Post B5p1kmsPcnt7KViafo by malwaretech@infosec.exchange
 (DIR) More posts by malwaretech@infosec.exchange
 (DIR) Post #B5p1kmsPcnt7KViafo by malwaretech@infosec.exchange
       5 likes, 1 repeats
       
       Listening to cybersecurity people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.
       
 (DIR) Post #B5p2RuJRqylQqPvQQ4 by sancla@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech I don’t care, if this puts security back on the agenda, I’ll take it…
       
 (DIR) Post #B5p2wZAIWtzAEXGSa8 by adrian@mastodon.design
       0 likes, 0 repeats
       
       @malwaretech Not to mention that this isn't new...LLMs have been able to do this since day one. And small models found the same vulnerabilities in FreeBSD ¯\_(ツ)_/¯Also, from what I understand Mythos couldn't actually make an exploit for that bug, sooooooo big marketing stink imho.
       
 (DIR) Post #B5p4KhJTzEGcPOdCHA by gsuberland@chaos.social
       0 likes, 0 repeats
       
       @malwaretech now now, don't be raggin' on my local water treatment plant, they're much more up to date than that. they run Windows Vista.
       
 (DIR) Post #B5p4QNnnRPfRdLWNOa by ozu@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech I truly don't understand it. CISOs and managers are jizzing themselves from snake oil is not new but form technical people I'd expect more.
       
 (DIR) Post #B5p5X2C4HNvIb5br6m by nav@mstdn.social
       0 likes, 0 repeats
       
       @malwaretech I think you underestimate how ancient some of us are. I'm definitely older than anything my mobile provider owns, cos I'm older than the industry.
       
 (DIR) Post #B5p5uEgbzwn20ExYMS by lemgandi@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech "Using encryption on the Internet is the equivalent of arranging an armored car to deliver credit card information from someone living in a cardboard box to someone living on a park bench"(Gene Spafford)
       
 (DIR) Post #B5p6OWFFHQm39CbDRA by snowyfox@deadinsi.de
       0 likes, 1 repeats
       
       .
       
 (DIR) Post #B5p70Jd0dYx71OjmGe by guigsy@mstdn.social
       0 likes, 0 repeats
       
       @malwaretech I work in a large company that was hacked last year. Many modern systems were compromised. The RS6000 box and several of our ancient mainframes were untouched and weren't even turned off during the lockdown or recovery. Gave them a quick once over and they kept ticking like it was 1999.
       
 (DIR) Post #B5p7j0A5rLIng9WJPM by rrb@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech I think it would be kinda cool.
       
 (DIR) Post #B5p8zELoyKT6H0JA2K by simonzerafa@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech Well only hijack / hack mobile connection when it's really necessary like when your princess has escaped and you want to kidnap her back.
       
 (DIR) Post #B5pBPLnG7hTMnFizRI by Wouter@maly.io
       0 likes, 0 repeats
       
       @malwaretech excellent point. A lot of infrastructure runs outdated software. But thankfully, most of these systems are not connected to the internet.
       
 (DIR) Post #B5pCEGLm7YK2gE97Oy by T2R@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech The Internet being held together by string and bubble gum is not far from the truth.
       
 (DIR) Post #B5pCKN5E05HLIeJkiu by NineStonesClose@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech so true
       
 (DIR) Post #B5pERdpiK5vHBSen1U by Newk@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretechFuck Mythos and marketing bullshit, but AI that immensely reduces time-to-exploit is real. Companies are not prepared for it.
       
 (DIR) Post #B5pG89HjsL34qab9iS by beasts@social.mythic-beasts.com
       0 likes, 0 repeats
       
       @malwaretech be fair! We secured BGP with lots of crypto, but then left an XSS exploit in the crypto control panel allowing your entire network to get de-routed  with one mis-click. https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/
       
 (DIR) Post #B5pPsRBSYlfRGdoAVs by v1rulenc3@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech hey man, it would be really cringe if you misused the protocols that allow us to route internet traffic. Seriously, it would be great if one of these companies would come out with a comic book villain product that was meant to help users and corps efficiently remediate their vulnerabilities instead of exploiting them. Not to mention the hype. Mythos seems to only mark a tangible improvement over previous models in its testing, not the end of security as we know it. The initial article about Mythos sounds like one of the marketing team just played *Hacknet* and really likes the idea of the super hacker tool that can hack all the things when you type "./hack" into a terminal.
       
 (DIR) Post #B5pT2BEwzbSUZqmJqy by chrismckee@federate.social
       0 likes, 0 repeats
       
       @malwaretech ah just like SS7, vulnerable since 1975, still in use, still vulnerable 😂
       
 (DIR) Post #B5pT67feCnnIfJ95LE by loadhigh@bitbang.social
       0 likes, 0 repeats
       
       @malwaretech Is Mythos any good though? I can't find any actual results through all the hype.
       
 (DIR) Post #B5pTAvDbviQxUeJu0u by hal8999@infosec.exchange
       0 likes, 0 repeats
       
       @malwaretech The 'cybersecurity' people I hear speaking of gloom and doom also happen to have a product ready to release in a week or two, but can't demo it or explain what it actually does.   They're selling.
       
 (DIR) Post #B5piGi6b5zhLsEG2dc by ingram@mastodon.social
       0 likes, 0 repeats
       
       @malwaretech I bet there are still some people still running control systems on NT 4.0. Nice and "secure" because it doesn't support USB. Win95 probably lurking in the controller off many CNC machines too.
       
 (DIR) Post #B5pkYGmBdxVmEbDAsS by kyhwana@furry.nz
       0 likes, 0 repeats
       
       @malwaretech and everyone is still getting phished!
       
 (DIR) Post #B5pkvVzTF9M255Vd8y by brad@m.toad.host
       0 likes, 0 repeats
       
       @malwaretech when I worked at Sprint, we had to figure out crazy workarounds because if we update IE from a version that was 5 years old at the time, none of the system portals would work
       
 (DIR) Post #B5pmaO9bNt9dbTImQK by MortonRobD@mas.to
       0 likes, 0 repeats
       
       @malwaretech don’t ask how old the code your bank runs on is.
       
 (DIR) Post #B61Axh4Tkd9GZd6uJc by fuzzy@beige.party
       0 likes, 0 repeats
       
       @malwaretech yep, one word: tiring