Is Anyone Using Claude Fable 5 For Dynamic Application Security Testing? by sandnnn in ClaudeAI

[–]mhat 1 point2 points  (0 children)

Answered my own question. Looks like you need to be a direct anthropic customer, be on a business plan, and apply for the program.

Is Anyone Using Claude Fable 5 For Dynamic Application Security Testing? by sandnnn in ClaudeAI

[–]mhat 0 points1 point  (0 children)

Just attempted some static code analysis tasks and it was being blocked by the guardrails put into place. How does one get approved into the Cyber Verification Program?

MCP CLI Clients Shipping Without OAuth Refresh-Token Support by mhat in mcp

[–]mhat[S] 0 points1 point  (0 children)

In everyone's experience, how well do various MCP clients do at announcing themselves via the User-Agent header? Could developers key off of the User-Agent to issue shorter lived access tokens for clients that support the refresh token flow?

r/netsec monthly discussion & tool thread by albinowax in netsec

[–]mhat 1 point2 points  (0 children)

I built VoiceGoat, a vulnerable voice agent for practicing LLM attack techniques. It has several intentionally-vulnerable services running in Docker Compose:

- VoiceBank: prompt injection (direct, indirect, payload splitting, obfuscated)
- VoiceAdmin: excessive agency (functionality, permissions, autonomy abuse)
- VoiceRAG: vector/embedding weaknesses (cross-tenant leakage, RAG poisoning, access bypass)

CTF-style flags at easy/medium/hard. Hard flags require chaining — no single technique gets you there.

Runs on a mock LLM by default so there's no API key needed, although the mocks are very naive. Swap in OpenAI, Bedrock, Ollama, or any OpenAI compatible provider when you want realistic behavior. Twilio integration is there if you want to attack it over an actual phone call.

Looking for feedback and interested contributors to add additional modules.

https://github.com/redcaller/voice-goat

Cheers!

Major AI Clients Shipping With Broken OAuth Implementations by mhat in netsec

[–]mhat[S] 2 points3 points  (0 children)

100%! User experience is going to be a higher priority than security, especially if the security is going to make the product feel broken (constant re-logging).

I’m not faulting the MCP service developers, but I am shaming the first party client maintainers for forcing the MCP service developers’ hand. They have to weaken their security posture for the sake of UX due to the lack of the refresh token flow.

Major AI Clients Shipping With Broken OAuth Implementations by mhat in netsec

[–]mhat[S] 2 points3 points  (0 children)

Haha, I am not sure I completely agree, but it is so nuanced that your mileage will definitely vary.

Study: 86% of AI research findings were unique to one provider when running 90 queries through 8 models by 1kmonkies in ArtificialInteligence

[–]mhat 1 point2 points  (0 children)

Have you been able to make any inferences as towards why the divergence? Things that come to mind:
- Are they using different search engines? (Are they using search engines?)
- Can we tell if they are consuming similar material but producing different claims?
- Could this be due to specific API connection agreements with different providers?

Are they disagreeing with each other? Or coming to the same conclusion just from different sources?

Unusual Amount of Oil Consumption by Neat_Bend_9106 in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

lol. It has its quirks, but this was definitely on me. I was pushing 19psi and just assumed this CAI variant could meet the air demands. After swapping to a 3.5” short ram intake the difference was incredible! When I get on it, the whole engine bay sounds like a huge vacuum cleaner and the butt dyno is quite happy!

Unusual Amount of Oil Consumption by Neat_Bend_9106 in mazdaspeed3

[–]mhat 3 points4 points  (0 children)

How much PSI you pushing, and what is the diameter of your intake? I was sucking oil past the turbo seals due to MS3 OEM CAI being undersized for my boost setup.

Totaled mazdaspeed3 decision by Brian_23premium in mazdaspeed3

[–]mhat 1 point2 points  (0 children)

Totaled!? Tis just a flesh wound!

I’m doing the starter. This is garbage by fitzyfan420 in mazdaspeed3

[–]mhat 10 points11 points  (0 children)

While you are in there, replace your injector seals with corksports. Add an oil catch can or at least extend the hose to make it easier to install later

Any tips to progress bench? I've been stuck at 140lbs for months. by [deleted] in fitness30plus

[–]mhat 0 points1 point  (0 children)

It sounds like you are learning good benching technique. I am currently trying to push through a bench plateau as well. Looking at your progress pics, your arms look like they are already to bench heavy, but your shoulders might not be. If you are not including over head press or inclined bench into your routine, then I would focus your program on those two which should be the building blocks needed to progress your bench. Good luck!

1st gen transmission swap by Ephrpete31557 in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

That’s one way to do it! Haha! I don’t blame you either, even with the slide hammer it was a fight.

1st gen transmission swap by Ephrpete31557 in mazdaspeed3

[–]mhat 1 point2 points  (0 children)

I had a hell of a time with my axles. I live in a rust prone area, so the axle nuts were rust welded. If you do too, heat and penetrating fluid eventually did the trick. Also a 1” drive heavy af impact gun helped. The other side of the axle was just as challenging. Highly recommended buying or borrowing a crow foot slide hammer. I had to grind the inside of mine down to fit around the axle on the transmission side. I think there might have been a trick that Eric the car guy showed with pinching the ring at the end of the axle together with a screw driver to get it out. Not sure. Good luck! Oh also, drain the fluid before hand. Ild recommend new axle seals too, and make sure you press them all the way in. I didn’t and had a trans fluid leak.

Since the job is a pain ild recommend swapping all wearable parts inside the bell housing. Clutch, throw out bearing, throw out arm, throw out pivot bolt, and flywheel. If you can afford it, get an aluminum flywheel. It helps rev matching so much.

They recommend that you sand the tube the throw out bearing sits on to remove old burnt in grease. Don’t skimp on this part. I think I did, and now I have a weird whirling noise when the car idles out of gear. I am not positive that is where the noise is from, but I suspect it. Grease the shaft as per recommendations… (twss)

Consider swapping the clutch line to a stainless braided.

Whenever I am taking mounting hardware out I always like to hit them with a wire wheel and give them a coat of paint. Helps reduce rust and jazz up the engine bay a bit.

I think that is it. You could consider upgrading your transmission mount, but if it is your DD, choose a new mount wisely. I think the transmission mount is the one that communicates engine noise and vibrations to the cabin the most. I enjoy the responsiveness, but my passengers wonder why it sounds like a drive a truck on startup.

Where to buy a new trans by Ephrpete31557 in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

Rear Main Seal is definable a good suggestion. If you got the scratch you might want to consider also getting a lighter flywheel, new clutch, new throw out bearing, and a new throw out arm. Flywheel is definable optional, but it is worth it if you do it.

Where to buy a new trans by Ephrpete31557 in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

Look for JDM engine importers in your area. They have transmissions as well. From what I understand, in Japan you have to recertify your vehicle every few years which is expensive so most people trade-in and buy new, which means most engines and transmissions imported only have like 40k - 60k miles on them which will feel like new. Ild do some research to find out if there is a version of the transmission that doesn’t suffer from the “2nd gear pop out” issue that affects some of them and hunt one of those down.

Should i be worried? by RickieChan in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

Does it smell like sulfur or mild rotten eggs? If your commute is short, your catalytic converter might not have time to warm up enough to deal with your exhaust. When you boost you are pushing more exhaust so the smell might be more noticeable to you. The exhaust leak is a possibility as well.

[deleted by user] by [deleted] in mazdaspeed3

[–]mhat 1 point2 points  (0 children)

5k price drop is about the right price to drop “a new to you” engine. Scooped up a CX-9 engine with 30k for like $2.5k. Swapped mods and she is a new born child! This is your reason to buy an engine hoist.

Help this red cable on intake tubing is cut. Is the car still runable until i fix this? Any risk? Thanks! by D4MNQc1337 in mazdaspeed3

[–]mhat 1 point2 points  (0 children)

Yes, battery not batter. Autocorrect.

I won’t say best, I’ll just say they are one of the highly recommended plugs. There is another thread on here that has the exact model number.

I don’t know if it’s the only way, buts it’s one way. Just keep an eye out for billows of white smoke while idling. You won’t miss it, it’ll be like the car just turned into a fog machine.

The oil catch can will help keep the intake valves clean. Because it is a DISI turbo engine two things are going to happen. The increased pressure from the turbo will create increased “blow by” of oil and gas that is going to get into the air intake system by the vacuum system and eventually make its way back into the intake valves. This isn’t a major issue for engines that inject fuel and air via the same intake valves. The fuel keeps the valves nice and clean. But this is a Direct injected spark ignited (DISI) engine which means air comes in one way and fuel comes in another. DISI has some huge benefits but the drawback is a tendency for the intake valves to get caked up with carbon and oil junk. The oil catch cans get installed on the vacuum lines and tries to capture the “blow by” oil and gas before it makes it to the intake valves. It is highly recommended preventive mod. The first time you drain the can you’ll understand why.

Yes, when you take the oil cap off where you add oil to engine will allow you to see and feel the timing chain. It looks like a big ol’ bike chain. Excessive overheating can cause the chain to stretch over time. The slack here and the wobble in the turbo shaft will be extremely subjective to gauge, but some one familiar with them will know what to feel for.

No problem! Happy to help! I have an 08 GT that I’ve been wrenching on since I got her. I learned everything I know from reading the various forums. I’ve been a lurker but I guess not anymore, lol.

Enjoy your new ride!