this amazing planet of ours. A mantra I’ve had since I was a teen and it’s so good to see a Norwegian do what I want to do before I shuffle off this mortal coil: ride around Afghanistan on a bike just with my Leica and film

https://youtu.be/OMC7pj-0wQY?is=rWzQMWjQmVhrl701

You go Tom. This is living. Afghanistan looks amazing.

5
1
2
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

One has to pay respect for the effort that was clearly monumental for this edition of tmpout

https://tmpout.sh/5/

that ASCII art is off da faken scale

tmpout.sh
5
0
1
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Anyhoo. Los canarias…

7
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 5mo ago

Ever since @thedarktangent@defcon.social mentioned the concept of agency to me, I’ve not stopped thinking about how much modern technology asks us to relinquish control of our data.

I’ve never used music streaming services. I always disliked the idea of not owning my music. For me, the original iPod was the epitome of agency: mine to do with what I wanted, when I wanted.

With the relentless march of frontier models consuming as much of our data as possible, we need more agency today, not less. Control over who has access to our data. Control over when they have it. Control over what they are allowed to do with it.

Silicon Valley has given us some truly amazing inventions, but it has also welcomed some ugly things into our lives. Systems where we have very little control, very little ownership, and very little say.

That needs to change. Really looking forward to @defcon@defcon.social this year

48
5
26
1
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Don’t need a 16mm camera
Don’t need a 16mm
Don’t need a
Don’t need
Don’t

Hmmm. I mean…..

I do love the fact that we are seeing film stock being developed at the moment.

euphoria season 3 is shot on this and I can’t wait to watch it

5
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Now then, it's kinda known that the best watch in the world is a Casio F-91w (god-tier), fact, but surely this is screaming out to be a close hackable contender

https://www.casio.com/uk/watches/casio/product.F-B100W-1A/

Step tracker, Bluetooth sync and no charging cable? Oh hell yes

CR2016 and say no more.

Oh and hackable you bet. At that price point, this seems like a good winter exploration project with the kids here.

casio.com
5
1
2
1
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

Finally had a chance to shoot my CineStillFilm 800 and I’ve an ugly feeling it will be fogged TF thanks to minimum wage security idiots at the airport refusing a hand search

The security theatre at airports continues. Shoes off. Oh wait that watch looks dangerous. Oh no this film could be bad!!

4
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

RIP HELCH. Huge part of Londons graffiti scene.

Whilst there were many favs, the American carwash for me was the best.

https://drorhadadi.com/en/helch-graffiti-2/

drorhadadi.com
2
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

I'm blown away by what we have today. Take https://huggingface.co/Qwen/Qwen3-Embedding-0.6B which is just brilliant at taking output from RAPTOR and the datasets we create from our /understand (attack path, src, sink, dataflow, threat model etc) and then doing careful extraction, not crystal-ball nonsense. It’s capable enough to understand technical security language and follow a structured schema, but small enough to run properly on an 8GB M1 Mac mini.

I run it with temperature 0, an 8,192-token context and a tightly defined output schema, num_predict = 1400 which bounds the output.

The model has enough room for the structured labels but cannot wander into an enormous response or hallucinate as much in my experience.

Then, I use qwen3-embedding:0.6b to spot semantically related labels

Honestly this is such an exciting period for us, well at least me finding bugs 'n shit.

on the dinosaur front, we set about making a bloody solid sandbox and control/telemetry plane for RAPTOR: https://github.com/gadievron/raptor/issues/889

oh and it works really well from stopping it from eating your face.

huggingface.co
3
0
2
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

@xenogon@sunny.garden Oh im not expecting it to be done and dusted, but it is a step forward and a very positive one at that.

I'm sure apple and others have tried their hardest to make this not happen but I see positives in this attempt from the EU commissions

2
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 5mo ago

“We are going to crave more authentic in-person experiences as our online interactions are seemingly less authentic”

@thedarktangent@defcon.social utterly nailing it

20
2
7
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 2mo ago
Replying to
@thedarktangent@defcon.social oh it’s wild. We’ve almost got to the point where you need to do a physical assessment of the cars telemetry systems in order to block them, or at least find out where the hell they are at first That or we need an EDR or WAF for the cars. Heaven help us all
4
1
3
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

then today is very much a hardware hacking day, bear with me.

Some cool research by fellow Blackhat review board'r, Ben Nassi and Co

https://www.nassiben.com/video-based-crypta

Exploiting a Video Camera's Rolling Shutter to Recover Secret Keys from Devices Using Video Footage of Their Power LED

Then @AndrewMohawk@infosec.exchange spent time on @bunnie@social.treehouse.systems's badge

https://andrewmohawk.com/2026/08/16/dc34-badge-hackin/

nassiben.com
2
1
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 1mo ago

As AI creeps more and more into the creative arts, I love hearing what real artists are coming up with as a result

https://www.youtube.com/watch?v=jEfWTJzlMoY

Andre just builds this so well. You can almost imagine the smoke and the sweat and throbbing bodies dancing to this at 0300 and then it just goes on and on.

Here's to more like this

1
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 5mo ago

Day two of Black Hat and I got a chance to see my friend Ariel Herbert-Voss
do the keynote. It opened a floodgate of thoughts.

Oh and yay, GPT-5.5 is here and it feels like we’re entering another mad period of growth for frontier models and security research.

The big thing I’m seeing is that we need less scaffolding around these models. Give them code, context, a goal and some tools, and they are getting much better at cracking on.

That matters for bug hunting. A lot

But let’s not pretend the machines have solved vuln research. They haven’t.

The biggest gains are still at the shallow end.

Low severity bugs, obvious logic mistakes, unsafe patterns, missing checks, boring-but-real issues, that’s where models are starting to clean up. If the bug class is well documented and the code is clear, they move quickly.

The low-hanging fruit is getting hoovered up at pace. The easy stuff is becoming cheaper to find, well sorta cheaper.

We’re also seeing decent gains on modest bugs. Not deep chains. Not always novel research. But useful findings where the model can read, reason, trace, and join enough dots to help.

Where it still gets spicy is state.

Models can talk about state all day, but they don’t really feel it. They still struggle with temporal bugs, race conditions, lifecycle weirdness, multi-step flows, and those “only happens after you do these seven things in this exact order” bugs.

Spotting something dodgy is not the same as proving it is exploitable.

On the exploit side, validation, exploitability and reliability are improving, but more slowly. This is one of the big areas John and I have been working through with RAPTOR: getting away from “looks interesting, mate” towards “this is real, reachable, and repeatable”.

Because exploit reliability is still a graft. Targeting is still fragile. You still need iterations.

Oh and the human in the loop is still vital.

We all thought fuzzing would solve the bug problem. It didn’t. It changed the economics of bug discovery, but we still needed harnesses, triage, context, exploit dev, judgement, and all the boring engineering bits that make the work useful.

I think frontier models are having a similar moment.

The best results won’t come from throwing a giant model at a repo and hoping it finds magic. They’ll come from layered systems: frontier models for reasoning and code understanding, smaller focused models trained on private data, internal vuln history, remediation patterns, product context, validation loops, and humans who know when the model is chatting crap.

As models get better at writing code, they get better at breaking it. Capability doesn’t scale politely. It compounds.

Better tool use helps validation.

Better context helps reachability.

Better reasoning helps exploit chains.

But it still needs structure.

It still needs evidence.

It still needs humans who know what good looks like.

The shallow bugs are already getting compressed. The interesting bit is what comes next.

7
0
7
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 5mo ago
Replying to
@dpp @thedarktangent @defcon @wendynather @inkandswitch.com I’m sad to say I’m not, but I’m rectifying that now. Thank you very much.
1
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 5mo ago
Replying to
@Npars01@mstdn.social @thedarktangent@defcon.social I couldn’t agree more. I kind of actively look for companies now that don’t have chat bots.
1
0
0
0
Open post
Daniel Cuthbert @dcuthbert@defcon.social
· 35mo ago
Replying to
@homebrew @trailofbits @yossarian @openssf this is unbelievably cool and ToB continues to do the work we all need. Respect!!!
2
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:34:16 UTC