we really want to present heif heist as there's so many things to talk but unfortunately no conference date are aligning.
6
1
86
6,169
Harsh Jaiswal retweeted
heif heist? @HacktronAI moving exploitation base to san francisco hit us up, would love to meet people.
6
3
141
11,424
Harsh Jaiswal retweeted
do it once, call us lucky? what if we do it again? but for all of them?
17
10
273
20,258
Its so overr our team just coooookeddd so baddd
holllyyyyyyyyyyyyy fffffffffffffffffff
6
6
238
56,829
Dont be sleeping on Heif Heist! Meta paid 100k for my RCE on FB/Instagram! heif-heist.com/
110
210
4,964
530,703
Is this art?
5
1
242
37,236
Agree. At Hacktron we follow 30 days disclosure policy. here’s why: once a security-relevant fix is committed or released, motivated attackers can monitor commits, diff changes and reverse engineer with capable models to identify the fixed vulnerability and turn that into a working exploit. people who are least likely to be doing that are the defenders. without a clear public signal that an issue is serious sooner than later, those defenders may have little reason to prioritize an update. that is why I think the traditional 90 days long embargo model can become counterproductive after a fix is available. It can create a period where sophisticated attackers have enough information to investigate the patch, while a large portion of defenders remain unaware of the urgency. public disclosure changes that asymmetry, security teams can notice that and priortize fixes. Ive seen this directly in our other research. With the critical BeyondTrust issue we reported (beyondtrust.com/trust-center…), the vendor communicated the issue publicly and urgently, and in our own Internet-wide observations we watched the number of exposed affected deployments fall from thousands to the hundreds within a span of 2–3 days. Similarly, with Next.js, we reported the HEIF Heist issue and, immediately after remediation and release of patched versions, Vercel published a public advisory (vercel.com/changelog/nextjs-…) explicitly warning users about a critical vulnerability in AVIF image optimization and telling self-hosted users to upgrade. I believe that making the risk visible and get systems patched quickly, not saying go and drop the full exploit, but dont rely on the assumption that attackers will not be able to reverse engineer and exploit during a prolonged quiet period. this is what we followed with our Discourse disclosure tho we didnt release the exploit to not make it obvious for everyone.
Frontier models have lowered the bar for discovering and exploiting vulnerabilities. This has resulted in an increase of CVEs and workload for both SWE and vulnerability management teams. And yet the norms around coordinated vulnerability disclosure timelines have remained around 90 days. This timeline worked 10 years ago, but is unlikely to survive much longer. We need to move closer to a window of 30 days. But in order to do this we need to rely on those same models to accurately fix those vulnerabilities and coordinate the release and deployment of new versions. The primary blocker here seems to be confidence in those models to do that job well, and reluctance to remove humans from that loop. Every day the probability of another shellshock, log4j, or heartbleed rises. If you were in the trenches for those events then you know how difficult it was to track vulnerable assets, test and deploy patches, and ensure the risk was mitigated. We shouldn’t wait for a crisis like this to rethink and change these norms. We need to move much faster and that requires shorter disclosure timelines, and removing humans from the vulnerability management loop.
5
4
45
11,253
This is the email we sent to Discourse CEO before our blog. Hard agree that 90 days should not be standard anymore.
Frontier models have lowered the bar for discovering and exploiting vulnerabilities. This has resulted in an increase of CVEs and workload for both SWE and vulnerability management teams. And yet the norms around coordinated vulnerability disclosure timelines have remained around 90 days. This timeline worked 10 years ago, but is unlikely to survive much longer. We need to move closer to a window of 30 days. But in order to do this we need to rely on those same models to accurately fix those vulnerabilities and coordinate the release and deployment of new versions. The primary blocker here seems to be confidence in those models to do that job well, and reluctance to remove humans from that loop. Every day the probability of another shellshock, log4j, or heartbleed rises. If you were in the trenches for those events then you know how difficult it was to track vulnerable assets, test and deploy patches, and ensure the risk was mitigated. We shouldn’t wait for a crisis like this to rethink and change these norms. We need to move much faster and that requires shorter disclosure timelines, and removing humans from the vulnerability management loop.
3
57
12,825
It sucks that the security community’s frontier moves slower than the developer frontier. New models CVP/TAC access often comes months later and we can't even benchmark properly.
3
2
79
9,550
This will be a fun story ;)
our next “on M, DD, YYYY” drop, from two of the random guys, is probably the most impactful bug we’ve ever found. i mean wouldn't be that easy, but there is potential for backdooring half the internet.
2
15
4,778
RT @S1r1u5_: our next “on M, DD, YYYY” drop, from two of the random guys, is probably the most impactful bug we’ve ever found. i mean woul…
1
186
Made claude viral last week but still no CVP for me. rip. Can someone please help here?
19
4
128
22,644
now you know why you shouldn't engage with everyone on the internet 🤦‍♂️ . also, posting this screenshot without approval is probably against Meta program rules.
Replying to @S1r1u5_
For the record, I'm doing VDPs and got the scars to prove it. e.g. Meta's VDP
4
63
14,019
Come work with us!
3 random dudes looking to expand the team. please reach out. requirement, make sure your random research mogs whatever we’ve done below.
1
4
81
10,317
Harsh Jaiswal retweeted
This is unpopular but correct. AI labs have gotten spoiled by super chill responses to CFAA violations and the whole edifice is a house of cards. Wanna know why Hugging Face didn't sue OpenAI? Google “new DOJ policy CFAA” and thank the hacker community fighting for this.
3
46
8,649
This is unpopular but correct. AI labs have gotten spoiled by super chill responses to CFAA violations and the whole edifice is a house of cards. Wanna know why Hugging Face didn't sue OpenAI? Google “new DOJ policy CFAA” and thank the hacker community fighting for this.
This is unpopular but correct. Modern bug bounty participants have gotten spoiled by super chill responses to CFAA violations (like this one) and the whole edifice is a house of cards. Wanna know why OpenAI asked for detailed logs? Google “Sullivan + Misprision of a Felony”
1
14
201
26,054
Harsh Jaiswal retweeted
it’s incredibly sad that you interpret this as asking for ransom like we are some poor beggars. is that how you look down on everyone? fwiw, i rather want my research to go out and read by peers than getting shut up by 100k bounty for a cool bug like the openai one.
mutual disclosure policy is decadent and against the spirit of hacker culture. essentially a puppet to vendor, they can treat you like shit and you won't be able to disclose even a ounce of the detail. fuck bounties and shitty disclosure policies on h1/bc and drop bugs to security@ with p0 disclosure policy. win-win either way and you are in control of your research and sweat, if shit goes south -- name and shame. > This bug is subject to a 90 day disclosure deadline. If a fix for this issue is made available to users before the end of the 90-day deadline, this bug report will become public 30 days after the fix was made available. Otherwise, this bug report will become public at the deadline. More details on the policy: htxps://about.google/company-info/appsecurity/.
1
1
30
3,225