defparam's profile picture. Opinions are my own

d3fp4r4m

@defparam

Opinions are my own

Google could literally give 50ms of dark pattern money to ffmpeg (like incognito mode) without even feeling it and have the project funded for the next 200 years and probably should given, well, Youtube.


d3fp4r4m reposted

had some decent homies affected by the amzn layoffs any seceng sde or tpm roles you need to fill and want people that don’t suck reply to thread i’ll feed you souls


d3fp4r4m reposted

nothing has cured me of so many anxiounesses of life like marriage + kids. I get to truly feel alive because life is no longer about what i want, but about the very real needs of people who depend on me that i love with a love i did not believe i was capable of

i have... - an amazing girlfriend - making ~$450k this year - can work anywhere / anytime - live in a house w/ a pool yet i have anxiety every damn day, tight chest, hard to take a deep breaths, intrusive thoughts, always feeling not enough, can never relax what went wrong



d3fp4r4m reposted

Bucharest drivers see you putting on your seat belt and take it as a personal insult


This one resonated hard

ChatGPT5 is so useless now



I also feel that engineering tools with a scripting ability (like Python in IDA) is much more powerful if you just create a CLI tool to pipe the interpreter directly to the model rather than attempt to abstract (and constrain) every action into an MCP tool


d3fp4r4m reposted

Actually an project interesting idea would be an MCP to Cli tool converter for all programatic API use cases (not just LLM)


d3fp4r4m reposted

I don't understand mcp. Is there anything mcp can do that a cli tool can't do better?


d3fp4r4m reposted

📢 Time for an update on my workflow. This one's a 23 min read, so buckle up. 100% organic and hand-written, like an animal. steipete.me/posts/just-tal…


I’m kind of sick of ChatGPT 5 complimenting my questions, do we really need to waste the output tokens for the sake of flattery?


d3fp4r4m reposted

Wrote a blogpost today about getting Lucid fuzzing on a "real" target, all of the work that it took and the changes we made along the way. Next, we'll take a more earnest bug-finding approach and conduct a serious fuzzing campaign with Lucid: h0mbre.github.io/Lucid_Dreams_1/


FalseCrashReducer - LLMs being used to generate constraints and and analyze crash feasibility for LLM-generated bottom-up fuzz drivers in OSS-Fuzz-Gen. arxiv.org/pdf/2510.02185…


d3fp4r4m reposted

Lucid is alive! it's fuzzing its first real target and found it's first 0day already, an 00B read. had to patch it to keep fuzzing. this + some modifications is going to be blog post 1 in a series about iterating on the fuzzer until it's vastly improved.

h0mbre_'s tweet image. Lucid is alive! it's fuzzing its first real target and found it's first 0day already, an 00B read. had to patch it to keep fuzzing. this + some modifications is going to be blog post 1 in a series about iterating on the fuzzer until it's vastly improved.

Between pwn2own, bug bounty and countless amount of sec eng hours invested in securing the web browser, meticulously locking down APIs and other client side exploits just to have product designers slap in an AI subsystem without a proper security review 😂 🍿


d3fp4r4m reposted

If you are gonna use H1 as a marketing platform and hint about ”use use instead of humans! just look at out stats” I would please ask of you to start releasing the cost of running this tool. It starts to feel like you are eroding the trust of researchers on these platforms


d3fp4r4m reposted

Even mature products hide critical flaws – and @XBOW just found another one. CVE-2025-49493: XXE in Akamai CloudTest discovered during our climb to #1 on HackerOne. A complete technical breakdown from an error-based detection to a full exfiltration by @djurado9

Xbow's tweet image. Even mature products hide critical flaws – and @XBOW just found another one.

CVE-2025-49493: XXE in Akamai CloudTest discovered during our climb to #1 on HackerOne. 

A complete technical breakdown from an error-based detection to a full exfiltration by @djurado9…

Loading...

Something went wrong.


Something went wrong.