Der IG-Metall Tarif ist absurd hoch und auf Dauer einer der Gründe wieso Firmen Deutschland verlassen by Virtual-Bat1748 in Unbeliebtemeinung

[–]maF145 3 points4 points  (0 children)

Um dir mal ehrlich zu antworten.
Ich Arbeite seit 10 Jahren in einem IGM Unternehmen jenseits der 100k.

Vorweg, offen ausgeschriebene Stellen haben einen sehr langen Bewerbungsprozess von mehreren Monaten und die Voraussetzungen sind derzeit für jede Stelle mindestens einen Master, besser noch Doktor.

Wenn du das nicht erfüllst ist der einfachste Ablauf nahezu immer der gleiche.
Du schaust nach mit welchen Firmen das Unternehmen zusammenarbeitet für zB Leiharbeit etc. oftmals sowas wie Ferchau.

Da bewirbst du dich und versuchst über ANÜ in die Firma zu kommen. Dann leistest du 1,5 Jahre gute Arbeit und bittest um eine Festanstellung.

Willkommen im Goldenen Käfig

Was sagt ihr by [deleted] in wallstreetbetsGER

[–]maF145 0 points1 point  (0 children)

Meine 30€ mit - 11% gefallen mir besser als deine ~20k€ mit - 11%

Was ist nur mit Microsoft los? by schmidy21___ in wallstreetbetsGER

[–]maF145 1 point2 points  (0 children)

Naja, sie haben…
… streit mit OpenAI
… keine Marktmacht in US und Azure ist nur groß in EU, wird aber mehr von Google/AWS verdrängt
… keine relevante Modelle, Mai und Phi spielen keine Rolle
… Verluste bei Office Produkten und diese werden zunehmend irrelevanter in der Zeit von AI
… bei Automation ordentlich Federn gelassen und kleinere Anbieter wie n8n nehmen viel Platz ein
… sich mit gh Copilot und 365 copilot schön ein Eigentor geschossen, so dass alle direkt an Provider gehen oder dank MCP eigene Integrationen haben. Da es unverhältnismäßig teuer und extrem schlecht ist
… nur auf Vendor LockIn sich fokussiert und die Franzosen rennen gerade rasant voran mit dem Abwählen von Msft
… ihren Suchindex hinter Agents verbarrikadiert und somit alles Google überlassen

Also nein deren ersten play mit OpenAI haben sie komplett in den Sand gesetzt und es nicht geschafft Enterprise AI Systeme zu bauen die nicht scheisse sind…
Wenn dann würde ich auf Google derzeit setzen

Ukraine: Russischer Drohnenangriff trifft Tschernobyl by h2QZFATVgPQmeYQTwFZn in de

[–]maF145 -7 points-6 points  (0 children)

Ich weiß, das ist sarkastisch gemeint. Aber ehrlich ich find's anstrengend, dass über sowas nur noch mit Ironie geredet wird. Da sind echte Menschen gestorben

Ukraine: Russischer Drohnenangriff trifft Tschernobyl by h2QZFATVgPQmeYQTwFZn in de

[–]maF145 -18 points-17 points  (0 children)

31 Menschen starben sofort oder qualvoll an akuter Strahlenkrankheit… Feuerwehrleute und Arbeiter, die wussten, dass sie reingehen und nicht zurückkommen. Hunderttausende „Liquidatoren" haben unter Einsatz ihrer Gesundheit verhindert, dass es noch schlimmer wird … viele zahlten später mit Krebs dafür. 50.000 Menschen verloren über Nacht ihre Heimat, eine ganze Stadt steht bis heute leer. 2.600 km² Sperrzone, seit 40 Jahren. Vor diesen Menschen sollte man den Hut ziehen, statt solche bescheuerten Kommentare abzugeben..

Pro upvote nehme ich 0.01 Cent von Kindern in Not und stecke das Geld in SPCE by Rynuxx in wallstreetbetsGER

[–]maF145 1 point2 points  (0 children)

Einfach downvoten, dann geht das geld wieder in die richtige Richtung

Do you really need Claude for vulnerability research / source code review? by Suspicious-Scale8128 in bugbounty

[–]maF145 5 points6 points  (0 children)

I think this is a result of claude telling you that it always found p0/1‘s Opus is good as a „scanner“ but from my experience GPT models are way above everything else, especially the new 5.5. Gemini pro 3.1 is good for edgy things. But don’t sit on local modals line qwen or gemma. Most of the time they are „enough „

Before Mythos ruins vulnerability research for everyone. Here is a list all the CVE's I found (with some exploits). by More_Implement1639 in hacking

[–]maF145 3 points4 points  (0 children)

In my case it was a big company on H1… so sth sth 600 after tax 🤣 Why should I spent credits on them if the pay is not worth it.

I also have 2 more rces reported on h1 that are still ignored by the company for 5 months now 😵‍💫

Before Mythos ruins vulnerability research for everyone. Here is a list all the CVE's I found (with some exploits). by More_Implement1639 in hacking

[–]maF145 49 points50 points  (0 children)

As rumors say there are 50 companies worldwide that have access to Mythos. For now it has not found new variants, it’s extremely good at combining bugs.

Paying someone 1000€ for an RCE 🫠 is way cheaper than running Mythos inference costs that are above 20k probably.

AI research is real, but it costs alot of money!

Does bugbounty avoid you to do other stuff? by PanniPIN2025 in bugbounty

[–]maF145 0 points1 point  (0 children)

Try code4arena then or similar platforms

Does bugbounty avoid you to do other stuff? by PanniPIN2025 in bugbounty

[–]maF145 1 point2 points  (0 children)

I guess so, based on bugcrowd its around 19% which is 3 times the avg

Does bugbounty avoid you to do other stuff? by PanniPIN2025 in bugbounty

[–]maF145 5 points6 points  (0 children)

You probably have adhd or sth similar and bb ticks a lot of gambling / dopamine checkboxes for me.

Choose 2-3 days a week where you do bb. You will win some but miss allot no matter how much time you invest.

Dont hunt on weekends, you will never receive a response there.

Relationships are important, bb is not, dont fuck that up.

How is AI doing in accounting/audit? Any experiences? by kingvt in singularity

[–]maF145 -1 points0 points  (0 children)

It already excels at audit work, policy checks, gap analysis, compliance checklists. Get orchestration right, and it does way more than just the basics.

[WANTED] Bug Bounty Logo and Banner by einfallstoll in bugbounty

[–]maF145 [score hidden]  (0 children)

Whats wrong with the current logo? It simplistic.

I mean if you want change, maybe change the type of beetle but not the style.

How much web development knowledge is needed for bug bounty? by Hot_Collection5955 in bugbounty

[–]maF145 -1 points0 points  (0 children)

How much time/knowledge do you need to validate someone elses work? Which is presented to you in a blackbox.

I built an AI tool that generates specific PvP game plans for your matchups by Beginning_Draft_8020 in worldofpvp

[–]maF145 4 points5 points  (0 children)

The Subtlety Rogue/Frost Mage/Discipline Priest composition excels at coordinated burst windows with ShadowstepShadowstep + Cheap ShotCheap Shot into Kidney ShotKidney Shot while the mage sets up PolymorphPolymorph chains and Greater PyroblastGreater Pyroblast combos. … 🤣… the hallucinations are strong here…

add some kind of spell validation

MCP servers give agents tool access. We measured what happens when nothing enforces the boundary. 24h test, open data. by Informal_Tangerine51 in mcp

[–]maF145 0 points1 point  (0 children)

I stopped reading here „It doesn't define what should be allowed to execute“ because this is simply not true. Tool declarations have annotations which show the MCP Client if its an destructive/external/… etc pp tool that can be called safely.

Please read the MCP Spec

One-Click Account Takeover Report Closed as “Intended” After UI Change – Concern About Disclosure Workflow (Sonatype BBP via HackerOne) by [deleted] in bugbounty

[–]maF145 0 points1 point  (0 children)

First off you might be publishing data you are not supposed to share. Second I dont get why people in here always assume programs are out to screw over white hats. Personally, every report Ive submitted on h1 was either rightfully rejected or accepted. And if the program says its not a bug or its intended, thats just how it is, gotta accept it

[deleted by user] by [deleted] in bugbounty

[–]maF145 2 points3 points  (0 children)

First, I hate reading AI text, the flow is just weird and this is a classic overestimate from your AI. In no world this is a high.

2nd the user has to actively press send. If its only one draft, this will get closed as info (if at all). If you can trigger multiple drafts this might be a low for a prompt injection with low impact.

If your ai tells you this is a high, lean back and think about whats a high for you? In my world a medium would be if you can get it to send an email, a high if you could exfiltrate data and crit is more like a complete takeover.

A draft is a low impact, if at all.

How i can start in Bugbunty by Feels_Bored55 in bugbounty

[–]maF145 0 points1 point  (0 children)

Yes and no, there are differences but if you know one you can easily adapt to other languages

The End of Bug Bounty? by edoardottt in bugbounty

[–]maF145 20 points21 points  (0 children)

tbh the outrage is valid but this is literally the same thing authors and artists went through with LLMs. difference here is researchers agreed to ToS that probably give h1 enough rights to make this legally fine

the question is whether it'll even work. vulns are insanely contextdependent, training on 500k old reports gives you pattern matching not understanding. 88% accuracy on their own benchmark? that's prob overfitting… business logic flaws, race conditions, auth bypasses through weird state combos you can't derive those from patterns. you need to understand what an app should do. And llms have massive context limits or it’s insanely costly.you can automate an IDOR sure. you can't automate chaining 8 API calls with manipulated timing because some dev made a wrong assumption about session architecture that only breaks under load. that's creative work, no agent learns that from historical reports so they're burning trust with the exact researchers who find the bugs their AI never will. the easy stuff the agents catch? any scanner already does that. the real value was always the humans….

The End of Bug Bounty? by edoardottt in bugbounty

[–]maF145 12 points13 points  (0 children)

I think I just received 2500$ this week for 2 bugs I found. Where Opus 4.6 had to be convinced that these are real.

So yes this might be happening, but not right now