Casey Ellis
Security is an afterthought, and that's economics
There are some black pill truths around security (the "nothing's ever going to change" kind) that need to be reconciled.
I can just do stuff
Personally, I'm hacking on stuff again. With AI in the toolkit it feels kind of like the early 2000s in some ways:
The law matters less than the legal team
I'm not a lawyer, and if I was, I'm not your lawyer. With anti-hacking laws there's a
The hackers weren't lying
A lot of what's actually happening right now is people realizing that, no, the hackers weren't lying this whole time.
Fixing everything is a fool's errand
Vulnerability management is a bit of a fool's errand if your goal is to make sure that everything's fixed. We&
Root is the product
For those of us on offense, root (full control of the target) is the product. If we're just doing pure offense, that&
We think like that because we're like that
People in security greatly overestimate the ability and the propensity for people to think like bad guys in the way that we do. We
Don't be the tooling, build the tooling: [un]prompted.au talk
Slides from my [un]prompted.au talk on using AI to build deterministic tooling, with lookup.disclose.io as the worked example.
You don't kill a bug by finding it
I've never really believed that you just kill a bug by finding it. This is the guy who started Bugcrowd, so I
AI and bug bounties: notes from 68 minutes on Across the Pondcast
68 minutes with Tib3rius and Andy Swift on Across the Pondcast, cut down to the salient points and timestamped: how Bugcrowd started, what AI has actually done to bug bounty, why a VDP is the sane fallback, and where researchers should point next.
A convict colony thing
Australia has always punched above its weight from an offensive security standpoint. I think it's a convict colony thing that just shows
A lot of people are just sitting on zero-day right now
I sat down with Ashish Rajan on the AI Security Podcast after Black Hat. The bit worth writing down: the triage queues are noisy enough that good researchers are sitting on zero-day. Plus export controls, attack graphs, port 3000, and why leaders should go use this stuff at home.