Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mike Siegel

@mikesiegel@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I do various offsec stuff.

103 Followers
189 Following
50 Posts
Joined November 07, 2022
Github:
https://github.com/mikesiegel
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social TBF aligning anything in Word is challenging.
36
0
5
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

They’re always watching.

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

Why is it always Vegas in August. How about Iceland in February? It’s inconsiderate to the frost-borne.

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

Everyone said Neuromancer has aged poorly because Case was trying to fence 3 megs of RAM.

But if current trends continue 3 MB of RAM will cost 17 million dollars by 2035.

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange holy shit they stole Apple designs for this? I thought it was going to be like an inference buttplug that opines on your colon health or at least something more interesting.
2
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

Next level OPSEC: Purchase your Framework laptop using your consulting company and then shut down the company and all associated accounts because you weren't making any money.

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@GossiTheDog he makes a good point about the subsidized cost. It's like in the early days when Uber was cheap AF to put the taxis out of business. Once they had market share, they cost as much as taxis.
6
0
1
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 6mo ago
Replying to
@invadersil
5
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 3mo ago
Replying to
@vga256@mastodon.tomodori.net I love the old hypercard games. Have you seen https://archive.org/details/mac_Zen_the_Art_of_Macintosh1986 ? It's full of 1-bit pixel art done on an early Mac.
Internet Archive

Zen & the art of the Macintosh : discoveries on the path to computer enlightment : Green, Michael, 1943- : Free Download, Borrow, and Streaming : Internet Archive

Zen & the Art of Macintosh1986

1
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

To all my Californian friends, make sure you have the appropriate clothing https://kmph.com/news/local/california-leaders-report-four-to-six-weeks-worth-of-gasoline-and-diesel-in-supply

California leaders report four to six weeks worth of gasoline and diesel in supply
KMPH

California leaders report four to six weeks worth of gasoline and diesel in supply

Californians are facing growing uncertainty at the pump after the state’s last major oil shipment from the Strait of Hormuz arrived in Long Beach on Monday, as

2
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

The severity of the vuln is proportional to the cuteness of the profile pic posting the PoC.

E.g. Guy Fawkes mask and hoodie? Probably weak ass slop. Tiny cute anime bunny? Oh fuck.

2
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 3mo ago
Replying to
@mttaggart@infosec.exchange
1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

It was the best of times, it was the worst of times (in offsec)

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

This would be super useful on red team engagements if anyone actually used Edge to do anything other than download Chrome. https://lemmy.world/post/46435614

lemmy.world

Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them; Microsoft will not fix, says the behavior is "by design" - Lemmy.World

Hacker News [https://news.ycombinator.com/item?id=48012735]. > When you save passwords in Edge, the browser decrypts every credential at startup and keeps them resident in process memory. This happens even if you never visit a site that uses those credentials. > > At the same time, Edge requires you to re‑authenticate before showing those same passwords in the Password Manager UI — yet the browser process already has them all in plaintext. > > Edge is the only Chromium‑based browser I’ve tested

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

My take on the motivation for the 313 Team Attacks: They're rabid Arch Linux fans.

1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@GossiTheDog this is exactly what happens when internal Hackathons run amok. I would bet $5 on it.
1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@0xabad1dea how long did it take you to learn Classical Chinese, and did you start out knowing Mandarin already?
1
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@sibrosan @kenshirriff this is a very old model, but there are more recent celestial navigation systems: https://prod-edam.honeywell.com/content/dam/honeywell-edam/aero/en-us/products/navigation-and-sensors/navigation-systems/celestial-aided-navigation/documents/hon-aero-celestial-aided-navigation-brochure-1493615-n61-3148-000-000.pdf?download=false
prod-edam.honeywell.com
1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 6mo ago
Replying to
@overholt@glammr.us
1
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@kenshirriff I was wondering if satellite constellations fucks this up? I think these are still in use and given a dooms day scenario, it's likely anti-SAT weapons will be used and GPS may be jammed or useless.
0
2
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

https://www.redwoodresearch.org/research/hugging-face-incident far more details than what OpenAI released.

redwoodresearch.org

Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident | Redwood Research

Two METR staff members and Redwood Research’s Chief Scientist investigated an incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned message board.

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

https://collusion.wiki/

collusion.wiki
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 3mo ago
Replying to
@bagder@mastodon.social Enjoy your much deserved rest!
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 6mo ago
Replying to
@abrignoni@infosec.exchange look at the bright side, at least it can't go out in the field and dupe disks with a write blocker. If people still do that? Or do they just use Encase agents? IDK I haven't done IR in a decade.
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Oh shit he was right
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Open Weights and American AI Leadership
Microsoft Corporate Responsibility

Open Weights and American AI Leadership

Open weight AI can expand access, strengthen competition, improve security, and help sustain American AI leadership.

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social while they can certainly find some fun things, a number of the "vulns" are ridiculous "Oh this can be an RCE during full moons with ASLR disabled running on TRSDOS ported to ARM." The models don't really threat model well at all. I like @bagder@mastodon.social 's approach of VULN-DISCLOSURE-POLICY.md
0
0
1
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 6mo ago
Replying to
@brauner I don't think this accounts for the user being born during a leap second, or having undergone relativistic time dilation.
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange alternate theory: an OpenAI exec called open weight models communist last week. HuggingFace is the main repo for open weight models, and essentially a competitor given they will host Kimi/GLM for you.
0
2
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

I should probably go back to Debian TBH

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Every day we stray further from dog's light.
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social I can imagine a scenario where I have a junior employee,who has never used the cloud. I tell them to just spin up some toy experiments using terraform and AWS. Sure, spend $100. Great, you learned something. You'll be able to help me do actual work. But it would be bat shit insane to continue this behavior for 6+ months and then make a leader-board or KPIs based on AWS spend.
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social
0
2
2
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

The Truth? YOU CAN'T HANDLE THE TRUTH

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@gadi@infosec.exchange I am confused. Things you helped write like Raptor and OpenAnt do things like check for memory safety mechanisms, because the models will pretend they don't exist and find things aren't exploitable. A lot. If I need to deterministically tell a model if a binary is compiled with NX or PIE why would I want to try to prompt that instead of write a harness to help that? Why would I want that to eat up the context window and tokens each time, and get a non-deterministic response to something like that?
0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 3mo ago
Replying to
@tinker@infosec.exchange I think that day is already here, just not evenly distributed (and quite expensive!) https://limitedrungames.com/collections/all/products/earnest-evans-collectors-edition-genesis
limitedrungames.com
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2w ago

I can have your model hack shit for much cheaper than whatever Irregular is charging.

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago

Also why must Vegas hotel rooms be devoid of coffee makers? Forcing me to go outside and interact with humans prior to coffee is just wrong

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@metacurity@infosec.exchange I think is just a rehash of April? https://breachnews.com/breaches/shinyhunters-claims-sale-of-anthropic-claude-mythos-ai-model-data-and-internal-documents/
ShinyHunters Claims Sale of Anthropic Claude Mythos AI Model Data and Internal Documents
BreachNews

ShinyHunters Claims Sale of Anthropic Claude Mythos AI Model Data and Internal Documents

ShinyHunters claims sale of Anthropic Claude Mythos AI model data, including internal documents and alleged system access.

0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 1mo ago
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange At least in the US there was a proposed rule by the FCC. But I think it's still sitting in 'proposed' and would apply to prepaid phones as well: https://www.federalregister.gov/documents/2026/05/26/2026-10407/enhancing-know-your-customer-requirements#p-19 The "match" your name thing is fun for people named Mike and Will I imagine. Anecdotally, I've heard of folks having issues with LinkedIn verification when they are named Mike, Will, Rob etc.
federalregister.gov
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago

I think one of the big asymmetries here is: If you lock 1000 agents in a box with only way out, they only need to be right once to succeed. All the hallucinations are peeled away by contact with reality.

I'm not sure the same can be said for the defensive side.

Time will tell.

https://www.youtube.com/watch?v=87DyyMV0kCY

0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
The behavior described is so common anyone who evals a LLM or harness knows about it. It's called Reward Hacking. There's an entire section in the Mythos System Card about it. They monkey-paw their way to pass the test.
0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
Replying to
@PogoWasRight is it common among ransomware groups to do this to each other? What if your data is being held for ransom and your ransom gets ransomed? Do you think there is a future in a ransomware-gang HBO show where two young script kiddies are star-crossed lovers?
0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago

When I was a wee lad, back in the 1900s, I used to MUD. It was unusual for someone who was 13 or so to have a shell account, but I had one.

As a result, I was basically one of the few children on MUDs that were largely full of college students or other adults. They were some of the first people who taught me how to program (an Objective C based language) and became good friends with a number of them. I didn't really know many folks inrl who were giant computer nerds, so it became an important social space for me (as well as a good place to kill dragons).

But like most things from ye' old internet this is going away. What worries me particularly is that this is not limited to commercial entities. Instead, what's left of non-profit, player content-sourced gaming will end up vanishing because it will lumped in with 'social media'. You want to make a new MUD? Too bad, its illegal unless you pay Persona $30k a year or some shit.

It might get to the point where @jerry@infosec.exchange has to ban people from New York.

https://www.nysenate.gov/legislation/bills/2025/S4609/amendment/original

nysenate.gov
0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
Replying to
@Viss@mastodon.social there are also dongles you can buy to spoof EDID data. Search for 'EDID Emulator'. To automagically pull down the driver you'd probably need to pass WHQL testing though?
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 4mo ago
Replying to
@GossiTheDog@cyberplace.social I mean they already do key escrow if you link to a MSFT account right? So seems sloppy for an intentional backdoor.
0
0
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 5mo ago
0
1
0
0
Open post
Mike Siegel @mikesiegel@infosec.exchange
· 2mo ago
At least the smoke is shielding us from the worst of the heat. That's probably what the dinosaurs said.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:14:43 UTC