Viss,
@Viss@mastodon.social avatar

every time i see a headline about how some org is "using ai to revolutionize redteaming" or like "ai is gonna force multiply security" i think of these sort of examples - and i think its gonna move things backwards in a surprising way. dont quit your dayjobs, security nerds - we're gonna be unrolling this stuff for years

Viss,
@Viss@mastodon.social avatar

for clarity: Im not against ai. i use it to help me write (bad) python and i have it help me with narrowly scoped things.

the catch is you have to have SOME LEVEL OF COMPETENCY in the thing you want help with.

if you think you can just fuckin yolo it, lie on your resume, and google/ai your way into a complex technical job passing off ai output as "your job" youre likely going to get people killed.

use ai for what its good at.
30 line python scripts. ffmpeg syntax.

rye,
@rye@ioc.exchange avatar

@Viss it can be good to also encapsulate and find patterns.

Viss,
@Viss@mastodon.social avatar

@rye its good at narrow, singular things at the moment.

asking it to think like a person and like "reason" is a bad idea, because it'll fuck it up, like my screenshot example above.

assuming it thinks like a person (it doesnt think or reason at all) is a mistake, and asking it questions like you'd ask a person is a mistake.

you have to ask it like its autocomplete (which it basically is)

once you wrap your head around that, it becomes more useful

hrbrmstr,
@hrbrmstr@mastodon.social avatar

@Viss oh it 110% made/makes ffmpev/avconv actually usable, now.

Viss,
@Viss@mastodon.social avatar

@hrbrmstr dude it has greatly improved my gif game.

now its:
rando video or mp4/webp -> losslesscut for snipping -> a shellscript augmented with edits from gpt that keeps the gif at the highest possible quality/framerate and keeps it under 10 megs ::: if im on my linux box.

if im on my mac, i just use gifbrewery3, which i wish i could use on ubuntu

Viss,
@Viss@mastodon.social avatar

i used it recently on a gig to write a bunch of powershell to basically tear out specific narrow functions of what bloodhound does to ask a fleet of windows boxes for info. it was pretty good at that - it took 5 iterations to get the syntax right, but it got there.

asking ai to 'redteam for you' is gonna end up having black helicopters come to your house.

and if it doesnt - then it should.

mastobit,
@mastobit@awscommunity.social avatar

@Viss Yep. It's only a tool, and not every tool in the toolbox.

Viss,
@Viss@mastodon.social avatar

@mastobit i read this the other day on crankysec and it should be fucking cast in bronze and hung in every security department:

nf3xn,
@nf3xn@mastodon.social avatar

@Viss We went from "omg it can code!" to "please do my whole ass job" very quickly lol.

Viss,
@Viss@mastodon.social avatar

@nf3xn yup. so the layoffs arent over. leadership is gonna keep finding people who are ai-yolo'ing it and trebucheting them into the sun.

Jplonie,
@Jplonie@aus.social avatar

@Viss so just to be clear getting people killed doesn't impact my bonus?

Viss,
@Viss@mastodon.social avatar

@Jplonie not so long as you got that sweet sweet golden parachute clause in your executive contract! or any language in there that says they cant fire you for any reason before a certain time

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • JUstTest
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • megavids
  • provamag3
  • tester
  • lostlight
  • All magazines