Jameson Lopp's avatar
Jameson Lopp
lopp@lopp.net
npub17u5d...t4tp
Insights on security, privacy, technology, & money · Casa Co-founder & Chief Security Officer · https://bitcoin.page
Jameson Lopp's avatar
Jameson Lopp 1 week ago
After 10 rounds of training just on the coldcard entropy vulnerability, it's rather amusing how the training clanker is getting frustrated with how retarded the pentest clanker is and how it keeps making inexcusable mistakes. 🫠 This might take a while... View quoted note →
Jameson Lopp's avatar
Jameson Lopp 1 week ago
How to train your clanker? Building a generic pentest harness seems far more difficult than building one for a specific codebase because it requires an additional layer of context building in order to formulate a plan of attack. I'm trying something new now, which is feeding a corpus of recently found vulnerabilities in open source codebases to a training clanker that then runs the pentest clanker without giving it any hints, and then the training clanker analyzes the output of the pentest and tries to work backwards to figure out why the vulnerability wasn't found so that it can improve the pentest harness in a generic fashion.
Jameson Lopp's avatar
Jameson Lopp 1 week ago
This is my life now. Obsessed with automating & optimizing pentesting. image
Jameson Lopp's avatar
Jameson Lopp 2 weeks ago
If you rob a bank, you’re a criminal. If the bank robs you, it’s finance. If everyone robs each other, it’s crypto.
Jameson Lopp's avatar
Jameson Lopp 3 weeks ago
Never trust an incoming message on any platform.
↑