defparam Profile Banner
d3fp4r4m Profile
d3fp4r4m

@defparam

Followers
7K
Following
4K
Media
263
Statuses
4K

Opinions are my own

Joined May 2014
Don't wanna be here? Send us removal request.
@defparam
d3fp4r4m
5 days
Google could literally give 50ms of dark pattern money to ffmpeg (like incognito mode) without even feeling it and have the project funded for the next 200 years and probably should given, well, Youtube.
0
0
3
@realytcracker
ytcracker.sol/.eth 🎤💻🔬🗝🏴‍☠️🤙
11 days
had some decent homies affected by the amzn layoffs any seceng sde or tpm roles you need to fill and want people that don’t suck reply to thread i’ll feed you souls
4
13
64
@ThePrimeagen
ThePrimeagen
15 days
nothing has cured me of so many anxiounesses of life like marriage + kids. I get to truly feel alive because life is no longer about what i want, but about the very real needs of people who depend on me that i love with a love i did not believe i was capable of
@mattwelter
Matt Welter
16 days
i have... - an amazing girlfriend - making ~$450k this year - can work anywhere / anytime - live in a house w/ a pool yet i have anxiety every damn day, tight chest, hard to take a deep breaths, intrusive thoughts, always feeling not enough, can never relax what went wrong
82
139
4K
@alxbrsn
Alex Birsan
18 days
@ArchAngelDDay Bucharest drivers see you putting on your seat belt and take it as a personal insult
0
1
3
@defparam
d3fp4r4m
20 days
This one resonated hard
@defparam
d3fp4r4m
21 days
ChatGPT5 is so useless now
0
0
1
@defparam
d3fp4r4m
21 days
I think it’s a good time to throw my money somewhere else
2
0
3
@defparam
d3fp4r4m
21 days
ChatGPT5 is so useless now
13
0
32
@defparam
d3fp4r4m
21 days
I also feel that engineering tools with a scripting ability (like Python in IDA) is much more powerful if you just create a CLI tool to pipe the interpreter directly to the model rather than attempt to abstract (and constrain) every action into an MCP tool
1
0
3
@defparam
d3fp4r4m
21 days
@halvarflake Actually an project interesting idea would be an MCP to Cli tool converter for all programatic API use cases (not just LLM)
0
1
0
@halvarflake
Halvar Flake
21 days
I don't understand mcp. Is there anything mcp can do that a cli tool can't do better?
24
5
64
@steipete
Peter Steinberger
25 days
📢 Time for an update on my workflow. This one's a 23 min read, so buckle up. 100% organic and hand-written, like an animal.
Tweet card summary image
steipete.me
A practical guide to working with AI coding agents without the hype.
133
219
2K
@defparam
d3fp4r4m
1 month
I’m kind of sick of ChatGPT 5 complimenting my questions, do we really need to waste the output tokens for the sake of flattery?
1
0
4
@h0mbre_
h0mbre
1 month
Wrote a blogpost today about getting Lucid fuzzing on a "real" target, all of the work that it took and the changes we made along the way. Next, we'll take a more earnest bug-finding approach and conduct a serious fuzzing campaign with Lucid:
h0mbre.github.io
Background We’ve spent a lot of time so far on this blog documenting the development process of Lucid, our full-system snapshot fuzzer, and I really wanted to start using it to do some real fuzzing....
1
41
198
@defparam
d3fp4r4m
1 month
FalseCrashReducer - LLMs being used to generate constraints and and analyze crash feasibility for LLM-generated bottom-up fuzz drivers in OSS-Fuzz-Gen. https://t.co/O2G51LGfUI
0
0
4
@h0mbre_
h0mbre
2 months
Lucid is alive! it's fuzzing its first real target and found it's first 0day already, an 00B read. had to patch it to keep fuzzing. this + some modifications is going to be blog post 1 in a series about iterating on the fuzzer until it's vastly improved.
9
16
227
@defparam
d3fp4r4m
3 months
Between pwn2own, bug bounty and countless amount of sec eng hours invested in securing the web browser, meticulously locking down APIs and other client side exploits just to have product designers slap in an AI subsystem without a proper security review 😂 🍿
1
0
4
@joaxcar
Johan Carlsson
3 months
@oegerikus @Xbow If you are gonna use H1 as a marketing platform and hint about ”use use instead of humans! just look at out stats” I would please ask of you to start releasing the cost of running this tool. It starts to feel like you are eroding the trust of researchers on these platforms
6
6
94
@defparam
d3fp4r4m
4 months
I can’t tell if the creator of curl is just not privy to kettle’s reputation or really just hates exploit logos that much
1
0
5
@defparam
d3fp4r4m
4 months
The man produces cutting edge research for blackhat 10 years in a row conducting proper disclosure each step of the way including 3 other desync related talks resulting in highly impactful data/tools for all of infosec and people still lose their minds over logos and websites 🤷‍♂️
@albinowax
James Kettle
4 months
If you’re planning to promote your research with a website, better prepare for some quite hostile takes! (Yes, I am practicing responsible disclosure as always)
2
4
40
@Xbow
XBOW
4 months
Even mature products hide critical flaws – and @XBOW just found another one. CVE-2025-49493: XXE in Akamai CloudTest discovered during our climb to #1 on HackerOne. A complete technical breakdown from an error-based detection to a full exfiltration by @djurado9
7
37
239