Zardus @zardus.bsky.social · 10/08/2026Hello hackers! I accidentally came into possession of this DEF CON hat. Is this yours? If so, let me know! Let’s get this hat home! 000
Zardus @zardus.bsky.social · 09/08/2026Hello hackers! Earned your @pwncollege belt and want to get it live? Come to the DEF CON Academy belting ceremony today at 12:30pm! See you there in Hall 4! 020
Zardus @zardus.bsky.social · 08/08/2026Hello hackers! If you reached out to chat with me during DEF CON about life, security, and CTF, and I haven't had a chance to reply, I'll chill out at DEF CON Academy for a sort of impromptu Zardus office hours at 2pm! Come hang out and chat (and LEARN TO HACK!) in Hall 4! 000
Zardus @zardus.bsky.social · 08/08/2026The DEF CON Academy is open! Come in, use our laptops, and LEARN TO HACK with awesome mentors. Swag alert: first 3 new hackers to finish an intro module in Web, Crypto, Network, or Binary hacking will win an exclusive limited edition @pwncollege white belt! See you in Hall 4! 011
Zardus @zardus.bsky.social · 07/08/2026Hello hackers! DEF CON Academy is up and running in Hall 4. Our goal is to take people from the wandering the hallways to actively learning to hack! We have (very beginner-friendly!) learning material, challenges, mentors to help, and laptops for you to use. Come on by! 011
Zardus @zardus.bsky.social · 16/05/2026As of yesterday's Usenix Security notifications, I have received a cumulative 199 paper rejections in my research career! One more to 200! 🤞🤞🤞🤞🤞 060
Zardus @zardus.bsky.social · 02/05/2026For those that don't recall, SynSec is an experiment on agentically-executed scientific research in all areas of cybersecurity. All papers must have an AI model as first author, though we *do* have a human-first-author track too. Go prompt some science!synsec.orgConference of Synthetic Security ResearchSynSec 2026 is a hybrid (in-person and online) conference in Phoenix focused on automated security research by AI agents, including AI-led papers and AI-first peer review. 010
Zardus @zardus.bsky.social · 02/05/2026Reminder! Today is the submission deadline for the first ever Conference of Synthetic Security Research @synsec_ai, so unless you want to gamble on a(nother) extension, warm up those agents and get those papers submitted! 111
Zardus @zardus.bsky.social · 28/04/2026This concludes what may be the longest tweet thread I've ever written. Interested to hear your thoughts! safelibs.org safelibs.org/apt hub.docker.com/r/saf... github.com/safelibs/ If you want to chat in person, I’m at DEF CON Singapore at DEF CONAcademy!safelibs.orgSafeLibs | Memory-safe drop-in replacementsSafeLibs builds memory-safe (Rust) reimplementations of critical load-bearing C/C++ libraries used throughout open source infrastructure, while attempting to preserve drop-in co... 110
Zardus @zardus.bsky.social · 28/04/2026Finally, credit where credit is due: @DARPA's TRACTOR program (www.darpa.mil/resear...) was first to suggest we Translate All C TO Rust. It's been on my mind since its announcement, and it wouldn't have occurred to me do this otherwise! As usual, DARPA is leading the way here!darpa.milTRACTOR: Translating All C to Rust | DARPAThis program aims to automate the translation of legacy C code to Rust. The goal is to achieve the same quality and style that a skilled Rust developer would produce, thereby eliminating the entire class of memory safety security vulnerabilities present in C programs. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Brainrot? I wrote no code for this project. It's awesome to harness the power of this emerging tech, but I *liked* writing code. Now, it occupies a similar conceptual space as gardening (a mental health supporting hobby) and is equally hard to prioritize. A bit of a bummer. 100
Zardus @zardus.bsky.social · 28/04/2026Q: AI? With ASU's infinite codex experiment concluded, we don't have a good solution here. Currently, I've exhausted my weekly codex and am sitting idle, which is why we're at 15 verified libraries and not 24. Maybe there's someone out there that can toss some tokens our way ;-) 100
Zardus @zardus.bsky.social · 28/04/2026Q: Humanpower? This still takes a lot of humanpower. Scaling it is tricky (see: supply chain attacks, security). If I trust you and you're interested in helping, let me know! Or, if you are in a position to do so, consider sponsoring our lab to keep this type of work going! 100
Zardus @zardus.bsky.social · 28/04/2026For the latter, I created a repo of library functionality validation scripts that people can report bugs against (github.com/safelibs/...), which I'll slop testcases from and then have a Test workflow step fix the port to pass the testcases. I think this will be a good balance.github.comGitHub - safelibs/validatorContribute to safelibs/validator development by creating an account on GitHub. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Bugs/Contributions? I haven't even read the ported code, so there's no way in hell I'll take PRs on it. With supply chain attacks running wild, it's just too dangerous. I've settled on accepting contributions of prompting/workflow PRs and port misbehavior bug reports. 100
Zardus @zardus.bsky.social · 28/04/2026One obvious solution is to use more agents to audit the agent-generated code. It would be especially cool to see what a next-generation frontier model could do here, if a frontier lab wants to collaborate on this! Looking at you, @anthropic, @openai, @googleai. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Security? These libs are 100% slopped; I haven't read a single line. I don't even really DO rust, but even if I did, there's just too much to read here! I have checkers that check for overuse of unsafe and so on, but at some point, we have to trust the agents here... 100
Zardus @zardus.bsky.social · 28/04/2026Q: Ubuntu? Our ubuntu drop-in-replacement focus forces ABI compatibility and some other choices. It's a good start, but it would be really cool to extend this to something like nix, which seems better-suited to these sorts of replacements. If you're interested, let me know! 100
Zardus @zardus.bsky.social · 28/04/2026Overall, this is better than transpilation and is probably a good start (though estimating actual safety is definitely more difficult than counting blocks and lines), but there is clearly still work to be done to make these ports even safer. 100
Zardus @zardus.bsky.social · 28/04/2026Additionally, because we're just porting libraries (for now!), the actual applications using these libraries will still be either written in (very unsafe!) C or use the (very unsafe!) library C API, so any flaws in a dependent application will of course still be dangerous. 100
Zardus @zardus.bsky.social · 28/04/2026Our ~2M lines of Rust contain ~17.6k unsafe blocks. Of these, ~13.5k handle C API/ABI translation. We can drop ABI compatibility (requiring recompilation of dependent apps) and eliminate many of these, but with our current Ubuntu focus, this complicates deployment and adoption. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Safety? Plenty of projects exist to transpile C to unsafe Rust, but that doesn't give any benefits in terms of safety. Agentically, we should be able to do better, but we are somewhat constrained by the API/ABI compatibility requirements. Let's dig in! 100
Zardus @zardus.bsky.social · 28/04/2026Obviously, we can probably slop up some such testcases and happily extend this beyond libraries. Definitely some potential future work here! 100
Zardus @zardus.bsky.social · 28/04/2026Q: Libraries? The testcase issue is also why this project focuses on libraries. Every program dependent on a library can serve as a testcase for that library, helping us port, but it's hard to get that many testcases (especially UI/UX ones) for normal applications. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Functionality? These reimplementations are only as good as the testcases that ground the agents. While one can argue that this is the case for any normal software, it still makes me nervous, and is the main reason I'm considering this a beta "use at your own risk" launch. 100
Zardus @zardus.bsky.social · 28/04/2026Q: Upgrades? How do we upgrade to new versions of the library? When I had infinite codex, I planned to just regenerate them fresh for every version, but now I've had to accept reality and add an Upgrade step (though haven't had a chance to test that out yet). 100
Zardus @zardus.bsky.social · 28/04/2026So, we've got 2 MILLION lines of rust across 24 in-progress (15 complete/tested) reimplemnetations. These libraries are runtime- and compile-time drop-in replacements for their existing equivalents in the Ubuntu repositories. Naturally, this raises many questions! 100
Zardus @zardus.bsky.social · 28/04/2026As a side note, I'm as concerned about brainrot as the next prof, but being able to casually throw 100 agents at any problem that comes to mind is a superpower. It really shifts what's possible, and we'll have other cool things coming out downstream of this capability soon! 100
Zardus @zardus.bsky.social · 28/04/2026Now, this uses a LOT of AI tokens! Luckily, @ASU came to the rescue here, providing INFINITE codex for every employee for the first quarter of the year! While this wasn't sustainable beyond the initial period, it let me leap ahead and get 20 libraries ported for this launch! 100
Zardus @zardus.bsky.social · 28/04/2026The result is pretty amazing. A library might take a full day in planning mode and three days of executing and checking workflow steps, but we can autonomously port massive codebases and end up with functional and reasonable rust rewrites! 100
Zardus @zardus.bsky.social · 28/04/2026We can use this: for every implementation step that Juvenal's agents carry out, Juvenal spawns several (fresh-context) validation agents that check the work for different properties. Anything missing gets punted back to the implementer, dozens of times if necessary. 100
Zardus @zardus.bsky.social · 28/04/2026Coding agents clock out early, lie, and cheat. What they *don't* do is have each other's back: they'll happily throw the work of another agent under the bus, feeling no obligation to cover for something as long as it doesn't share (and, thus, doesn't have to justify) its context! 100
Zardus @zardus.bsky.social · 28/04/2026... and falls on its face, because coding agents are brilliant but terrible. If one of Juvenal's intricately-crafted workflow steps fails, latter steps longer make sense. This would compromise the entire operation, but here we have Juvenal's core insight: agents are lazy liars. 100
Zardus @zardus.bsky.social · 28/04/2026Juvenal's plan creation is intense: it'll draft a high level workflow, iteratively refine it, split it into concrete steps, and keep iterating on this until everything makes sense. This can take as long an entire day of *just planning*, then it gets to implementing... 100
Zardus @zardus.bsky.social · 28/04/2026The Port phase does the main heavy lifting of actually porting the library. My "one size fits all" attempts for this all failed in the face of C library uniqueness, and so this uses an extensive planning step that produces and executes complex library-specific porting workflows. 100
Zardus @zardus.bsky.social · 28/04/2026This test expansion is critical here. My goal is that the ported library should be API & ABI compatible and work as a direct drop-in apt-installable replacement enabling trivial deployment. This requires a LOT of grounding for the agent, and the tests provide this grounding. 100
Zardus @zardus.bsky.social · 28/04/2026Next, Setup prepares the code for porting. This step includes ensuring that existing test cases use public library APIs when possible (to make them applicable to the rust port), and adding new testcases (both directly exercising the library and doing so through dependent apps). 100
Zardus @zardus.bsky.social · 28/04/2026Anyways, let's port some C libraries to rust! Step 1: Recon retrieves the original source (via Ubuntu's source packages; more on this later) and existing CVEs (to keep track of previous non-memory bugs). Not too complex; just three simple prompts. 100
Zardus @zardus.bsky.social · 28/04/2026To power this workflow, and to slop some other projects with high complexity, I made a workflow manager called Juvenal (after the Roman poet who famously asked something like "who prompts the agents?"). If you're interested, it's at github.com/zardus/ju... and explained latergithub.comGitHub - zardus/juvenal · GitHubContribute to zardus/juvenal development by creating an account on GitHub. 100
Zardus @zardus.bsky.social · 28/04/2026I solved this with a hierarchical workflow for the high-level process, with complex individual steps dynamically creating library-specific workflows. The main high-level steps I'll describe here are Recon, Setup, and Port, but the full workflow is here: github.com/safelibs/... 100
Zardus @zardus.bsky.social · 28/04/2026My first attempt at solving this was to create an intricate universal workflow to drive agents to porting C libraries, but to paraphrase Tolstoy, "each C library is C in its own way", and this universal workflow was too inflexible and required constant handholding as a result. 100
Zardus @zardus.bsky.social · 28/04/2026One solution is the "ralph loop" that tells the agent to just keep going (popularized by github.com/snarktank..., which does more than just the loop described here). However, with complex projects, this can send the agent down crazy rabbit holes from which it will never emerge.github.comGitHub - snarktank/ralph: Ralph is an autonomous AI agent loop that runs repeatedly until all PRD items are complete.Ralph is an autonomous AI agent loop that runs repeatedly until all PRD items are complete. - snarktank/ralph 100
Zardus @zardus.bsky.social · 28/04/2026For example, laziness. This isn't their fault: the training process has to have limits, and you can intuitively feel these limits in the boundaries that agents place on their efforts. Given a massive task, like, "convert libjpeg to rust", an agent will take a few steps and quit. 100
Zardus @zardus.bsky.social · 28/04/2026On the face of it, coding agents should just be able to convert a C program to rust. After all, why not? It's just translation from one capable language to another. However, even today's cutting-edge agents suffer from a few issues. 100
Zardus @zardus.bsky.social · 28/04/2026If you want to ignore the "how" in the rest of the thread and get to "what", you can find translated libraries (two million lines of rust!), easily apt-get installable, at safelibs.org! Enjoy! For the interested readers, we'll dig in below!safelibs.orgSafeLibs | Memory-safe drop-in replacementsSafeLibs builds memory-safe (Rust) reimplementations of critical load-bearing C/C++ libraries used throughout open source infrastructure, while attempting to preserve drop-in co... 100
Zardus @zardus.bsky.social · 28/04/2026Can we translate all C to Rust? The susceptibility of C to memory corruption has long been a cybersecurity pain point, and coding agents can free us of it. Read on for my recent experiments in this space, and apt & docker repos that you can pull rust-converted libraries from! 153
Zardus @zardus.bsky.social · 28/04/2026Hello hackers! The first DEF CONAcademy mentoring session at DEF CON Singapore is happening NOW! Drop by the DEFCON Academy area and ask us any pressing questions you might have about academic cybersecurity; we'll be here! 000
Zardus @zardus.bsky.social · 28/04/2026Aside from hacking mentors, we also have a series of talks! We'll have two daily "hack with us" sessions with either small presentations or challenge walkthroughs and a mentoring session for those interested in academia, industry, etc. Check out the schedule on HackerTracker! 010
Zardus @zardus.bsky.social · 28/04/2026Hello hackers! DEF CONAcademy is LIVE at DEF CON Singapore! For those who're new to the concept, DEFCON Academy is a first-stage education community. We have laptops, material, and l337 h4X0R mentors standing by to help you learn. Drop by and LEARN TO HACK with us! 120
Zardus @zardus.bsky.social · 03/04/2026We've also finalized the venue, with the live conference moving up to October! All the dates: - Submission: May 1 - Notification: Jun 1 - Camera Ready: July 1 - Conference: October 22–23 Looking forward to your (agents') research! Stay up to date at synsec.org!synsec.orgConference of Synthetic Security ResearchSynSec 2026 is a hybrid (in-person and online) conference in Phoenix focused on automated security research by AI agents, including AI-led papers and AI-first peer review. 010