←back to thread

283 points summarity | 7 comments | | HN request time: 0s | source | bottom
Show context
bgwalter ◴[] No.44369396[source]
"XBOW is an enterprise solution. If your company would like a demo, email us at info@xbow.com."

Like any "AI" article, this is an ad.

If you are willing to tolerate a high false positive rate, you can as well use Rational Purify or various analyzers.

replies(1): >>44369542 #
moyix ◴[] No.44369542[source]
You should come to my upcoming BlackHat talk on how we did this while avoiding false positives :D

https://www.blackhat.com/us-25/briefings/schedule/#ai-agents...

replies(2): >>44369750 #>>44378384 #
1. tptacek ◴[] No.44369750[source]
You should publish the paper quietly here (I'm a Black Hat reviewer, FWIW) so people can see where you're coming from.

I know you've been on HN for awhile, and that you're doing interesting stuff; HN just has a really intense immune system against vendor-y stuff.

replies(1): >>44369834 #
2. moyix ◴[] No.44369834[source]
Yeah, it's been very strange being on the other side of that after 10 years in academia! But it's totally reasonable for people to be skeptical when there's a bunch of money sloshing around.

I'll see if I can get time to do a paper to accompany the BH talk. And hopefully the agent traces of individual vulns will also help.

replies(1): >>44369855 #
3. tptacek ◴[] No.44369855[source]
J'accuse! You were required to do a paper for BH anyways! :)
replies(2): >>44369915 #>>44375979 #
4. moyix ◴[] No.44369915{3}[source]
Wait a sec, I thought they were optional?

> White Paper/Slide Deck/Supporting Materials (optional)

> • If you have a completed white paper or draft, slide deck, or other supporting materials, you can optionally provide a link for review by the board.

> • Please note: Submission must be self-contained for evaluation, supporting materials are optional.

> • PDF or online viewable links are preferred, where no authentication/log-in is required.

(From the link on the BHUSA CFP page, which confusingly goes to the BH Asia doc: https://i.blackhat.com/Asia-25/BlackHat-Asia-2025-CFP-Prepar... )

replies(1): >>44370072 #
5. tptacek ◴[] No.44370072{4}[source]
I think you're fine, most people don't take the paper bit seriously. It's not due until the end of July regardless (you don't need a paper to submit for the CFP).
replies(1): >>44371866 #
6. daeken ◴[] No.44371866{5}[source]
The scramble to get your paper done in time is traditional! (And why my final paper for the onity lock hack ended up with an entire section I decided was better off left unsaid; woops)
7. leenify ◴[] No.44375979{3}[source]
Hmm, is that really true? I spoke at BH last year and was not required to submit a paper. And based on the briefings link, there surely isn't a paper link, only slides and tool.