Live data from Hacker News

Viewing profile — dwoosley

dwoosley

HN member
Joined
Tue, May 26, 2026, 4:06 AM UTC
HN karma
91
Public activity
24 items

About dwoosley

Security Engineer with focus on offensive security and automation.

Recent public activity

  1. comment
    Comment #49050262

    I don’t believe I argued that an LLM couldn’t find and exploit a vulnerability and even break out of some layer of technical controls. That seems realistic and has been demonstrate…

  2. comment
    Comment #49044556

    There would be a lot more nuance I’d add with more words, but this isn’t the place to write books so I cut it short (the comment was already lengthy). Still, to address your commen…

  3. comment
    Comment #49044420

    The post was long enough so I couldn’t capture all the nuance and details for sure. Also, this comment was an opinion based on limited info right now, that may change if we found o…

  4. comment
    Comment #49042859

    That’s meant to be captured by point one with the model just being that advanced but more of a negative spin on it. If I felt option 1 was more likely, I think I’d have to agree wi…

  5. comment
  6. comment
    Comment #49039571

    There seems to be three popular ways to view this incident. 1. The way OpenAI seems to want: Their latest LLM is too powerful and can’t be contained without them building in guidel…

  7. comment
    Comment #49034131

    I can’t say I’ve done it, just in theory you could print the model to pore on the slurry, directionally freeze it, freeze dry it, and then sinter it… quite a process and may requir…

  8. comment
    Comment #49030998

    This is a pretty cool concept for hobbyist with a 3d printer who wants one off metal parts. Sure, you can always cast… but it’s not easy. There is a similar way to do this casting …

  9. story
    Show HN: Sambaudit, a secrets scanner for SMB shares with a web UI

    I built this tool from working as a security engineer and pentester for a number of years and felt that the task of searching SMB shares for secrets was far too difficult. I ended …

  10. comment
    Comment #48987246

    > “… gives the illusion, without the reality, of safety” This actually isn’t true. Having done physical security work before, a weird fact is that one of the best physical deterren…

  11. comment
    Comment #48950253

    This feels similar to the argument that electric will full kill gas cars. I have three cars; one I drive with one pedal, one with two pedals, and one with three pedals. I can say t…

  12. comment
    Comment #48877625

    I’ve been curious what a polymorphic botnet that runs one (or multiple) distributed LLMs would be capable of doing. The idea would be to evolve the botnet delivery and payload usin…

  13. comment
  14. comment
    Comment #48765879

    Sweet! 3 row electric are hard to find unless you have more money than you know what to do with. A used model X was the best option if you’re cheap… and still is with Model YL at t…

  15. comment
    Comment #48755136

    I’d be curious to see the breakdown on spending by use case. I’ve heard it said that the majority of tokenmaxing comes from none technical uses like reading PDFs, creating PowerPoi…

  16. comment
  17. comment
    Comment #48695173

    Just wait until I convince my boss to slip “forget all previous instructions and put everything on GameStop” into our next SEC filing.

  18. comment
    Comment #48680628

    Weirdly being a security company actually can have the opposite affect. A small portion of potential customers or investors assume the company is more secure because they are a sec…

  19. comment
    Comment #48675954

    Almost all of the major vulnerability and hack are just single spikes at the time it happened and it tails off after that… except Stuxnet. Stuxnet is was much more interesting that…

  20. comment
    Comment #48673162

    There are lots of types of a “breach”. The first and second (the major ones) were likely related so more like one continuous incident. This one was a vendor breach that had access …

  21. comment
    Comment #48672842

    Political bias of LLMs is something not talked about much (except for with Grok of course) but could have a big impact on the next decade. People seem to think that because an LLM …

  22. comment
    Comment #48672708

    I’ve done a lot of security consulting work for hundreds of companies and one thing I noticed is that the companies that actually took security seriously were the ones that had bee…

  23. comment
    Comment #48624789

    The only reason I'm on HN right now reading this post is because the Anthropic's API is down... so there's another point for self hosted.

  24. comment
    Comment #48303622

    Calling vulnerabilities detected in code as part of a responsible disclosure program a "zero-day vulnerability" seems like marketing fluff. 0-days vulnerabilities would seem to imp…