Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
moyix
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
Breaking Crypto with XBOW
(xbow.com)
1 points
by
moyix
2y ago
|
0 comments
32.
▲
AI Agent Exploiting and Debugging a Jenkins RCE
(threadreaderapp.com)
2 points
by
moyix
2y ago
|
0 comments
33.
▲
by
moyix
2y ago
syscall is only available if gdb is able to resolve libc. So for example this won’t work to stop a process running in a container, since gdb won’t be able to see the libc in the container’s filesystem. I did make my own variant using gdb, t
34.
▲
by
moyix
3y ago
Yes, that's a limitation of trying to ensure exact binary reconstruction. Luckily there is also a separate line of work on detecting the compiler version and optimization flags based on a binary – it turns out this is not that hard a
35.
▲
by
moyix
3y ago
They're actually orthogonal approaches – from what I've seen so far the LLM fuzzer generates much higher quality seeds than you'd get even after fuzzing for a while (in the case of the VRML target, even if you start with so
36.
▲
by
moyix
3y ago
I don't think using a language model to generate inputs directly is ever going to be as efficient as writing a little bit of code to do the generation; it's really hard to beat an input generator that can craft thousands of inpu
37.
▲
by
moyix
3y ago
The original test of the GIF parser does, but the VRML parser less so and the completely novel packet parser even less so. I'm not quite sure what you mean by the scope of the "unknown" format being limited – it's not th
38.
▲
by
moyix
3y ago
Yes – it's a bit hard to follow the various branches of the thread on Twitter (I wasn't really intending this to be more than a 30 minute "hey that's neat" kind of experiment, but people kept suggesting new and inte
39.
▲
Using LLMs to Generate Fuzzers
(verse.systems)
156 points
by
moyix
3y ago
|
28 comments
40.
▲
by
moyix
3y ago
Worth noting that you can use "invisible text" to give instructions to LLMs without it showing up in the chat box. So all you have to do is get someone to copy/paste one of those messages into their chat, and there are lots o
41.
▲
by
moyix
3y ago
The theorem that proves this is the PCP Theorem, in case anyone wants to read more about it: https://en.wikipedia.org/wiki/PCP_theorem#PCP_and_hardness_o...
42.
▲
by
moyix
3y ago
Seems to be contradicted by this paper, no? https://arxiv.org/abs/2207.05221
43.
▲
by
moyix
3y ago
Atuin is lovely, although I found some of its defaults pretty annoying until I changed them: - It turns out I basically never want fuzzy search through my command history, and certainly not by default. I gave it a try for a couple weeks but
44.
▲
by
moyix
3y ago
Not free, but I have used 010 Editor for years and it's excellent.
45.
▲
by
moyix
3y ago
The startup time mentioned is actually a big deal for me – I do record all of my terminal sessions (I even wrote a tool that uses his avt library to grep through the terminal logs, although I never got around to making it fast enough to be
46.
▲
by
moyix
3y ago
In theory this is what CVSS scores were supposed to fix, but a lot of the "does this vulnerability really matter" evaluation ultimately depends on the details of your environment and application :(
47.
▲
by
moyix
3y ago
It's a bit debatable whether this is a security bug vs a "you're holding it wrong" kind of bug, but fixing the bounds check is a good defensive practice and I'm glad they implemented it. Somewhat tangentially, Micro
48.
▲
by
moyix
3y ago
Tried it. Slow, uses lots of memory.
49.
▲
by
moyix
3y ago
It's the default, which means it has a lot of people use it. And IME the alternatives on mac aren't very good.
50.
▲
by
moyix
3y ago
My guess is that widespread 24-bit support in terminal apps is still held back by the fact that the macOS terminal still doesn't support it. As far as I can tell nearly everything else does :(
51.
▲
by
moyix
3y ago
AlphaCodium is more of a prompt engineering / flow engineering strategy, so it can be used with existing models.
52.
▲
by
moyix
3y ago
You can run it on a Macbook M1/M2 with 64GB of RAM.
53.
▲
by
moyix
3y ago
My Macbook has a mere 64GB and that's plenty to run 70B models at 4-bit :) LM Studio is very nice for this.
54.
▲
by
moyix
3y ago
Are you trying to get at the distinction between second preimage and collision resistance? If all you need is a collision, "try random pairs until you find a collision" method works fine and is arbitrarily parallelizable with no s
55.
▲
by
moyix
3y ago
I don't think that's correct? It's probabilistic, yes, but in expectation you would still need ~2^64 hashes to find a collision for a 128-bit hash (birthday paradox).
56.
▲
by
moyix
3y ago
You can generate pairs of hashes for random inputs and check for collision without storing all of the outputs, no?
57.
▲
by
moyix
3y ago
Since that post was published, the 4090 came out, which can (according to this hashcat benchmark [1]) do 50,638.7 million SHA1 hashes per second, so now it would only take a single 4090 GPU 11.55 years. Or you could buy 12 of them and do it
58.
▲
by
moyix
3y ago
Unfortunately the site doesn't seem to cover cordless blinds? In New York they're voluntarily phasing out corded blinds because of safety issues with small children, but the cordless blinds we have are terrible and unreliable.
59.
▲
by
moyix
3y ago
At least they used HumanEval+, which adds a bunch more test cases and fixes some errors in the original benchmark!
60.
▲
by
moyix
3y ago
As one safety measure, compiling with -DFORTIFY_SOURCE > 0 will enable checks on the FD_SET etc macros: https://github.com/bminor/glibc/commit/a0f33f996f7986dbf3763... The kernel side interface probably wo
More ›