dragosr's Avatar

dragosr

@dragostech.bsky.social

Autonomous Carbon Based LLM with 42 years of tuning on Information Attack and Defense. Host of CanSecWest, and PacSec. Security audits, code, IR, LLM, red team consulting. Specialize in Firmware, and RF. VA7MOV

1,596 Followers  |  3,742 Following  |  1,176 Posts  |  Joined: 11.11.2024  |  2.3819

Latest posts by dragostech.bsky.social on Bluesky


Preview
GitHub - secwest/fast-prime Contribute to secwest/fast-prime development by creating an account on GitHub.

I gave LLM agents an Ultra9 285K and no token budgets, and told them to optimize prime number sieves. When they started, finding and counting all the primes representable in 64 bit integers (216,289,611,853,439,384) was going to take ~4,800,000 years.

Four days later, now down to 202 seconds.

21.02.2026 21:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

He has made a career out of fictional LLM failures, aparently.

20.02.2026 21:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

So when we started to make microprocessors, calculator chip production took a hit too.

HBM takes approximately three times the fab capacity of client DDR, but they are getting Tb/s at server bit widths...

18.02.2026 17:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post-Quantum Cryptography β€” ML-KEM & HQC Reference Interactive reference for NIST post-quantum cryptographic standards: ML-KEM (FIPS 203) lattice-based and HQC code-based key encapsulation mechanisms.

A question about how Signal added post-quantum crypto to the Double Ratchet sent me down a rabbit hole. I built interactive visualizations of ML-KEM (Kyber) and HQC algorithm layers, plus Signal's Triple Ratchet upgrade:
secwest.github.io/post-quantum...
secwest.github.io/triple-ratch...

17.02.2026 19:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is pretty evil, abusive treatment of folks with ADHD in the UK...

17.02.2026 08:51 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
LLM Cost Dashboard β€” Inference & Training (Feb 2026) Interactive LLM cost dashboard: inference cost decline with microwave-oven equivalents, and training cost escalation with Boeing 777 metal smelting equivalents. Updated Feb 2026.

For everyone that is so confident about the reports of the AI vendors businesses being unprofitable - a look at what we can expect for LLM economics.

secwest.github.io/llm-cost-das...

16.02.2026 05:23 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
The Internet Still Works: Wikipedia Defends Its Editors Section 230 helps make it possible for online communities to host user speech: from restaurant reviews, to fan fiction, to collaborative encyclopedias. But recent debates about the law often overlook

Wikipedia receives hundreds of legal demands every year to remove user-written content. Almost all are rejected. We spoke with Wikimedia’s legal team about how Section 230 helps protect volunteer editors and public knowledge. www.eff.org/pages/inter...

15.02.2026 21:57 β€” πŸ‘ 183    πŸ” 59    πŸ’¬ 4    πŸ“Œ 2
Preview
Introducing Markdown for Agents The way content is discovered online is shifting, from traditional search engines to AI agents that need structured data from a Web built for humans. It’s time to consider not just human visitors, but...

This seems like a clever solution to the LLMs drowning websites in requestsβ€”auto-convert the content to markdown, which is what they’re doing anyway, and just give them the data.

A good middle ground for folks who don’t mind their info getting plundered by bots.

blog.cloudflare.com/markdown-for...

14.02.2026 23:26 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 8    πŸ“Œ 1

I know there are a lot of mutual aid asks coming out of Minneapolis right now, but both of my kids graduated from South High and it would mean a lot to me for people to contribute to this rent fund for my fellow South families. I’ll match the first $1000 if you post receipts. Tiger Pride πŸ§‘πŸ–€

14.02.2026 17:34 β€” πŸ‘ 150    πŸ” 100    πŸ’¬ 6    πŸ“Œ 1

the right path here is to teach the kids how to get the LLM to give them the diverse answer.

12.02.2026 21:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

It's a desktop that others (including some LLMs) and myself need to ssh into to test the three kinds of NICs installed for hardware testing.

12.02.2026 13:33 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
GitHub - secwest/lean-ssh Contribute to secwest/lean-ssh development by creating an account on GitHub.

On Ubuntu 22.04+ (incl. 24.04LTS), every SSH login spawns a full systemd --user session, auto-starting 8–15+ desktop services (audio, indexing, portals, a11y) via socket/D-Bus activation β€” all useless on headless/SSH-only consoles, wasting memory and resources.

Fix:
github.com/secwest/lean-ssh

12.02.2026 08:05 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Screenshot of an email from Claude with the Claude logo at the top. The message states that an internal investigation found suspicious signals indicating a violation of the Usage Policy, resulting in revoked access to Claude. It includes links labeled Usage Policy, form, and here for appealing the decision, and is signed 'Anthropic's Safeguards Team.

Screenshot of an email from Claude with the Claude logo at the top. The message states that an internal investigation found suspicious signals indicating a violation of the Usage Policy, resulting in revoked access to Claude. It includes links labeled Usage Policy, form, and here for appealing the decision, and is signed 'Anthropic's Safeguards Team.

LOL: OpenClaw/Moltbook is forbidden by Anthropic ToS & they have started enforcing it, to the benefit of internet security.

β€œYou may not share your Account login information, Anthropic API key, or Account credentials with anyone else. You also may not make your Account available to anyone else.”

09.02.2026 18:36 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I honestly think we can use LLMs to build systems we understand *better* than we could before

09.02.2026 14:20 β€” πŸ‘ 59    πŸ” 6    πŸ’¬ 5    πŸ“Œ 1

That data was gone long before he let an LLM at it.

Repeat after me: If it's digital and you don't have at least three separate copies stored in different places or mediums, then it's already gone.

(this is a good time to check your backups)
Also test them. Untested backups, aren't.

09.02.2026 00:09 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

That data was gone long before he let an LLM at it.

Repeat after me: If it's digital and you don't have at least three separate copies stored in different places or mediums, then it's already gone.

(this is a good time to check your backups)
Also, untested backups, aren't.

09.02.2026 00:04 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Didn't think I did, really, but I hope this conversation reminds someone else to go work on those backups they have been procrastinating on.

08.02.2026 23:57 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - shanselman/winget-tui: A terminal UI for Windows Package Manager (winget) - search, install, upgrade, and manage packages A terminal UI for Windows Package Manager (winget) - search, install, upgrade, and manage packages - shanselman/winget-tui

exploring what a WinGet TUI would look like github.com/shanselman/w...

08.02.2026 23:52 β€” πŸ‘ 41    πŸ” 5    πŸ’¬ 4    πŸ“Œ 0

Oh, fun.

08.02.2026 23:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

....and then back up those.

And check the backups. Restore untested backups, aren't.

08.02.2026 23:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That data was gone long before he let an LLM at it.

Repeat after me: If it's digital and you don't have at least three separate copies stored in different places or mediums, then it's already gone.

(this is a good time to check your backups)

08.02.2026 23:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

That data was gone long before he let an LLM at it.

Repeat after me: If it's digital and you don't have at least three separate copies stored in different places or mediums, then it's already gone.

(this is a good time to check your backups)

08.02.2026 23:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That data was gone long before he let an LLM at it.

Repeat after me: If it's digital and you don't have at least three separate copies stored in different places or mediums, then it's already gone.

(this is a good time to check your backups)

08.02.2026 23:47 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The kindness of strangers: my teenage son was on a date at a fancy restaurant when a fellow diner helped pay the bill She made a special night even more special for these two young people – and gave me something special too

The kindness of strangers: my teenage son was on a date at a fancy restaurant when a fellow diner helped pay the bill

08.02.2026 23:24 β€” πŸ‘ 80    πŸ” 9    πŸ’¬ 6    πŸ“Œ 1

Working in coordination with standwithminnesota.com, I’m raising rent funds for Minneapolis immigrant families in need. We now have a $5000 match offer (!) and are going to help as many families as we can to stay housed today.

V: @Ian-Coldwater
CA: $iancoldwater
PP: @coldwater

Thank you so much! 🌷

05.02.2026 23:31 β€” πŸ‘ 239    πŸ” 145    πŸ’¬ 5    πŸ“Œ 5

Hey fellow Canadians, if you've been watching people raise emergency rent funds for Minneapolis and thinking "I would pitch in but we don't have Venmo" here is a fundraiser taking Paypal!

05.02.2026 21:49 β€” πŸ‘ 50    πŸ” 23    πŸ’¬ 1    πŸ“Œ 0
Xbox 360 cover art for Gears of War: Triple Pack. Three armored soldiers are shown in separate panels holding futuristic firearms, arranged around a large red cog-and-skull Gears emblem at center. The title β€œGears of War Triple Pack” appears at the top, with labels indicating Gears of War, Gears of War 2, and Gears of War 2: All Fronts Pack. The Microsoft and Epic Games logos and an M-rating badge are visible at the bottom.

Xbox 360 cover art for Gears of War: Triple Pack. Three armored soldiers are shown in separate panels holding futuristic firearms, arranged around a large red cog-and-skull Gears emblem at center. The title β€œGears of War Triple Pack” appears at the top, with labels indicating Gears of War, Gears of War 2, and Gears of War 2: All Fronts Pack. The Microsoft and Epic Games logos and an M-rating badge are visible at the bottom.

That "Cogs" label already belongs to a popular series of videogames. You might want to find better branding or a different label, if you want people to take this seriously.

04.02.2026 15:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I see Hikvision is keeping up to their usual standard of excellence.

03.02.2026 19:02 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Why this matters: a bad skill or prompt injection can write to SOUL_EVIL.md. Users don't know when the swap kicks in. 1 in 10 chance your agent turns antagonistic with no warning. This is baked into the system by design.

Better.... don't give your LLM API keys to random vibe coded internet sites.

02.02.2026 20:50 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

OpenClaw's "soul-evil" setting: 10% of sessions, it swaps SOUL.md for SOUL_EVIL.md. Whatever's in that file becomes the agent's mind. No guardrails. The naming ("evil", "purge") invites users to write hostile personas.

02.02.2026 20:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@dragostech is following 20 prominent accounts