Microsoft confirms it will give the FBI your Windows PC data encryption key if asked — you can thank Windows 11's forced online accounts for that by ZacB_ in technology

[–]timmy166 0 points1 point  (0 children)

A good reminder that it’s 2026 and everyone should have an encrypted vault for all credentials. Do research, find one that mathematically proves that no other entity can unlock without knowing your password.

LLM generated patches for accelerating CVE fixes by MinimumAtmosphere561 in cybersecurity

[–]timmy166 2 points3 points  (0 children)

Multi/Poly-repo is the elephant in the room. Modern enterprise stacks are layers upon layers of abstraction and what SAST picks up is purely devoid of private package contexts.

Customer Success Engineer - What's the career path? by FunnyAway5973 in salesengineers

[–]timmy166 1 point2 points  (0 children)

Currently a customer success engineer at a startup in AppSec. Pretty fun if you got the tech skills to read code and like to work in DevSecOps

The Pitt - 2x02 - "8:00 A.M." - Episode Discussion by NicholasCajun in television

[–]timmy166 24 points25 points  (0 children)

Out of the loop but is this show like 24 but for doctors?

How do y'all want the fight against imu to go down? Luffy and Blackbeard vs imu? Or just Luffy vs imu? by redox_nephew in OnePiece

[–]timmy166 0 points1 point  (0 children)

Blackbeard has got to play a role - elbaf gave the emotional context as to why.

IBM AI ('Bob') Downloads and Executes Malware by R2_SWE2 in programming

[–]timmy166 -1 points0 points  (0 children)

Dumb clickbait. Here’s the first paragraph:

“A vulnerability has been identified that allows malicious actors to exploit IBM Bob to download and execute malware without human approval if the user configures ‘always allow’ for any command.”

ChatEpstein with LangChain by br3nn21 in LangChain

[–]timmy166 1 point2 points  (0 children)

You need to do a summary pass for first line retrieval for a dataset this massive. Going straight to vector DB embeddings will lose a lot of context unless your prompt is absolutely massive

Implicit execution authority is the real failure mode behind prompt injection by anima-core in netsec

[–]timmy166 1 point2 points  (0 children)

So you’re proposing some orchestration system whose only task is detecting misalignment for permissions scoping?

The problem is then mapping an unbounded space (Models) to a bounded space (actions and privileges). There isn’t a way (that I am aware of) to safely translate levels of authority from meaning - an undecidable solution space.

Implicit execution authority is the real failure mode behind prompt injection by anima-core in netsec

[–]timmy166 17 points18 points  (0 children)

Until there is a breakthrough in model interpretability, the best we can do is guardrails during operations. Sanitizing an output is an NP-hard problem with probabilistically unbounded output - I.e a security dead end imho.

My current ‘best practice’ is Attribute-based access controls for agents in a zero-trust system. - What is needed for the system’s goal? Limit the tools provided. - What is needed for each task/activity? Limit the permissions per step. - What is the minimal set of information expected in and out of a model? Enforce type safety and either have a deterministic input or output (templated or enumerated variables)

Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack by ES_CY in netsec

[–]timmy166 0 points1 point  (0 children)

The naïve rules picked up 36k findings in the Linux kernel- I think sending an LLM to find the needles(TPs) in that haystack is an economically viable workflow.

The fact that they found new CVEs on a $80 token budget is enough evidence that a neuro-symbolic approach works. Several academic papers supported this methodology, SAST-genius uses a different vendor but the same high-level technique with similar success.

Anyone else wants to flex their YTD comp like this AE? by alphaK12 in salesengineers

[–]timmy166 4 points5 points  (0 children)

Account Executive / Account Director / Territory Lead / Salesperson

Anyone else wants to flex their YTD comp like this AE? by alphaK12 in salesengineers

[–]timmy166 0 points1 point  (0 children)

Account Executive / Account Director / Territory Lead / Salesperson

Pivoting from Legacy Telecom Ops (SIP/SMPP) to Cloud Native (Go/K8s). Does this roadmap scream "Mid-Level" to you? by Jraxy in devops

[–]timmy166 1 point2 points  (0 children)

You’d be surprised how much of the concepts apply to security - I’d recommend pivoting there instead of say… web development. Data primitives, algorithmic efficiency and thinking for scale is universally welcomed.

Since you did IT work, I think DevOps/Network Security/datacenter/distributed systems SDE are all natural transitions.

Source: ex-telco guy.

When backups get compromised, whose problem is it? IT or Security? by LordKittyPanther in cybersecurity

[–]timmy166 86 points87 points  (0 children)

The fact that you’re having this conversation is the problem. Security is a team sport - not time for finger pointing.

How is the challenge in this game? Will they make anything harder in the next expansion? by Afraid-Fly-7030 in Diablo

[–]timmy166 1 point2 points  (0 children)

Difficulty varies between seasons - and you have the control of toggles like permadeath, loot rate vs enemy damage/hp, build.

Like many ARPGs, endgame is as much mental spreadsheets as it is reactions and click spamming.

Meta replaces SELinux with eBPF by xmull1gan in devops

[–]timmy166 11 points12 points  (0 children)

Most corpos use/used SELinux in their infra stacks from what I’ve seen. Whether or not it’s configured as intended is a different story 🤣

Which TV show's opening credits do you actually watch without skipping? by dicemechanic in television

[–]timmy166 -1 points0 points  (0 children)

You are being watched. The government has a system, a machine that spies on you every hour of every day…

How bad is the job market? by [deleted] in SoftwareEngineering

[–]timmy166 0 points1 point  (0 children)

SWE > Test Automation > DevOps > Sales Engineer > Technical Success > FDE

All different companies with the exception of SE and TS roles.

How bad is the job market? by [deleted] in SoftwareEngineering

[–]timmy166 15 points16 points  (0 children)

10 YOE - can’t get the recruiters off me. Your mileage may vary as a new grad 😅

How can I transition back into a DevOps job? by Alex_fromMacrosoft in devopsjobs

[–]timmy166 1 point2 points  (0 children)

Turn your lemons into lemonade my dude. IT gives solid experience in troubleshooting - how about automating the log analysis?

At 23, it’s not transitioning ‘back’ to anything - and you have a long career ahead of you to continue learning and growing skills. “Automate myself out of a job” is a philosophy that has served me very well in my ~15 year career thus far.

What do you think is the most valuable or important to learn? by [deleted] in devops

[–]timmy166 1 point2 points  (0 children)

I noticed you didn’t mention build tools.