
Daily Dave Mailing List
This technical discussion list covers vulnerability research, exploit development, and security events/gossip. It was started by ImmunitySec founder Dave Aitel and many security luminaries participate. Many posts simply advertise Immunity products, but you can't really fault Dave for being self-promotional on a list named DailyDave.
List Archives
- Jan–Mar
- Apr–Jun
- Jul–Sep
- Oct–Dec
- 2025
- 10
- 5
- –
- 7
- 2024
- 9
- 14
- 14
- 4
- 2023
- 3
- 13
- 14
- 5
- 2022
- 6
- 4
- 18
- –
- 2021
- 11
- 2
- 4
- 1
- 2020
- 15
- 10
- 19
- 8
- 2019
- 38
- 8
- 12
- 15
- 2018
- 23
- 12
- 15
- 16
- 2017
- 41
- 37
- 43
- 20
- 2016
- 63
- 74
- 54
- 16
- 2015
- 62
- 51
- 68
- 63
- 2014
- 85
- 57
- 68
- 88
- 2013
- 77
- 53
- 67
- 71
- 2012
- 70
- 65
- 89
- 55
- 2011
- 40
- 113
- 90
- 87
- 2010
- 86
- 68
- 55
- 56
- 2009
- 143
- 146
- 129
- 74
- 2008
- 161
- 136
- 252
- 134
- 2007
- 324
- 209
- 176
- 193
- 2006
- 270
- 220
- 315
- 318
- 2005
- 352
- 399
- 408
- 281
- 2004
- 247
- 204
- 294
- 361
- 2003
- –
- –
- –
- 84
Latest Posts
Re: Defense ?
Dean Pierce via Dailydave (Nov 16)
I like the idea of having a software supply chain that people can pay into
that basically funds a universal bug bounty system for anything that
matters.
You can put systems in place that utilize zero knowledge exploitability
proofs to automate bounty triage, so it doesn't even need to be run by a
central trusted entity. As the bounty markets stabilize, what you're left
with is a software ecosystem where anyone can build what they need...
Re: Defense ?
Chris Anley via Dailydave (Nov 16)
(gingerly raises head above parapet)
Historically, “we’ve” moved the bar in defense.
- Everything is now in the cloud, accessible 24/7 via APIs whose keys are stored in plaintext alongside code, or via
preauthenticated sessions
- Everything has ~40 dependencies, each of which has ~40 dependencies, etc, which, combined with a published CVE rate
of 1 per 15 minutes (calendar year 2024), means that patching an enterprise before an...
Re: Defense ?
Alfonso De Gregorio via Dailydave (Nov 16)
Imbalances in the skills and workforce are real. The gap remains hard
to bridge also in the presence of greater degrees of automation that
AI buys us, because, at this stage, we want humans to be in the loop –
and for good reasons – and, also, cause we are not going to grow the
skillset faster than the attack surface, I am afraid.
I hate to sound like a broken record, but I will take a bite
regardless: those imbalances are a byproduct of the...
Re: Defense ?
Conan Dooley via Dailydave (Nov 16)
Reduce complexity, duplication, and scope in your infrastructure. Your
developers and infrastructure staff would need to agree on standardized
libraries, frameworks, etc, and you'd need skilled technical staff to
validate when people said doing something wasn't possible within that
scope, and make them accountable for making sure adding that level of
complexity led to business value that was greater than that overhead (vs,
say, just...
Re: Defense ?
etojake--- via Dailydave (Nov 16)
The content of this message was lost. It was probably cross-posted to
multiple lists and previously handled on another list.
Defense ?
Dave Aitel via Dailydave (Nov 15)
How would one actually move the actual bar in defense? A big part of me
thinks that you're just not going to patch your way out of the problem. But
the number of organizations that you can rely on to actually make a
difference seems pretty small? Like even converting every Linux binary to
rust would only make sense if you could find a team that could actually
maintain and support that code base, which I don't know that you could.
Like...
Offensive AI Con
Dave Aitel via Dailydave (Oct 08)
So I just got back from "Offensive AI Conference" in San Diego and it was a
great event - for a first time conference it ran especially smoothly, the
attendees were an amazing crowd, and many of the talks were extremely
strong. There's something about a conference that is not recording the
talks that gets people to actually sit and listen to them via the magic of
FOMO, but also, when a conference is "invite only" then you...
More Lists
Dozens of other network security lists are archived at SecLists.Org.
