Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

g-clef

@gclef@mstdn.social
mastodon 4.7.2
  • Open on mstdn.social

Mostly Infosec stuff, though I also enjoy terrible puns, music, and science-y stuff. Twitter diaspora from @gclef_

Opinions my own, my employer can speak for themselves.

165 Followers
130 Following
18 Posts
Joined November 04, 2022
An obligatory blog:
https://blog.g-clef.net/
Github:
https://github.com/g-clef
Dayjob:
https://www.domaintools.com/authors/aaron-gee-clough
Open post
g-clef @gclef@mstdn.social
· 6mo ago
Replying to
@me @g apocalopedes It's at least fun to say.
6
0
0
0
Open post
g-clef @gclef@mstdn.social
· 9mo ago

Well, I'm sure this rebrand will be welcomed with cheers and joy.

/s

(in case they change it, this is a screenshot of https://www.office.com as of a few minutes ago)

office.com
11
6
6
1
Open post
g-clef @gclef@mstdn.social
· 8mo ago
Replying to
@morattisec@infosec.exchange https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals
Claude Platform Docs

Handle streaming refusals

Detect and handle refusal stop reasons in streaming responses, and retry refused requests on a fallback model.

4
0
0
0
Open post
g-clef @gclef@mstdn.social
· 6mo ago

@neurovagrant@masto.deoan.org not to toot my own horn too much, but I've had some surprisingly good results using the SAT-skill stuff I put out a couple weeks ago.

Like, follow up an investigation agent conclusion with "validate your conclusions by running a SAT-Skill Devil's Advocate test against them." It still gets over-ambitious at times, but it dials itself back a bunch.

I've found that a layer of "criticize your own conclusions" is a good pattern for a lot of LLM use, both in code and analysis.

2
0
0
0
Open post
g-clef @gclef@mstdn.social
· 8mo ago
Replying to
@DaveMWilburn@infosec.exchange Hah! I think I was at that CAMLIS. Need to see if I can find my notes.
1
0
0
0
Open post
g-clef @gclef@mstdn.social
· 8mo ago
Replying to
@DaveMWilburn@infosec.exchange Thanks! Yeah, I was worried about the hallucination problem, which is why I did the questioner-role thing. Thanks for the reference - is this what you were referring to? https://cloud.google.com/blog/topics/threat-intelligence/clustering-and-associating-attacker-activity-at-scale I think my biggest worry at the moment is that the LLM will try to step into the answering role if the user doesn't take the lead. Not sure at the moment how to address that other than saying "don't do that", though - being "helpful" is kinda baked into the LLM prompts.
Going ATOMIC: Clustering and Associating Attacker Activity at Scale | Mandiant | Google Cloud Blog
Google Cloud Blog

Going ATOMIC: Clustering and Associating Attacker Activity at Scale | Mandiant | Google Cloud Blog

1
2
0
0
Open post
g-clef @gclef@mstdn.social
· 8mo ago
Replying to
This is very much a first cut, so I'm super-curious about feedback. If there's wording here that you think I should change, please do let me know (or just throw a pull request or issue at the repo).
1
4
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
The Copyright office guidelines (that the Supreme Court left in place) say that a human must be part of the creation process of a work for it to qualify for copyright. They explicitly say that merely prompting an LLM and then accepting the output is not enough.
0
6
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
Also, an earlier copyright case, the "monkey selfie" case, established that even if you do lots of setup, if a non-human actually *creates* the work, it's not eligible for copyright. The fact that a monkey pressed a button to take a picture made the picture un-copyright-able.
0
5
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
I *think* that means anything generated autonomously by an LLM agent or an openclaw system isn't eligible for copyright, and the group doing it doesn't own the results.
0
4
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
I'm thinking particularly of things like "write code to resolve my open tickets" or "run this query, decide on the important data points, and write a report on the results". Would you put out a report that you can't claim copyright on? Maybe, but you should do so knowingly, not accidentally.
0
3
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
Also, I feel like any code or patches generated by an openclaw system can't be open-source - the code isn't owned, so neither the agent nor its operator can assign copyright or use copyright to enforce any license terms.
0
2
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
Lastly, I'm also thinking about all the statements from CEO's to the effect of "90% of our code last quarter was automatically written." I feel like those statements are going to bite them the next time they claim any sort of copyright ownership in court.
0
1
0
0
Open post
g-clef @gclef@mstdn.social
· 7mo ago
Replying to
The next Oracle vs Google case could end up with a nuclear option of "you don't even own the thing you're suing me for copying...you said yourself an LLM wrote it."
0
0
0
0
Open post
g-clef @gclef@mstdn.social
· 6mo ago

Apparently there's a Shane MacGowan tribute album coming out soon. The track from Bruce Springsteen:

https://youtu.be/r_Z3JL42L5Q

Bruce Springsteen - A Rainy Night in Soho (Official Lyric Video)

0
0
0
0
Open post
g-clef @gclef@mstdn.social
· 8mo ago

Realized over the weekend I forgot to add a "feature" to the DNS tarpit: endless CNAME chains.

That's fixed now. So, now you can specify a subdomain of your tarpit and all A or AAAA responses in that subdomain will be CNAMEs, with no hints. Look up that CNAME, you'll just get another CNAME.

https://github.com/g-clef/dns_tarpit

GitHub

GitHub - g-clef/dns_tarpit

Contribute to g-clef/dns_tarpit development by creating an account on GitHub.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:27:18 UTC