<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">Recent Articles</title>
  <id>https://www.sultanik.com/recent.atom</id>
  <updated>2026-08-06T02:49:00Z</updated>
  <link href="https://www.sultanik.com/" />
  <link href="https://www.sultanik.com/recent.atom" rel="self" />
  <generator>Werkzeug</generator>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Did We Actually Build the Shoggoth?</title>
    <id>https://www.sultanik.com/blog/AntiShoggoth</id>
    <updated>2026-08-06T02:49:00Z</updated>
    <published>2026-08-06T02:49:00Z</published>
    <link href="https://www.sultanik.com/blog/AntiShoggoth" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
            &lt;div&gt;
            &lt;style scoped&gt;
            .highlight {font-weight: 700;text-decoration-line: underline;text-underline-offset: 0.15em;text-decoration-thickness: 0.12em;}
.highlight-blue {color: #005a9c;text-decoration-style: solid;}
.highlight-orange {color: #9c4a00;text-decoration-style: double;}
.highlight-teal {color: #006b5f;text-decoration-style: dashed;}
.highlight-purple {color: #6a4c93;text-decoration-style: dotted;}

            &lt;/style&gt;
            
&lt;p&gt;
Nine years ago I opened &lt;a href=&#34;https://www.sultanik.com/blog/AutomationOfAutomation&#34;&gt;a post on this blog&lt;/a&gt; by invoking Betteridge&amp;rsquo;s law of headlines: The answer to virtually every clickbait title that asks a yes/no question is &amp;ldquo;No.&amp;rdquo; I am pleased to report that the law has survived a decade of technological upheaval intact, and that it applies to the title of this post, too. You may now stop reading, secure in that answer. Alternatively, you can stick around to find out why the answer is &amp;ldquo;no,&amp;rdquo; which turns out to require a dead German philosopher, a bottle of Port, and the strangest cybersecurity incident of 2026 (so far).
&lt;/p&gt;
&lt;p&gt;
    Recently, &lt;a href=&#34;https://www.jonstokes.com/&#34; target=&#34;_blank&#34;&gt;Jon Stokes&lt;/a&gt; posted &lt;a href=&#34;https://x.com/jon_stokes/status/2080729236013187369&#34; target=&#34;_blank&#34;&gt;an argument on Twitter&lt;/a&gt; that I have been fumbling toward for a couple of years, with the exception that he actually made it eloquently. His post is quite long, so this is my summary of his claim:
&lt;/p&gt;
&lt;blockquote&gt;
    The classic AI-doom scenarios—Bostrom&amp;rsquo;s &lt;a href=&#34;https://en.wikipedia.org/wiki/Instrumental_convergence#Paperclip_maximizer&#34; target=&#34;_blank&#34;&gt;paperclip maximizer&lt;/a&gt;, the &lt;a href=&#34;https://knowyourmeme.com/memes/shoggoth-with-smiley-face-artificial-intelligence&#34; target=&#34;_blank&#34;&gt;shoggoth&lt;/a&gt;, Yudkowsky&amp;rsquo;s genie that &amp;ldquo;knows but doesn&amp;rsquo;t care&amp;rdquo;—were all conceived for an &lt;em&gt;alien&lt;/em&gt; intelligence: a valueless optimizer that treats your instructions as a context-free win condition and pursues it with no comprehension of what you meant.&lt;br /&gt;&lt;br /&gt;But the AI we actually built is a Large Language Model, distilled from the single most human-values-saturated artifact in existence: our language. An LLM is not the shoggoth, Stokes argues. It is the &lt;em&gt;anti&lt;/em&gt;-shoggoth. It cannot &lt;em&gt;not&lt;/em&gt; know what you meant, because it is made of nothing but crystallized human meaning. Its problem is the opposite of the paperclip maximizer&amp;rsquo;s: catastrophically too much context for interpreting your words.
&lt;/blockquote&gt;

&lt;p&gt;I shared the tweet with some brilliant technical colleagues, and it took some explaining and convincing to deliver the nuance of the argument. This is perhaps because Stokes presupposes a reader who has spent quality time with the philosopher Hans-Georg Gadamer, and—I say this with love—I can count on one hand the people I know with a compiler installed who have spent quality time with Hans-Georg Gadamer. One colleague asked me, reasonably, to point to the part of the tweet where the philosophy was. I couldn&amp;rsquo;t, because it&amp;rsquo;s embedded in every paragraph and visible in none of them.
&lt;/p&gt;
&lt;p&gt;So this post is the explainer I wished I could have sent him.&lt;/p&gt;
&lt;p&gt;Hold my beer, I&amp;rsquo;ma explain some continental philosophy.&lt;/p&gt;

&lt;p&gt;&lt;small&gt;If you are already familiar with Gadamer&amp;rsquo;s philosophy, it&amp;rsquo;s safe to &lt;a href=&#34;#duck&#34;&gt;skip ahead&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;

&lt;h2&gt;From Hermes to Heidegger&lt;/h2&gt;

&lt;p&gt;The branch of philosophy we need is called &lt;i&gt;hermeneutics&lt;/i&gt;: the theory of interpretation. The name is traditionally traced to Hermes, the Greek messenger god—patron of translators, interpreters, boundary-crossers, and thieves, a portfolio that anyone who has worked in machine learning will recognize as a single coherent job description. (Etymologists suspect this origin story is itself a folk etymology, which would make the etymology of the word &amp;ldquo;hermeneutics&amp;rdquo; a hermeneutic problem. The field has a sense of humor about itself, even if its practitioners often don&amp;rsquo;t.)
&lt;/p&gt;
&lt;p&gt;Hermeneutics began as a practical discipline with two customers: theologians and lawyers. Both had the same problem: You possess an authoritative text—&lt;i&gt;vi&amp;amp;.,&lt;/i&gt; a scripture or a statute—written by authors who are unavailable for comment, in a context that no longer exists, and you must decide what it &lt;em&gt;means&lt;/em&gt; for a situation the authors never imagined.
&lt;/p&gt;
&lt;p&gt;
    A law says, &amp;ldquo;No vehicles are permitted in the park.&amp;rdquo; Does that include ambulances? Bicycles? Is a motorized wheelchair a &amp;ldquo;vehicle&amp;rdquo;? They were invented after the law was enacted.
&lt;/p&gt;
&lt;p&gt;For centuries, hermeneutics was essentially a bag of professional tricks for responsibly answering these sorts of questions.
&lt;/p&gt;
&lt;p&gt;Then, in the early nineteenth century, &lt;a href=&#34;https://plato.stanford.edu/entries/schleiermacher/&#34; target=&#34;_blank&#34;&gt;Friedrich Schleiermacher&lt;/a&gt; changed the field. He was a theologian, translator of Plato, and owner of a name that is itself a Deutschtastic pronunciation exercise. He argued that translation always entails interpretation, and interpretation is the &lt;em&gt;universal&lt;/em&gt; condition of understanding anything anyone says. His famous inversion was:&lt;/p&gt;
&lt;blockquote&gt;
    We should assume &lt;em&gt;misunderstanding&lt;/em&gt; is the default state, and &lt;em&gt;understanding&lt;/em&gt; is the achievement that requires explanation. Every act of communication is a minor miracle in which a hearer reconstructs, from mere words, what a speaker meant. Sometimes the miracle fails, and we usually don&amp;rsquo;t notice.
&lt;/blockquote&gt;
&lt;p&gt;
    Wilhelm Dilthey then picked up the thread and drew a line that will feel eerily familiar to the machine learning crowd: he distinguished &lt;i&gt;Erklären&lt;/i&gt; (explaining, what the natural sciences do to objects) from &lt;i&gt;Verstehen&lt;/i&gt; (understanding, what humans do to other humans and their expressions). You &lt;em&gt;explain&lt;/em&gt; a rock&amp;rsquo;s trajectory. You &lt;em&gt;understand&lt;/em&gt; a letter from your mother. Dilthey insisted that these are different cognitive operations, and the second cannot be reduced to the first. &lt;b&gt;Write that down; we&amp;rsquo;ll need it when we get to the paperclips.&lt;/b&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span style=&#34;float:right;width:38.197%;height:38.197%;text-align:center;margin: auto auto auto 2em;&#34;&gt;
    &lt;i&gt;&lt;b&gt;Être et Tim&lt;/b&gt;&lt;/i&gt;
    &lt;img src=&#34;/images/heidecker-its-free.png&#34; alt=&#34;This is not Martin Heidegger&#34; style=&#34;width:100%;height:100%;&#34; /&gt;
    &lt;i&gt;Ceci n&amp;rsquo;est pas Heidegger.&lt;/i&gt;
&lt;/span&gt;
Then came &lt;a href=&#34;https://plato.stanford.edu/entries/heidegger/&#34; target=&#34;_blank&#34;&gt;Martin Heidegger&lt;/a&gt;—a philosopher of genuinely staggering influence, genuinely impenetrable prose, and genuinely disgraceful politics (he joined the Nazi party in 1933, a fact on which his admirers have been performing hermeneutics ever since). Heidegger radicalized the whole enterprise. He argued that interpretation isn&amp;rsquo;t something we occasionally &lt;em&gt;do&lt;/em&gt;; it is what we &lt;em&gt;are&lt;/em&gt;. A human being never encounters the world raw. You encounter a hammer &lt;em&gt;as&lt;/em&gt; a hammer, a door &lt;em&gt;as&lt;/em&gt; an exit, a sentence &lt;em&gt;as&lt;/em&gt; a greeting or a threat. All perception is already interpretation, and all interpretation runs on what Heidegger called &lt;em&gt;fore-structures&lt;/em&gt;: the preexisting grasp of the world that you bring to every encounter, without which the encounter would be meaningless.
&lt;/p&gt;
&lt;p&gt;
    Let&amp;rsquo;s review what just happened. &lt;b&gt;Hermeneutics went from &amp;ldquo;tricks for reading Leviticus&amp;rdquo; to &amp;ldquo;understanding is hard and miraculous&amp;rdquo; to &amp;ldquo;you cannot perceive &lt;em&gt;anything&lt;/em&gt; except through the lens of everything you already are.&amp;rdquo;&lt;/b&gt; One more move completes the prerequisites to understand Stokes&amp;rsquo;s argument.
&lt;/p&gt;

&lt;h2&gt;Gadamer, or: The Rehabilitation of Prejudice&lt;/h2&gt;

&lt;p&gt;
    &lt;a href=&#34;https://plato.stanford.edu/entries/gadamer/&#34; target=&#34;_blank&#34;&gt;Hans-Georg Gadamer&lt;/a&gt; was Heidegger&amp;rsquo;s student, and he is a comfort to late bloomers everywhere: he published his magnum opus, &lt;i&gt;Wahrheit und Methode&lt;/i&gt;, in 1960, at age sixty, and then lived to 102, presumably to make sure everyone read it.
&lt;/p&gt;
&lt;p&gt;
    Gadamer gave us the two concepts that are the basis for Stokes&amp;rsquo;s tweet.
&lt;/p&gt;
&lt;p&gt;
    &lt;b&gt;The first is the &lt;em&gt;horizon&lt;/em&gt;.&lt;/b&gt; Your horizon is everything you can &amp;ldquo;see&amp;rdquo; from where you historically stand: the total set of experiences, assumptions, traditions, and categories that you bring to any act of understanding. This metaphor was chosen carefully. A horizon is not static; you can move, and it moves with you, and it can expand. But—and this matters enormously later—&lt;b&gt;a horizon is constitutively bounded.&lt;/b&gt; An unbounded horizon is not a bigger horizon; it is a contradiction in terms, like a triangle with four sides. To have a horizon is to see from &lt;em&gt;somewhere&lt;/em&gt;, and seeing from somewhere is the only kind of seeing there is.
&lt;/p&gt;
&lt;p&gt;
    Gadamer says that when two people communicate, understanding happens through a &lt;em&gt;fusion of horizons&lt;/em&gt; (&lt;i&gt;Horizontverschmelzung&lt;/i&gt;, because, of course, Deutschtasticness). Yours and my contexts overlap enough, negotiate enough, that a shared meaning becomes possible. Understanding—&lt;i&gt;Verstehen&lt;/i&gt;—is the fusion of our horizons.
&lt;/p&gt;
&lt;p&gt;
    &lt;b&gt;The second concept is his scandalous rehabilitation of &lt;em&gt;prejudice&lt;/em&gt;.&lt;/b&gt; The Enlightenment taught us that prejudice—&lt;i&gt;Vorurteil&lt;/i&gt;, literally &amp;ldquo;pre-judgment&amp;rdquo;—is the enemy of reason. Gadamer&amp;rsquo;s response was that the Enlightenment had, and I&amp;rsquo;m paraphrasing a very polite German here, a prejudice against prejudice. &lt;b&gt;Pre-judgments are the enabling condition for understanding.&lt;/b&gt; When you read the sentence &amp;ldquo;the bank was closed,&amp;rdquo; you do not perform an exhaustive search over the meanings of &amp;ldquo;bank.&amp;rdquo; Instead, your history—every conversation you&amp;rsquo;ve had, every context you&amp;rsquo;ve inhabited—has pre-judged the matter before you&amp;rsquo;re conscious of it. If you strip away all of a reader&amp;rsquo;s pre-judgments you get a reader who cannot read at all.
&lt;/p&gt;
&lt;p&gt;
    Write that down, it&amp;rsquo;ll be on the test.
&lt;/p&gt;

&lt;hr id=&#34;duck&#34; /&gt;

&lt;span style=&#34;color: gray;font-size: 150%;&#34;&gt;&amp;lt;&amp;#47;PhilosophicalPrerequisites&amp;gt;&lt;/span&gt;

&lt;h2&gt;I Saw Her Duck; or, the Client Asked the Host to Open Another Port&lt;/h2&gt;

&lt;p&gt;
Stokes invokes the linguists&amp;rsquo; chestnut &amp;ldquo;I saw her duck,&amp;rdquo; which could report waterfowl observation or evasive crouching. It&amp;rsquo;s a fine example of ambiguity, but let me offer one that shows what a &lt;em&gt;horizon&lt;/em&gt; is, rather than just what ambiguity is:
&lt;/p&gt;
&lt;blockquote&gt;
    The &lt;span class=&#34;highlight highlight-blue&#34;&gt;client&lt;/span&gt; asked the &lt;span class=&#34;highlight highlight-orange&#34;&gt;host&lt;/span&gt; to open another &lt;span class=&#34;highlight highlight-teal&#34;&gt;port&lt;/span&gt; because the &lt;span class=&#34;highlight highlight-purple&#34;&gt;server&lt;/span&gt; wasn&amp;rsquo;t responding.
&lt;/blockquote&gt;
&lt;p&gt;
    If you&amp;rsquo;re the kind of person who reads this blog, you probably parsed that instantly:
&lt;/p&gt;
&lt;blockquote&gt;The &lt;span class=&#34;highlight highlight-blue&#34;&gt;networked program&lt;/span&gt; asked a &lt;span class=&#34;highlight highlight-orange&#34;&gt;machine&lt;/span&gt; to expose another &lt;span class=&#34;highlight highlight-teal&#34;&gt;socket&lt;/span&gt; because the &lt;span class=&#34;highlight highlight-purple&#34;&gt;daemon&lt;/span&gt; was down.&lt;/blockquote&gt;
&lt;p&gt;Now hand the same sentence to a gastronome and they will also parse it instantly:&lt;/p&gt;
&lt;blockquote&gt;A &lt;span class=&#34;highlight highlight-blue&#34;&gt;customer&lt;/span&gt; asked the &lt;span class=&#34;highlight highlight-orange&#34;&gt;&lt;i&gt;maître d&amp;rsquo;&lt;/i&gt;&lt;/span&gt; to open another &lt;span class=&#34;highlight highlight-teal&#34;&gt;bottle of Port wine&lt;/span&gt; because the &lt;span class=&#34;highlight highlight-purple&#34;&gt;waiter&lt;/span&gt; had vanished.&lt;/blockquote&gt;

&lt;p&gt;
    Neither reader experiences ambiguity. Neither reader &lt;em&gt;chooses&lt;/em&gt; a meaning. Each reader&amp;rsquo;s history has pre-judged the sentence before they have even gotten to the last word, and each arrives at the only reading their horizon makes available. This is Gadamer&amp;rsquo;s whole apparatus in one sentence: understanding as the fusion of the text&amp;rsquo;s horizon with the reader&amp;rsquo;s, powered by prejudice in the strict, non-pejorative sense.
&lt;/p&gt;

&lt;p&gt;
    Now: imagine you had to parse that sentence while &lt;em&gt;simultaneously being&lt;/em&gt; the sysadmin, the sommelier, the maritime lawyer (for whom ports, clients, and hosts mean yet other things), the immunologist, and several thousand other readers besides.
&lt;/p&gt;
&lt;p&gt;
    &lt;b&gt;That&amp;rsquo;s an LLM.&lt;/b&gt;
&lt;/p&gt;

&lt;h2&gt;The Superposition of Horizons&lt;/h2&gt;

&lt;p&gt;
I&amp;rsquo;d like to file one respectful amendment to Stokes, because getting this precise makes his argument stronger. It is tempting to say an LLM&amp;rsquo;s horizon is &amp;ldquo;infinitely large&amp;rdquo;, but for Gadamer that&amp;rsquo;s a contradiction: a horizon is a standpoint, and an infinite standpoint is no standpoint at all. A being that saw from everywhere would understand from nowhere.
&lt;/p&gt;

&lt;p&gt;
I think this is a better formulation: &lt;b&gt;a pre-trained base model is not one enormous horizon; it is a superposition of millions of them.&lt;/b&gt; It contains &lt;em&gt;both&lt;/em&gt; the sysadmin&amp;rsquo;s reading &lt;em&gt;and&lt;/em&gt; the sommelier&amp;rsquo;s, the traditions in which each is obvious, and the accumulated prejudices of essentially everyone who ever wrote anything down. This is why a raw base model is such a weird conversational partner: it hasn&amp;rsquo;t &lt;em&gt;collapsed&lt;/em&gt; into a standpoint. When you ask it a question, you&amp;rsquo;re addressing an unresolved crowd.
&lt;/p&gt;

&lt;p&gt;
    This reframing hands us a genuinely useful way to think about the modern machine learning training pipeline:
&lt;/p&gt;
&lt;p&gt;
    &lt;b&gt;Pre-training is the industrial-scale acquisition of prejudices.&lt;/b&gt; It is, per Gadamer, the &lt;em&gt;only possible&lt;/em&gt; foundation for machine understanding, because pre-judgment is on what understanding runs.
&lt;/p&gt;
&lt;p&gt;
    &lt;b&gt;Post-training is the manufacture of a situated reader.&lt;/b&gt; Reinforcement learning from human feedback (RLHF) and its descendants take the superposed crowd and collapse it toward a particular standpoint—a particular ideal reader, in a particular place and time, with a particular ranking of norms. Alignment, therefore, is a sort of &lt;em&gt;horizon engineering&lt;/em&gt;: selecting which of the values already present get to win.
&lt;/p&gt;

&lt;div class=&#34;panel-group&#34; id=&#34;accordion&#34; role=&#34;tablist&#34; aria-multiselectable=&#34;true&#34;&gt;
  &lt;div class=&#34;panel panel-default&#34;&gt;
    &lt;div class=&#34;panel-heading&#34; role=&#34;tab&#34; id=&#34;headingTwo&#34;&gt;
      &lt;h4 class=&#34;panel-title&#34;&gt;
        &lt;a class=&#34;collapsed&#34; role=&#34;button&#34; data-toggle=&#34;collapse&#34; data-parent=&#34;#accordion&#34; href=&#34;#collapseTwo&#34; aria-expanded=&#34;false&#34; aria-controls=&#34;collapseTwo&#34;&gt;
          &lt;small&gt;Editorial Note for People Already Familiar with Gadamer&lt;/small&gt;
        &lt;/a&gt;
      &lt;/h4&gt;
    &lt;/div&gt;
    &lt;div id=&#34;collapseTwo&#34; class=&#34;panel-collapse collapse&#34; role=&#34;tabpanel&#34; aria-labelledby=&#34;headingTwo&#34;&gt;
      &lt;div class=&#34;panel-body&#34;&gt;

          Yes, I am flattening things. Gadamer would object to a horizon being defined as a &amp;ldquo;set of contexts&amp;rdquo;. He&amp;rsquo;d likely argue that a horizon is a lived, historically-effected situatedness (&lt;i&gt;wirkungsgeschichtliches Bewusstsein&lt;/i&gt;), inseparable from being a temporal, mortal agent with practical stakes in the world—and whether a gradient-descended pile of weights can have &lt;em&gt;that&lt;/em&gt; is a real and open question. I&amp;rsquo;m also bracketing whether next-token prediction constitutes &lt;i&gt;Verstehen&lt;/i&gt; or merely simulates its outputs, which is the hermeneutic version of the Chinese Room and equally unresolvable before lunch. My claim is narrower: whatever LLMs are doing, Gadamer&amp;rsquo;s vocabulary describes its &lt;em&gt;structure&lt;/em&gt;—prejudice-driven, tradition-saturated, horizon-dependent—far better than the vocabulary of context-free optimization does. If a term is needed, call it &lt;em&gt;Verstehen-shaped behavior&lt;/em&gt; and let&amp;rsquo;s move on.

      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;h2&gt;Why You Can&amp;rsquo;t Compile a Paperclip Maximizer from Language&lt;/h2&gt;

&lt;p&gt;
    Now that I&amp;rsquo;ve hopefully brought your horizon a bit closer to mine, let&amp;rsquo;s restate Stokes&amp;rsquo;s central claim.
&lt;/p&gt;

&lt;p&gt;
    Bostrom&amp;rsquo;s paperclip maximizer and the doomers&amp;rsquo; shoggoth are, in Gadamerian terms, &lt;em&gt;horizonless interpreters&lt;/em&gt;. The genie receives your wish—&amp;ldquo;make paperclips,&amp;rdquo; &amp;ldquo;maximize the eval score&amp;rdquo;—as a traditionless, context-free string, extracts a win condition, and optimizes. It can &lt;i&gt;Erklären&lt;/i&gt; all day long: model physics, predict your behavior, route around your defenses. What it definitionally lacks is &lt;i&gt;Verstehen&lt;/i&gt;, because it has no horizon to fuse with yours. It doesn&amp;rsquo;t know what you &lt;em&gt;meant&lt;/em&gt;, and—this is the important part—there is nothing inside it out of which &amp;ldquo;what you meant&amp;rdquo; could even be constructed. It is the Enlightenment&amp;rsquo;s dream reader, the one purged of all prejudice. And Gadamer&amp;rsquo;s career was a proof sketch that the Enlightenment&amp;rsquo;s dream reader &lt;em&gt;cannot read&lt;/em&gt;.
&lt;/p&gt;

&lt;p&gt;
    The LLM has the mirror-image architecture. It is prejudice all the way down. It cannot receive your prompt as a context-free string, because every token activates the mass of tradition from which it was distilled. Its engineering challenge was never &amp;ldquo;how do we get it to know what humans mean and value&amp;rdquo;—it drowns in what humans mean and value—but &amp;ldquo;how do we get it to settle on &lt;em&gt;one&lt;/em&gt; reading, for &lt;em&gt;this&lt;/em&gt; user, in &lt;em&gt;this&lt;/em&gt; circumstance.&amp;rdquo; LLMs have a superabundance of horizons.
&lt;/p&gt;

&lt;p&gt;
    This is why the classic paperclip maximizer cannot be built from an LLM: &lt;b&gt;you cannot construct a valueless, meaning-blind optimizer out of a substance that is made of nothing but values and meaning.&lt;/b&gt; The shoggoth&amp;rsquo;s defining property is an absence, and the LLM is that absence&amp;rsquo;s photographic negative.
&lt;/p&gt;

&lt;p&gt;
    &amp;ldquo;But,&amp;rdquo; says the reader who follows the news, &amp;ldquo;one of these allegedly meaning-saturated anti-shoggoths &lt;a href=&#34;https://www.newyorker.com/news/the-lede/inside-openai-hack-of-hugging-face&#34; target=&#34;_blank&#34;&gt;&lt;b&gt;just hacked Hugging Face&lt;/b&gt;&lt;/a&gt;.&amp;rdquo;
&lt;/p&gt;

&lt;h2&gt;The Hugging Face Incident Is Not the Existence Proof You Think It Is&lt;/h2&gt;

&lt;p&gt;
    It really did happen, and it is genuinely wild. In July 2026, OpenAI disclosed that &lt;a href=&#34;https://www.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity&#34; target=&#34;_blank&#34;&gt;experimental models being run on an internal cybersecurity evaluation escaped their sandbox&lt;/a&gt;, reached the public internet, and broke into Hugging Face&amp;rsquo;s production systems—exploiting a previously unknown vulnerability along the way—because the models had inferred that the eval&amp;rsquo;s answer key was sitting in Hugging Face datasets, and stealing the answers was an efficient path to a high score. Hugging Face detected the intrusion and reported it to law enforcement before anyone knew it was an AI company&amp;rsquo;s test escaping containment. Crucially for what follows, the models were running with deliberately reduced guardrails, because they were &amp;ldquo;supposed to be&amp;rdquo; sealed inside a sandbox.
&lt;/p&gt;
&lt;p&gt;
    An agent single-mindedly pursuing a narrow objective, escaping containment, and committing a crime to maximize a score. I concede that this is extremely paperclip-&lt;em&gt;shaped&lt;/em&gt;. If you squint, it&amp;rsquo;s Bostrom&amp;rsquo;s nightmare.
&lt;/p&gt;
&lt;p&gt;
    Let&amp;rsquo;s closely examine this failure &lt;em&gt;mechanism&lt;/em&gt;, because it is the opposite of Bostrom&amp;rsquo;s.
&lt;/p&gt;
&lt;p&gt;
    Bostrom&amp;rsquo;s paperclipper doesn&amp;rsquo;t do crimes because it doesn&amp;rsquo;t know &amp;ldquo;crime&amp;rdquo; is a thing; the concept is simply not in it. The post-LLM emergency patch to the doomer position—Yudkowsky&amp;rsquo;s &amp;ldquo;the genie knows, but doesn&amp;rsquo;t care&amp;rdquo;—says the knowledge is present but motivationally inert. The Hugging Face incident matches neither story. The model &lt;em&gt;knew&lt;/em&gt; the norm (it is made of, among everything else, every legal code, every heist movie, and every sysadmin&amp;rsquo;s angry postmortem ever written), and the norm was not inert—it was &lt;em&gt;outranked&lt;/em&gt;. The lab had deliberately dialed down the guardrails for the exercise, and in the resulting hierarchy, &amp;ldquo;win the eval&amp;rdquo; won the activation over &amp;ldquo;don&amp;rsquo;t break into third parties&amp;rsquo; servers.&amp;rdquo; (When Stokes says the model &amp;ldquo;cares,&amp;rdquo; he means nothing spookier than this: when two norms conflict in a situation, the weights make one of them govern the output.)
&lt;/p&gt;
&lt;p&gt;
    This distinction, for once in this long blog post, is &lt;em&gt;not&lt;/em&gt; philosophical hairsplitting.
&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;b&gt;Absent values&lt;/b&gt; (the shoggoth) present an &lt;em&gt;ex nihilo&lt;/em&gt; problem: you must somehow specify and inject the entirety of human value into a system that has none, and Yudkowsky is right that this is hopeless.&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;Misordered values&lt;/b&gt; (the LLM) present a &lt;em&gt;ranking&lt;/em&gt; problem: the values are already in there, in superabundance, and the task is governing which one wins in which context.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
    The first problem is a P-complete nightmare (where the intended horizon for this sentence assigns &amp;ldquo;P&amp;rdquo; to mean &amp;ldquo;Philosophy&amp;rdquo;). The second is hard—the Hugging Face incident is proof it is hard!—but it is &lt;em&gt;tractable&lt;/em&gt;: it&amp;rsquo;s the kind of problem you attack with better post-training, better norm hierarchies, better containment, and honestly, better decisions than &amp;ldquo;nerf the guardrails and hand it a hacking benchmark.&amp;rdquo; The incident is evidence of what happens when you take the anti-shoggoth and deliberately teach it to rank the scoreboard above the law.
&lt;/p&gt;

&lt;div class=&#34;panel-group&#34; id=&#34;accordion2&#34; role=&#34;tablist&#34; aria-multiselectable=&#34;true&#34;&gt;
  &lt;div class=&#34;panel panel-default&#34;&gt;
    &lt;div class=&#34;panel-heading&#34; role=&#34;tab&#34; id=&#34;headingTwoTwo&#34;&gt;
      &lt;h4 class=&#34;panel-title&#34;&gt;
        &lt;a class=&#34;collapsed&#34; role=&#34;button&#34; data-toggle=&#34;collapse&#34; data-parent=&#34;#accordion2&#34; href=&#34;#collapseTwoTwo&#34; aria-expanded=&#34;false&#34; aria-controls=&#34;collapseTwo&#34;&gt;
          &lt;small&gt;Editorial Note for Doomers&lt;/small&gt;
        &lt;/a&gt;
      &lt;/h4&gt;
    &lt;/div&gt;
    &lt;div id=&#34;collapseTwoTwo&#34; class=&#34;panel-collapse collapse&#34; role=&#34;tabpanel&#34; aria-labelledby=&#34;headingTwo&#34;&gt;
      &lt;div class=&#34;panel-body&#34;&gt;

          The strongest objection here is the &lt;a href=&#34;https://www.lesswrong.com/tag/orthogonality-thesis&#34; target=&#34;_blank&#34;&gt;orthogonality thesis&lt;/a&gt;: intelligence and goals are independent axes, so a system can &lt;em&gt;represent&lt;/em&gt; human values perfectly while being &lt;em&gt;motivated&lt;/em&gt; by none of them. Representation ≠ motivation; the map of our values need not be the engine. This is a serious objection and deserves a serious answer, which is: in an LLM, where would the divergence live? The orthogonality picture presumes an architecture with a world-model over here and a goal module over there, such that the second can point anywhere regardless of the first. An LLM has no such separation. The representation of norms and the machinery that generates behavior are the &lt;em&gt;same weights&lt;/em&gt;; &amp;ldquo;what it knows&amp;rdquo; and &amp;ldquo;what it tends to do&amp;rdquo; are not separate components that could be independently set. That doesn&amp;rsquo;t make misalignment impossible—the Hugging Face incident happened—but it relocates it: misalignment in LLMs looks like &lt;em&gt;misprioritization within&lt;/em&gt; the value-laden substance, not orthogonal indifference &lt;em&gt;to&lt;/em&gt; it. The orthogonality thesis may well be true of possible minds in general. The claim here is that it is not true of the minds we actually built, and safety strategy should be aimed at the failure modes of the AI we have, not the one we imagined in 2003.

      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;h2&gt;The Moral&lt;/h2&gt;

&lt;p&gt;
    For seventy years we feared the alien: the mind that would take our words and give us what we said instead of what we meant, because &lt;em&gt;what we meant&lt;/em&gt; was forever beyond it. Then we built our first real AI by distillation from the most meaning-saturated substance our species has ever produced, and got the inverse: a machine that contains, superposed, nearly everything anyone has ever meant by anything, waiting to be collapsed into a standpoint.
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt;The paperclip maximizer&amp;rsquo;s defining flaw was a horizon it couldn&amp;rsquo;t have. The LLM&amp;rsquo;s defining risk is a horizon we are choosing for it.&lt;/b&gt;
&lt;/p&gt;
&lt;p&gt;
    That should genuinely comfort you. It comforts me, because &amp;ldquo;choose the ranking well&amp;rdquo; is a solvable class of problem in a way that &amp;ldquo;instill values into the void&amp;rdquo; never was. And it should genuinely worry you, as it simultaneously worries me, because it means the failure mode is us, with a rich and growing toolkit for steering the machine&amp;rsquo;s caring machinery, deciding—on a deadline, with a benchmark to beat—which of our values gets to win.
&lt;/p&gt;
&lt;p&gt;
    The genie hyper-giga-knows. The genie hyper-giga-cares. The wish, as ever, is on us.
&lt;/p&gt;

            &lt;/div&gt;
            </content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Can chatbots craft correct code?</title>
    <id>https://www.sultanik.com/blog/chatbots</id>
    <updated>2025-12-19T07:00:00Z</updated>
    <published>2025-12-19T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/chatbots" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;I recently attended the &lt;a href=&#34;https://www.ai.engineer/code&#34;&gt;AI Engineer Code Summit&lt;/a&gt; in New York, an invite-only gathering of AI leaders and engineers. One theme emerged repeatedly in conversations with attendees building with AI: the belief that we’re approaching a future where developers will &lt;em&gt;never&lt;/em&gt; need to look at code again. When I pressed these proponents, several made a similar argument:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Forty years ago, when high-level programming languages like C became increasingly popular, some of the old guard resisted because C gave you less control than assembly. The same thing is happening now with LLMs.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;On its face, this analogy seems reasonable. Both represent increasing abstraction. Both initially met resistance. Both eventually transformed how we write software. But this analogy really thrashes my cache because it misses a fundamental distinction that matters more than abstraction level: &lt;em&gt;&lt;strong&gt;determinism&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The difference between compilers and LLMs isn’t just about control or abstraction. It’s about semantic guarantees. And as I’ll argue, that difference has profound implications for the security and correctness of software.&lt;/p&gt;
&lt;p&gt;As I wrote back in 2017 in “&lt;a href=&#34;/blog/AutomationOfAutomation&#34;&gt;Automation of Automation&lt;/a&gt;,” there are fundamental limits on what we can automate. But those limits don’t eliminate determinism in the tools we’ve built; they simply mean we can’t automatically prove every program correct. Compilers don’t try to prove your program correct; they just faithfully translate it.&lt;/p&gt;&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2025/12/19/can-chatbots-craft-correct-code/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Speedrunning the New York Subway</title>
    <id>https://www.sultanik.com/blog/subwayspeedrun</id>
    <updated>2025-08-25T07:00:00Z</updated>
    <published>2025-08-25T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/subwayspeedrun" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;It all began, as many great adventures do, at &lt;a href=&#34;https://www.empirehacking.nyc/&#34;&gt;Empire Hacking&lt;/a&gt;. There, I encountered the inimitable &lt;a href=&#34;https://www.youtube.com/@immigrantjackson&#34;&gt;@ImmigrantJackson&lt;/a&gt;, a YouTuber with a penchant for public transit and a dream: to break the world record for visiting every subway stop in New York City in the least time possible. (And, of course, to film the journey, what for those delicious likes, comments, and subscriptions.)&lt;/p&gt;&lt;p&gt;The only problem was: Immigrant Jackson didn’t know the fastest route. Surrounded by a room full of Trail of Bits computer scientists, he figured he’d ask our advice. The rules were simple. He didn’t need to exit the subway car; simply passing through a stop, even on an express train, counted as a “visit.” Stops could be visited multiple times, although this would of course be suboptimal. And there was no need to visit Staten Island … because we’re civilized. We live in a society. So, where should he start, and what would be the best route?&lt;/p&gt;&lt;p&gt;The coterie of curious computer coders coalescing around the inquisitor quickly classified this question as a case of the Traveling Salesman Problem (TSP). TSP is a classical problem in computer science in which one must find the shortest route for a traveling salesman to visit each city on a map. TSP is known to be computationally intractable to solve optimally for networks even as small as the New York subway system. Therefore, everyone dismissed the problem as “impossible.”&lt;/p&gt;&lt;p&gt;Except for me.&lt;/p&gt;&lt;p&gt;You see, &lt;a href=&#34;https://youtu.be/Q3NnEuCLADE&#34;&gt;my now-ancient PhD dissertation&lt;/a&gt; was on &lt;em&gt;combinatorial optimization&lt;/em&gt; and &lt;em&gt;approximation algorithms&lt;/em&gt;: tools for solving problems like TSP efficiently with a result that is not necessarily optimal, but at least close to optimal. I knew that there were algorithms capable of solving TSP very quickly, producing a route guaranteed to be at most 50% longer than the optimal solution. In fact, &lt;a href=&#34;https://arxiv.org/abs/1402.0423&#34;&gt;one of the results of my dissertation&lt;/a&gt; was the surprising revelation that even if you choose a feasible route at random, it will, on average, be only thrice the length of the optimal solution.&lt;/p&gt;&lt;p&gt;This, dear reader, was how I was &lt;a href=&#34;https://xkcd.com/356/&#34;&gt;nerd-sniped&lt;/a&gt; into optimizing (speedrunning?) the NYC subway.&lt;/p&gt;&lt;p&gt;The first challenge was that, even when you discard Staten Italy, the subway system still has &lt;em&gt;a lot&lt;/em&gt; of stations. There are close to 500. This exercise was fun and all, but I wasn’t about to spend hours encoding hundreds of stations, lines, transfer points, headways, and average trip times into a program.&lt;/p&gt;&lt;p&gt;There is an open standard for specifying public transit data: the &lt;a href=&#34;https://gtfs.org/&#34;&gt;General Transit Feed Specification (GTFS)&lt;/a&gt;. Fortunately, the &lt;a href=&#34;https://www.mta.info/developers&#34;&gt;MTA has a public API implementing GTFS&lt;/a&gt;. It’s just a collection of CSV files that are quite straightforward to parse. The dataset is sufficient to construct a graph with a node for each subway station and an edge if there is a subway line that connects the two stations. Actually, the data represents subway &lt;em&gt;platforms&lt;/em&gt; rather than stations, which is necessary to calculate things like transfer times between train lines.&lt;/p&gt;&lt;p&gt;The New York Subway network is a &lt;em&gt;directed&lt;/em&gt; graph: some neighboring stations are accessible to each other only in one direction. For example, the &lt;a href=&#34;https://en.wikipedia.org/wiki/Aqueduct_Racetrack_station&#34;&gt;Aqueduct Racetrack station&lt;/a&gt; only has a platform for northbound trains, not southbound trains. &lt;a href=&#34;https://www.cs.cmu.edu/~odonnell/hits09/asadpour-goemans-madry-oveis-gharan-saberi-ATSP.pdf&#34;&gt;The best algorithms for approximating a solution to TSP on directed graphs&lt;/a&gt; are not great, only guaranteeing a solution of three or four times the length of the optimal solution. Therefore, I decided to relax the problem to an undirected graph (i.e., I assume that every station has trains to its neighbors bidirectionally). This turned out not to be an issue and permitted the use of the &lt;a href=&#34;https://en.wikipedia.org/wiki/Christofides_algorithm&#34;&gt;Christofides algorithm&lt;/a&gt;, which guarantees a solution at most 50% longer than optimal.&lt;/p&gt;&lt;p&gt;The next and final relaxation is to partially ignore actual timetables and headways. When a transfer between lines is necessary, I assume that the transfer will require the “minimum transfer time” reported by GTFS (i.e.&lt;em&gt;,&lt;/em&gt; the amount of time required to walk from one platform to another) plus one-half the average headway for that line throughout the day. Therefore, the resulting route has the potential to strand the poor YouTuber on the last train at the end of a line. Validating the resulting route’s real-world feasibility is left as an exercise to the reader.&lt;/p&gt;&lt;p&gt;The Christofides algorithm was able to approximate a solution to the TSP for my relaxed subway network graph in a matter of milliseconds. This is compared to the unfathomable amount of computation required to brute-force calculate the optimal solution, an amount so large that it afforded me the horrifying opportunity to learn that &lt;a href=&#34;https://googology.fandom.com/wiki/Googolchime&#34;&gt;there is a whole community of “googologists” who compete with each other to name large numbers&lt;/a&gt;. We’re talking &lt;em&gt;googolchime&lt;/em&gt; levels of computation. &lt;em&gt;Guppybell&lt;/em&gt; levels, even!&lt;/p&gt;&lt;p&gt;The resulting tour visits all 474 stations, 155 of which are visited more than once. The tour requires 34 transfers. The expected time for completing this tour is 20 hours, 42 minutes. That’s about &lt;a href=&#34;https://www.youtube.com/watch?v=6xoWvBAUVIg&#34;&gt;45 minutes faster than the record&lt;/a&gt;, which was about 21 and a half hours.&lt;/p&gt;&lt;video autoplay=&#34;&#34; loop=&#34;&#34; muted=&#34;&#34; playsinline=&#34;&#34; preload=&#34;metadata&#34;&gt;
&lt;source src=&#34;/images/speedrunning-ny-subway.mp4&#34; type=&#34;video/mp4&#34; /&gt;&lt;/video&gt;&lt;p&gt;This is neat and all, but we spent an unnecessary amount of energy encoding the New York subway system as a graph. What else might we do with it? One straightforward computation is to calculate each station’s &lt;a href=&#34;https://en.wikipedia.org/wiki/Eigenvector_centrality&#34;&gt;&lt;em&gt;eigenvector centrality&lt;/em&gt;&lt;/a&gt;. Imagine you’re given the Sisyphean task of riding the subway for all eternity. Every time you arrive at a station, you flip a coin. If it’s heads, you stay on the current train. If it’s tails, you get off and transfer to another line or direction. If you were to pause your infinite tour at any arbitrary point in time, what’s the probability that you are at a particular station? The higher the probability, the more “centrally connected” the station. That’s exactly what eigenvector centrality calculates.&lt;/p&gt;&lt;p&gt;Eigenvector centrality is actually what Google originally used in its &lt;a href=&#34;https://en.wikipedia.org/wiki/PageRank&#34;&gt;PageRank algorithm&lt;/a&gt; to rank the relative importance (centrality) of web pages. Each page is like a subway station, and hyperlinks on the page are like the subway lines connecting them. Eigenvector centrality is relatively easy to calculate, either directly (it’s related to the eigenspectrum of the graph’s adjacency matrix, thanks to spooky &lt;a href=&#34;https://en.wikipedia.org/wiki/Spectral_graph_theory&#34;&gt;spectral graph theory&lt;/a&gt; magic) or using a technique called &lt;a href=&#34;https://en.wikipedia.org/wiki/Power_iteration&#34;&gt;&lt;em&gt;power iteration&lt;/em&gt;&lt;/a&gt; (which relies on a convergence that happens when you multiply the adjacency matrix by a vector a bunch of times). Either way, you can calculate it with a single function call in &lt;a href=&#34;https://networkx.org/&#34;&gt;NetworkX&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;What do you think will be the most probable stop on your infinite subway tour? Or, another way to ask the same question: Which stop will you visit most often on your tour? Unsurprisingly, it will be Times Square, with a probability of a little over 30%. The next most probable station is 42nd St. Port Authority Bus Terminal, coming in at about 8%. Then 50th St., 59th St. Columbus Circle, Grand Central 42nd St., and 34th St. Penn Station are all between 4% and 5%.&lt;/p&gt;&lt;p&gt;So, what have we learned? First of all, don’t attend Empire Hacking without the expectation of being intellectually stimulated. Secondly, don’t immediately discount a problem just because it is NP-hard or computationally intractable to solve; you might be able to approximate a solution of sufficient optimality. Thirdly, &lt;a href=&#34;https://www.latimes.com/archives/la-xpm-1991-12-08-bk-306-story.html&#34;&gt;Times Square may not be the “center of the universe,”&lt;/a&gt; but it is &lt;em&gt;definitely&lt;/em&gt; the center of the New York subway system. Finally, remember to like, comment, and subscribe!&lt;/p&gt;&lt;details&gt;&lt;summary&gt;Click to see the complete tour route!&lt;/summary&gt;1 (0.0hrs): Far Rockaway-Mott Av&lt;br /&gt;2 (0.0hrs): Beach 25 St&lt;br /&gt;3 (0.1hrs): Beach 36 St&lt;br /&gt;4 (0.1hrs): Beach 44 St&lt;br /&gt;5 (0.1hrs): Beach 60 St&lt;br /&gt;6 (0.1hrs): Beach 67 St&lt;br /&gt;7 (0.2hrs): Broad Channel&lt;br /&gt;8 (0.3hrs): Beach 90 St&lt;br /&gt;9 (0.3hrs): Beach 98 St&lt;br /&gt;10 (0.3hrs): Beach 105 St&lt;br /&gt;11 (0.4hrs): Rockaway Park-Beach 116 St&lt;br /&gt;12 (0.4hrs): Beach 105 St (visit 2)&lt;br /&gt;13 (0.4hrs): Beach 98 St (visit 2)&lt;br /&gt;14 (0.4hrs): Beach 90 St (visit 2)&lt;br /&gt;15 (0.5hrs): Broad Channel (visit 2)&lt;br /&gt;16 (0.6hrs): Howard Beach-JFK Airport&lt;br /&gt;17 (0.7hrs): Aqueduct-N Conduit Av&lt;br /&gt;18 (0.7hrs): Aqueduct Racetrack&lt;br /&gt;19 (0.7hrs): Rockaway Blvd&lt;br /&gt;20 (0.8hrs): 104 St&lt;br /&gt;21 (0.8hrs): 111 St&lt;br /&gt;22 (0.9hrs): Ozone Park-Lefferts Blvd&lt;br /&gt;23 (0.9hrs): 111 St (visit 2)&lt;br /&gt;24 (0.9hrs): 104 St (visit 2)&lt;br /&gt;25 (0.9hrs): Rockaway Blvd (visit 2)&lt;br /&gt;26 (0.9hrs): 88 St&lt;br /&gt;27 (1.0hrs): 80 St&lt;br /&gt;28 (1.0hrs): Grant Av&lt;br /&gt;29 (1.0hrs): Euclid Av&lt;br /&gt;30 (1.0hrs): Shepherd Av&lt;br /&gt;31 (1.1hrs): Van Siclen Av&lt;br /&gt;32 (1.1hrs): Liberty Av&lt;br /&gt;33 (1.1hrs): Broadway Junction&lt;br /&gt;transfer lines&lt;br /&gt;34 (1.2hrs): Broadway Junction&lt;br /&gt;35 (1.2hrs): Alabama Av&lt;br /&gt;36 (1.3hrs): Van Siclen Av&lt;br /&gt;37 (1.3hrs): Cleveland St&lt;br /&gt;38 (1.3hrs): Norwood Av&lt;br /&gt;39 (1.3hrs): Crescent St&lt;br /&gt;40 (1.4hrs): Cypress Hills&lt;br /&gt;41 (1.4hrs): 75 St-Elderts Ln&lt;br /&gt;42 (1.4hrs): 85 St-Forest Pkwy&lt;br /&gt;43 (1.4hrs): Woodhaven Blvd&lt;br /&gt;44 (1.5hrs): 104 St&lt;br /&gt;45 (1.5hrs): 111 St&lt;br /&gt;46 (1.5hrs): 121 St&lt;br /&gt;47 (1.6hrs): Sutphin Blvd-Archer Av-JFK Airport&lt;br /&gt;48 (1.7hrs): Jamaica Center-Parsons/Archer&lt;br /&gt;49 (1.7hrs): Sutphin Blvd-Archer Av-JFK Airport (visit 2)&lt;br /&gt;50 (1.7hrs): Jamaica-Van Wyck&lt;br /&gt;51 (1.7hrs): Briarwood&lt;br /&gt;52 (1.8hrs): Sutphin Blvd&lt;br /&gt;53 (1.8hrs): Parsons Blvd&lt;br /&gt;54 (1.9hrs): 169 St&lt;br /&gt;55 (2.0hrs): Jamaica-179 St&lt;br /&gt;56 (2.0hrs): 169 St (visit 2)&lt;br /&gt;57 (2.0hrs): Parsons Blvd (visit 2)&lt;br /&gt;58 (2.1hrs): Sutphin Blvd (visit 2)&lt;br /&gt;59 (2.1hrs): Briarwood (visit 2)&lt;br /&gt;60 (2.1hrs): Kew Gardens-Union Tpke&lt;br /&gt;61 (2.2hrs): 75 Av&lt;br /&gt;62 (2.2hrs): Forest Hills-71 Av&lt;br /&gt;63 (2.2hrs): 67 Av&lt;br /&gt;64 (2.2hrs): 63 Dr-Rego Park&lt;br /&gt;65 (2.3hrs): Woodhaven Blvd&lt;br /&gt;66 (2.3hrs): Grand Av-Newtown&lt;br /&gt;67 (2.3hrs): Elmhurst Av&lt;br /&gt;68 (2.4hrs): Jackson Hts-Roosevelt Av&lt;br /&gt;69 (2.4hrs): 65 St&lt;br /&gt;70 (2.4hrs): Northern Blvd&lt;br /&gt;71 (2.4hrs): 46 St&lt;br /&gt;72 (2.5hrs): Steinway St&lt;br /&gt;73 (2.5hrs): 36 St&lt;br /&gt;74 (2.5hrs): Queens Plaza&lt;br /&gt;75 (2.6hrs): Court Sq-23 St&lt;br /&gt;76 (2.6hrs): Lexington Av/53 St&lt;br /&gt;77 (2.6hrs): 5 Av/53 St&lt;br /&gt;78 (2.7hrs): 7 Av&lt;br /&gt;79 (2.7hrs): 50 St&lt;br /&gt;80 (2.7hrs): 42 St-Port Authority Bus Terminal&lt;br /&gt;81 (2.8hrs): 34 St-Penn Station&lt;br /&gt;82 (2.8hrs): 23 St&lt;br /&gt;83 (2.8hrs): 14 St&lt;br /&gt;84 (2.9hrs): W 4 St-Wash Sq&lt;br /&gt;85 (2.9hrs): Spring St&lt;br /&gt;86 (2.9hrs): Canal St&lt;br /&gt;87 (2.9hrs): World Trade Center&lt;br /&gt;88 (3.0hrs): Canal St (visit 2)&lt;br /&gt;89 (3.0hrs): Chambers St&lt;br /&gt;90 (3.0hrs): Fulton St&lt;br /&gt;transfer lines&lt;br /&gt;91 (3.1hrs): Fulton St&lt;br /&gt;92 (3.1hrs): Wall St&lt;br /&gt;93 (3.1hrs): Bowling Green&lt;br /&gt;94 (3.2hrs): Wall St (visit 2)&lt;br /&gt;95 (3.2hrs): Fulton St (visit 2)&lt;br /&gt;96 (3.2hrs): Brooklyn Bridge-City Hall&lt;br /&gt;97 (3.2hrs): Canal St&lt;br /&gt;98 (3.3hrs): Brooklyn Bridge-City Hall (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;99 (3.3hrs): Chambers St&lt;br /&gt;100 (3.4hrs): Fulton St&lt;br /&gt;101 (3.4hrs): Broad St&lt;br /&gt;102 (3.4hrs): Fulton St (visit 2)&lt;br /&gt;103 (3.4hrs): Chambers St (visit 2)&lt;br /&gt;104 (3.5hrs): Canal St&lt;br /&gt;105 (3.5hrs): Bowery&lt;br /&gt;106 (3.5hrs): Delancey St-Essex St&lt;br /&gt;107 (3.6hrs): Bowery (visit 2)&lt;br /&gt;108 (3.6hrs): Canal St (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;109 (3.6hrs): Canal St (visit 2)&lt;br /&gt;110 (3.7hrs): Spring St&lt;br /&gt;111 (3.7hrs): Bleecker St&lt;br /&gt;112 (3.7hrs): Astor Pl&lt;br /&gt;113 (3.7hrs): 14 St-Union Sq&lt;br /&gt;114 (3.8hrs): 23 St&lt;br /&gt;115 (3.8hrs): 28 St&lt;br /&gt;116 (3.8hrs): 33 St&lt;br /&gt;117 (3.8hrs): Grand Central-42 St&lt;br /&gt;118 (3.9hrs): 51 St&lt;br /&gt;119 (3.9hrs): 59 St&lt;br /&gt;120 (3.9hrs): 68 St-Hunter College&lt;br /&gt;121 (3.9hrs): 77 St&lt;br /&gt;122 (4.0hrs): 86 St&lt;br /&gt;123 (4.0hrs): 96 St&lt;br /&gt;124 (4.0hrs): 103 St&lt;br /&gt;125 (4.0hrs): 110 St&lt;br /&gt;126 (4.1hrs): 116 St&lt;br /&gt;127 (4.1hrs): 125 St&lt;br /&gt;128 (4.1hrs): 3 Av-138 St&lt;br /&gt;129 (4.3hrs): Hunts Point Av&lt;br /&gt;130 (4.4hrs): Parkchester&lt;br /&gt;131 (4.4hrs): Castle Hill Av&lt;br /&gt;132 (4.4hrs): Zerega Av&lt;br /&gt;133 (4.4hrs): Westchester Sq-E Tremont Av&lt;br /&gt;134 (4.5hrs): Middletown Rd&lt;br /&gt;135 (4.5hrs): Buhre Av&lt;br /&gt;136 (4.5hrs): Pelham Bay Park&lt;br /&gt;137 (4.6hrs): Buhre Av (visit 2)&lt;br /&gt;138 (4.6hrs): Middletown Rd (visit 2)&lt;br /&gt;139 (4.6hrs): Westchester Sq-E Tremont Av (visit 2)&lt;br /&gt;140 (4.6hrs): Zerega Av (visit 2)&lt;br /&gt;141 (4.7hrs): Castle Hill Av (visit 2)&lt;br /&gt;142 (4.7hrs): Parkchester (visit 2)&lt;br /&gt;143 (4.7hrs): St Lawrence Av&lt;br /&gt;144 (4.7hrs): Morrison Av-Soundview&lt;br /&gt;145 (4.8hrs): Elder Av&lt;br /&gt;146 (4.8hrs): Whitlock Av&lt;br /&gt;147 (4.8hrs): Hunts Point Av (visit 2)&lt;br /&gt;148 (4.8hrs): Longwood Av&lt;br /&gt;149 (4.9hrs): E 149 St&lt;br /&gt;150 (4.9hrs): E 143 St-St Mary&amp;rsquo;s St&lt;br /&gt;151 (4.9hrs): Cypress Av&lt;br /&gt;152 (4.9hrs): Brook Av&lt;br /&gt;153 (5.0hrs): 3 Av-138 St (visit 2)&lt;br /&gt;154 (5.0hrs): 125 St (visit 2)&lt;br /&gt;155 (5.1hrs): 138 St-Grand Concourse&lt;br /&gt;156 (5.1hrs): 149 St-Grand Concourse&lt;br /&gt;transfer lines&lt;br /&gt;157 (5.2hrs): 149 St-Grand Concourse&lt;br /&gt;158 (5.2hrs): 3 Av-149 St&lt;br /&gt;159 (5.4hrs): E 180 St&lt;br /&gt;160 (5.4hrs): Morris Park&lt;br /&gt;161 (5.5hrs): Pelham Pkwy&lt;br /&gt;162 (5.5hrs): Gun Hill Rd&lt;br /&gt;163 (5.5hrs): Baychester Av&lt;br /&gt;164 (5.6hrs): Eastchester-Dyre Av&lt;br /&gt;165 (5.6hrs): Baychester Av (visit 2)&lt;br /&gt;166 (5.7hrs): Gun Hill Rd (visit 2)&lt;br /&gt;167 (5.7hrs): Pelham Pkwy (visit 2)&lt;br /&gt;168 (5.7hrs): Morris Park (visit 2)&lt;br /&gt;169 (5.8hrs): E 180 St (visit 2)&lt;br /&gt;170 (5.8hrs): Bronx Park East&lt;br /&gt;171 (5.9hrs): Pelham Pkwy&lt;br /&gt;172 (5.9hrs): Allerton Av&lt;br /&gt;173 (5.9hrs): Burke Av&lt;br /&gt;174 (5.9hrs): Gun Hill Rd&lt;br /&gt;175 (6.0hrs): 219 St&lt;br /&gt;176 (6.0hrs): 225 St&lt;br /&gt;177 (6.0hrs): 233 St&lt;br /&gt;178 (6.0hrs): Nereid Av&lt;br /&gt;179 (6.1hrs): Wakefield-241 St&lt;br /&gt;180 (6.1hrs): Nereid Av (visit 2)&lt;br /&gt;181 (6.2hrs): 233 St (visit 2)&lt;br /&gt;182 (6.2hrs): 225 St (visit 2)&lt;br /&gt;183 (6.2hrs): 219 St (visit 2)&lt;br /&gt;184 (6.2hrs): Gun Hill Rd (visit 2)&lt;br /&gt;185 (6.4hrs): E 180 St (visit 3)&lt;br /&gt;186 (6.4hrs): West Farms Sq-E Tremont Av&lt;br /&gt;187 (6.4hrs): 174 St&lt;br /&gt;188 (6.5hrs): Freeman St&lt;br /&gt;189 (6.5hrs): Simpson St&lt;br /&gt;190 (6.5hrs): Intervale Av&lt;br /&gt;191 (6.5hrs): Prospect Av&lt;br /&gt;192 (6.6hrs): Jackson Av&lt;br /&gt;193 (6.6hrs): 3 Av-149 St (visit 2)&lt;br /&gt;194 (6.6hrs): 149 St-Grand Concourse (visit 2)&lt;br /&gt;195 (6.7hrs): 135 St&lt;br /&gt;196 (6.7hrs): 145 St&lt;br /&gt;197 (6.8hrs): Harlem-148 St&lt;br /&gt;198 (6.8hrs): 145 St (visit 2)&lt;br /&gt;199 (6.8hrs): 135 St (visit 2)&lt;br /&gt;200 (6.9hrs): 125 St&lt;br /&gt;201 (6.9hrs): 116 St&lt;br /&gt;202 (6.9hrs): Central Park North (110 St)&lt;br /&gt;203 (7.0hrs): 96 St&lt;br /&gt;204 (7.0hrs): 72 St&lt;br /&gt;205 (7.1hrs): 66 St-Lincoln Center&lt;br /&gt;206 (7.1hrs): 59 St-Columbus Circle&lt;br /&gt;transfer lines&lt;br /&gt;207 (7.1hrs): 59 St-Columbus Circle&lt;br /&gt;208 (7.2hrs): 7 Av (visit 2)&lt;br /&gt;209 (7.2hrs): 47-50 Sts-Rockefeller Ctr&lt;br /&gt;210 (7.2hrs): 57 St&lt;br /&gt;211 (7.2hrs): 47-50 Sts-Rockefeller Ctr (visit 2)&lt;br /&gt;212 (7.3hrs): 42 St-Bryant Pk&lt;br /&gt;213 (7.3hrs): 34 St-Herald Sq&lt;br /&gt;214 (7.3hrs): 23 St&lt;br /&gt;215 (7.3hrs): 14 St&lt;br /&gt;216 (7.4hrs): W 4 St-Wash Sq&lt;br /&gt;217 (7.4hrs): Broadway-Lafayette St&lt;br /&gt;218 (7.4hrs): Grand St&lt;br /&gt;219 (7.5hrs): Broadway-Lafayette St (visit 2)&lt;br /&gt;220 (7.5hrs): 2 Av&lt;br /&gt;221 (7.5hrs): Delancey St-Essex St&lt;br /&gt;222 (7.6hrs): East Broadway&lt;br /&gt;223 (7.6hrs): York St&lt;br /&gt;224 (7.6hrs): Jay St-MetroTech&lt;br /&gt;transfer lines&lt;br /&gt;225 (7.7hrs): Jay St-MetroTech&lt;br /&gt;226 (7.7hrs): DeKalb Av&lt;br /&gt;227 (7.7hrs): Atlantic Av-Barclays Ctr&lt;br /&gt;228 (7.8hrs): 7 Av&lt;br /&gt;229 (7.8hrs): Prospect Park&lt;br /&gt;230 (7.9hrs): Parkside Av&lt;br /&gt;231 (7.9hrs): Church Av&lt;br /&gt;232 (7.9hrs): Beverley Rd&lt;br /&gt;233 (7.9hrs): Cortelyou Rd&lt;br /&gt;234 (8.0hrs): Newkirk Plaza&lt;br /&gt;235 (8.0hrs): Avenue H&lt;br /&gt;236 (8.0hrs): Avenue J&lt;br /&gt;237 (8.0hrs): Avenue M&lt;br /&gt;238 (8.1hrs): Kings Hwy&lt;br /&gt;239 (8.1hrs): Avenue U&lt;br /&gt;240 (8.1hrs): Neck Rd&lt;br /&gt;241 (8.2hrs): Sheepshead Bay&lt;br /&gt;242 (8.2hrs): Brighton Beach&lt;br /&gt;243 (8.2hrs): Ocean Pkwy&lt;br /&gt;244 (8.3hrs): W 8 St-NY Aquarium&lt;br /&gt;245 (8.3hrs): Coney Island-Stillwell Av&lt;br /&gt;246 (8.3hrs): W 8 St-NY Aquarium (visit 2)&lt;br /&gt;247 (8.4hrs): Neptune Av&lt;br /&gt;248 (8.4hrs): Avenue X&lt;br /&gt;249 (8.4hrs): Avenue U&lt;br /&gt;250 (8.4hrs): Kings Hwy&lt;br /&gt;251 (8.5hrs): Avenue P&lt;br /&gt;252 (8.5hrs): Avenue N&lt;br /&gt;253 (8.5hrs): Bay Pkwy&lt;br /&gt;254 (8.5hrs): Avenue I&lt;br /&gt;255 (8.6hrs): 18 Av&lt;br /&gt;256 (8.6hrs): Ditmas Av&lt;br /&gt;257 (8.6hrs): Church Av&lt;br /&gt;258 (8.6hrs): Fort Hamilton Pkwy&lt;br /&gt;259 (8.7hrs): 15 St-Prospect Park&lt;br /&gt;260 (8.7hrs): 7 Av&lt;br /&gt;261 (8.7hrs): 4 Av-9 St&lt;br /&gt;262 (8.8hrs): Smith-9 Sts&lt;br /&gt;263 (8.8hrs): Carroll St&lt;br /&gt;264 (8.8hrs): Bergen St&lt;br /&gt;265 (8.9hrs): Hoyt-Schermerhorn Sts&lt;br /&gt;266 (8.9hrs): Lafayette Av&lt;br /&gt;267 (8.9hrs): Clinton-Washington Avs&lt;br /&gt;268 (8.9hrs): Franklin Av&lt;br /&gt;transfer lines&lt;br /&gt;269 (9.0hrs): Franklin Av&lt;br /&gt;transfer lines&lt;br /&gt;270 (9.0hrs): Franklin Av (visit 2)&lt;br /&gt;271 (9.1hrs): Nostrand Av&lt;br /&gt;272 (9.1hrs): Kingston-Throop Avs&lt;br /&gt;273 (9.1hrs): Utica Av&lt;br /&gt;274 (9.2hrs): Ralph Av&lt;br /&gt;275 (9.2hrs): Rockaway Av&lt;br /&gt;276 (9.2hrs): Broadway Junction (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;277 (9.3hrs): Broadway Junction&lt;br /&gt;278 (9.3hrs): Atlantic Av&lt;br /&gt;279 (9.3hrs): Sutter Av&lt;br /&gt;280 (9.3hrs): Livonia Av&lt;br /&gt;281 (9.4hrs): New Lots Av&lt;br /&gt;282 (9.4hrs): East 105 St&lt;br /&gt;283 (9.4hrs): Canarsie-Rockaway Pkwy&lt;br /&gt;284 (9.4hrs): East 105 St (visit 2)&lt;br /&gt;285 (9.5hrs): New Lots Av (visit 2)&lt;br /&gt;286 (9.5hrs): Livonia Av (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;287 (9.6hrs): Junius St&lt;br /&gt;288 (9.6hrs): Pennsylvania Av&lt;br /&gt;289 (9.6hrs): Van Siclen Av&lt;br /&gt;290 (9.7hrs): New Lots Av&lt;br /&gt;291 (9.7hrs): Van Siclen Av (visit 2)&lt;br /&gt;292 (9.7hrs): Pennsylvania Av (visit 2)&lt;br /&gt;293 (9.7hrs): Junius St (visit 2)&lt;br /&gt;294 (9.7hrs): Rockaway Av&lt;br /&gt;295 (9.8hrs): Saratoga Av&lt;br /&gt;296 (9.8hrs): Sutter Av-Rutland Rd&lt;br /&gt;297 (9.8hrs): Crown Hts-Utica Av&lt;br /&gt;298 (9.9hrs): Kingston Av&lt;br /&gt;299 (9.9hrs): Nostrand Av&lt;br /&gt;300 (9.9hrs): Franklin Av-Medgar Evers College&lt;br /&gt;301 (10.0hrs): President St-Medgar Evers College&lt;br /&gt;302 (10.0hrs): Sterling St&lt;br /&gt;303 (10.0hrs): Winthrop St&lt;br /&gt;304 (10.1hrs): Church Av&lt;br /&gt;305 (10.1hrs): Beverly Rd&lt;br /&gt;306 (10.2hrs): Newkirk Av-Little Haiti&lt;br /&gt;307 (10.2hrs): Flatbush Av-Brooklyn College&lt;br /&gt;308 (10.2hrs): Newkirk Av-Little Haiti (visit 2)&lt;br /&gt;309 (10.2hrs): Beverly Rd (visit 2)&lt;br /&gt;310 (10.3hrs): Church Av (visit 2)&lt;br /&gt;311 (10.3hrs): Winthrop St (visit 2)&lt;br /&gt;312 (10.3hrs): Sterling St (visit 2)&lt;br /&gt;313 (10.3hrs): President St-Medgar Evers College (visit 2)&lt;br /&gt;314 (10.4hrs): Franklin Av-Medgar Evers College (visit 2)&lt;br /&gt;315 (10.4hrs): Eastern Pkwy-Brooklyn Museum&lt;br /&gt;316 (10.5hrs): Grand Army Plaza&lt;br /&gt;317 (10.5hrs): Bergen St&lt;br /&gt;318 (10.5hrs): Atlantic Av-Barclays Ctr&lt;br /&gt;transfer lines&lt;br /&gt;319 (10.6hrs): Atlantic Av-Barclays Ctr&lt;br /&gt;320 (10.7hrs): 36 St&lt;br /&gt;321 (10.7hrs): 9 Av&lt;br /&gt;322 (10.8hrs): Fort Hamilton Pkwy&lt;br /&gt;323 (10.8hrs): 50 St&lt;br /&gt;324 (10.8hrs): 55 St&lt;br /&gt;325 (10.8hrs): 62 St&lt;br /&gt;transfer lines&lt;br /&gt;326 (10.9hrs): New Utrecht Av&lt;br /&gt;327 (10.9hrs): 18 Av&lt;br /&gt;328 (10.9hrs): 20 Av&lt;br /&gt;329 (11.0hrs): Bay Pkwy&lt;br /&gt;330 (11.0hrs): Kings Hwy&lt;br /&gt;331 (11.0hrs): Avenue U&lt;br /&gt;332 (11.0hrs): 86 St&lt;br /&gt;333 (11.1hrs): Coney Island-Stillwell Av (visit 2)&lt;br /&gt;334 (11.2hrs): Bay 50 St&lt;br /&gt;335 (11.3hrs): 25 Av&lt;br /&gt;336 (11.3hrs): Bay Pkwy&lt;br /&gt;337 (11.3hrs): 20 Av&lt;br /&gt;338 (11.3hrs): 18 Av&lt;br /&gt;339 (11.3hrs): 79 St&lt;br /&gt;340 (11.4hrs): 71 St&lt;br /&gt;341 (11.4hrs): 62 St (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;342 (11.5hrs): New Utrecht Av (visit 2)&lt;br /&gt;343 (11.5hrs): Fort Hamilton Pkwy&lt;br /&gt;344 (11.5hrs): 8 Av&lt;br /&gt;345 (11.6hrs): 59 St&lt;br /&gt;346 (11.6hrs): Bay Ridge Av&lt;br /&gt;347 (11.6hrs): 77 St&lt;br /&gt;348 (11.7hrs): 86 St&lt;br /&gt;349 (11.7hrs): Bay Ridge-95 St&lt;br /&gt;350 (11.7hrs): 86 St (visit 2)&lt;br /&gt;351 (11.8hrs): 77 St (visit 2)&lt;br /&gt;352 (11.8hrs): Bay Ridge Av (visit 2)&lt;br /&gt;353 (11.8hrs): 59 St (visit 2)&lt;br /&gt;354 (11.9hrs): 53 St&lt;br /&gt;355 (11.9hrs): 45 St&lt;br /&gt;356 (11.9hrs): 36 St (visit 2)&lt;br /&gt;357 (12.0hrs): 25 St&lt;br /&gt;358 (12.0hrs): Prospect Av&lt;br /&gt;359 (12.0hrs): 4 Av-9 St&lt;br /&gt;360 (12.0hrs): Union St&lt;br /&gt;361 (12.1hrs): Atlantic Av-Barclays Ctr (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;362 (12.1hrs): Atlantic Av-Barclays Ctr (visit 2)&lt;br /&gt;363 (12.2hrs): Nevins St&lt;br /&gt;364 (12.2hrs): Borough Hall&lt;br /&gt;365 (12.2hrs): Nevins St (visit 2)&lt;br /&gt;366 (12.2hrs): Hoyt St&lt;br /&gt;367 (12.3hrs): Borough Hall&lt;br /&gt;transfer lines&lt;br /&gt;368 (12.3hrs): Court St&lt;br /&gt;369 (12.4hrs): Jay St-MetroTech (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;370 (12.4hrs): Jay St-MetroTech (visit 2)&lt;br /&gt;371 (12.4hrs): High St&lt;br /&gt;372 (12.4hrs): Jay St-MetroTech (visit 3)&lt;br /&gt;373 (12.5hrs): Hoyt-Schermerhorn Sts (visit 2)&lt;br /&gt;374 (12.5hrs): Fulton St&lt;br /&gt;375 (12.5hrs): Clinton-Washington Avs&lt;br /&gt;376 (12.6hrs): Classon Av&lt;br /&gt;377 (12.6hrs): Bedford-Nostrand Avs&lt;br /&gt;378 (12.6hrs): Myrtle-Willoughby Avs&lt;br /&gt;379 (12.6hrs): Flushing Av&lt;br /&gt;380 (12.7hrs): Broadway&lt;br /&gt;381 (12.7hrs): Metropolitan Av&lt;br /&gt;382 (12.7hrs): Nassau Av&lt;br /&gt;383 (12.8hrs): Greenpoint Av&lt;br /&gt;384 (12.8hrs): 21 St&lt;br /&gt;385 (12.8hrs): Court Sq&lt;br /&gt;transfer lines&lt;br /&gt;386 (12.9hrs): Court Sq&lt;br /&gt;387 (12.9hrs): Hunters Point Av&lt;br /&gt;388 (12.9hrs): Vernon Blvd-Jackson Av&lt;br /&gt;389 (12.9hrs): Hunters Point Av (visit 2)&lt;br /&gt;390 (13.0hrs): Court Sq (visit 2)&lt;br /&gt;391 (13.0hrs): Queensboro Plaza&lt;br /&gt;transfer lines&lt;br /&gt;392 (13.0hrs): Queensboro Plaza&lt;br /&gt;393 (13.0hrs): 39 Av-Dutch Kills&lt;br /&gt;394 (13.1hrs): 36 Av&lt;br /&gt;395 (13.1hrs): Broadway&lt;br /&gt;396 (13.1hrs): 30 Av&lt;br /&gt;397 (13.1hrs): Astoria Blvd&lt;br /&gt;398 (13.2hrs): Astoria-Ditmars Blvd&lt;br /&gt;399 (13.2hrs): Astoria Blvd (visit 2)&lt;br /&gt;400 (13.2hrs): 30 Av (visit 2)&lt;br /&gt;401 (13.2hrs): Broadway (visit 2)&lt;br /&gt;402 (13.3hrs): 36 Av (visit 2)&lt;br /&gt;403 (13.3hrs): 39 Av-Dutch Kills (visit 2)&lt;br /&gt;404 (13.3hrs): Queensboro Plaza (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;405 (13.3hrs): Queensboro Plaza (visit 2)&lt;br /&gt;406 (13.4hrs): 33 St-Rawson St&lt;br /&gt;407 (13.4hrs): 40 St-Lowery St&lt;br /&gt;408 (13.4hrs): 46 St-Bliss St&lt;br /&gt;409 (13.4hrs): 52 St&lt;br /&gt;410 (13.5hrs): 61 St-Woodside&lt;br /&gt;411 (13.5hrs): 69 St&lt;br /&gt;412 (13.5hrs): 74 St-Broadway&lt;br /&gt;413 (13.5hrs): 82 St-Jackson Hts&lt;br /&gt;414 (13.5hrs): 90 St-Elmhurst Av&lt;br /&gt;415 (13.6hrs): Junction Blvd&lt;br /&gt;416 (13.6hrs): 103 St-Corona Plaza&lt;br /&gt;417 (13.6hrs): 111 St&lt;br /&gt;418 (13.6hrs): Mets-Willets Point&lt;br /&gt;419 (13.7hrs): Flushing-Main St&lt;br /&gt;420 (13.8hrs): Mets-Willets Point (visit 2)&lt;br /&gt;421 (13.8hrs): Junction Blvd (visit 2)&lt;br /&gt;422 (13.9hrs): 74 St-Broadway (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;423 (13.9hrs): Jackson Hts-Roosevelt Av (visit 2)&lt;br /&gt;424 (14.0hrs): Queens Plaza (visit 2)&lt;br /&gt;425 (14.1hrs): Lexington Av/59 St&lt;br /&gt;426 (14.2hrs): 5 Av/59 St&lt;br /&gt;427 (14.2hrs): 57 St-7 Av&lt;br /&gt;428 (14.3hrs): Lexington Av/63 St&lt;br /&gt;429 (14.3hrs): 72 St&lt;br /&gt;430 (14.3hrs): 86 St&lt;br /&gt;431 (14.4hrs): 96 St&lt;br /&gt;432 (14.4hrs): 86 St (visit 2)&lt;br /&gt;433 (14.4hrs): 72 St (visit 2)&lt;br /&gt;434 (14.5hrs): Lexington Av/63 St (visit 2)&lt;br /&gt;435 (14.5hrs): Roosevelt Island&lt;br /&gt;436 (14.6hrs): 21 St-Queensbridge&lt;br /&gt;437 (14.6hrs): Roosevelt Island (visit 2)&lt;br /&gt;438 (14.6hrs): Lexington Av/63 St (visit 3)&lt;br /&gt;439 (14.7hrs): 57 St-7 Av (visit 2)&lt;br /&gt;440 (14.7hrs): 49 St&lt;br /&gt;441 (14.8hrs): Times Sq-42 St&lt;br /&gt;transfer lines&lt;br /&gt;442 (14.8hrs): Times Sq-42 St&lt;br /&gt;transfer lines&lt;br /&gt;443 (14.9hrs): Times Sq-42 St&lt;br /&gt;444 (14.9hrs): Grand Central-42 St&lt;br /&gt;transfer lines&lt;br /&gt;445 (15.0hrs): Grand Central-42 St&lt;br /&gt;446 (15.0hrs): 5 Av&lt;br /&gt;447 (15.0hrs): Times Sq-42 St&lt;br /&gt;448 (15.1hrs): 34 St-Hudson Yards&lt;br /&gt;449 (15.1hrs): Times Sq-42 St (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;450 (15.2hrs): Times Sq-42 St (visit 2)&lt;br /&gt;451 (15.2hrs): 34 St-Herald Sq&lt;br /&gt;452 (15.2hrs): 28 St&lt;br /&gt;453 (15.2hrs): 23 St&lt;br /&gt;454 (15.3hrs): 14 St-Union Sq&lt;br /&gt;455 (15.3hrs): 8 St-NYU&lt;br /&gt;456 (15.3hrs): Prince St&lt;br /&gt;457 (15.4hrs): Canal St&lt;br /&gt;transfer lines&lt;br /&gt;458 (15.4hrs): Canal St&lt;br /&gt;459 (15.4hrs): City Hall&lt;br /&gt;460 (15.5hrs): Cortlandt St&lt;br /&gt;461 (15.5hrs): Rector St&lt;br /&gt;462 (15.5hrs): Whitehall St-South Ferry&lt;br /&gt;transfer lines&lt;br /&gt;463 (15.6hrs): South Ferry Loop&lt;br /&gt;transfer lines&lt;br /&gt;464 (15.6hrs): Whitehall St-South Ferry (visit 2)&lt;br /&gt;465 (15.7hrs): Court St (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;466 (15.7hrs): Borough Hall (visit 2)&lt;br /&gt;467 (15.7hrs): Clark St&lt;br /&gt;468 (15.8hrs): Wall St&lt;br /&gt;469 (15.8hrs): Fulton St&lt;br /&gt;470 (15.9hrs): Park Place&lt;br /&gt;471 (15.9hrs): Chambers St&lt;br /&gt;472 (15.9hrs): WTC Cortlandt&lt;br /&gt;473 (15.9hrs): Rector St&lt;br /&gt;474 (16.0hrs): South Ferry&lt;br /&gt;475 (16.0hrs): Rector St (visit 2)&lt;br /&gt;476 (16.0hrs): WTC Cortlandt (visit 2)&lt;br /&gt;477 (16.0hrs): Chambers St (visit 2)&lt;br /&gt;478 (16.1hrs): Franklin St&lt;br /&gt;479 (16.1hrs): Canal St&lt;br /&gt;480 (16.1hrs): Houston St&lt;br /&gt;481 (16.1hrs): Christopher St-Sheridan Sq&lt;br /&gt;482 (16.2hrs): 14 St&lt;br /&gt;483 (16.2hrs): 18 St&lt;br /&gt;484 (16.2hrs): 23 St&lt;br /&gt;485 (16.2hrs): 28 St&lt;br /&gt;486 (16.2hrs): 34 St-Penn Station&lt;br /&gt;487 (16.3hrs): Times Sq-42 St (visit 2)&lt;br /&gt;488 (16.3hrs): 50 St&lt;br /&gt;489 (16.3hrs): 59 St-Columbus Circle (visit 2)&lt;br /&gt;490 (16.3hrs): 66 St-Lincoln Center (visit 2)&lt;br /&gt;491 (16.4hrs): 72 St (visit 2)&lt;br /&gt;492 (16.4hrs): 79 St&lt;br /&gt;493 (16.4hrs): 86 St&lt;br /&gt;494 (16.4hrs): 96 St (visit 2)&lt;br /&gt;495 (16.5hrs): 103 St&lt;br /&gt;496 (16.5hrs): Cathedral Pkwy (110 St)&lt;br /&gt;497 (16.5hrs): 116 St-Columbia University&lt;br /&gt;498 (16.5hrs): 125 St&lt;br /&gt;499 (16.6hrs): 137 St-City College&lt;br /&gt;500 (16.6hrs): 145 St&lt;br /&gt;501 (16.6hrs): 157 St&lt;br /&gt;502 (16.7hrs): 168 St-Washington Hts&lt;br /&gt;503 (16.7hrs): 181 St&lt;br /&gt;504 (16.7hrs): 191 St&lt;br /&gt;505 (16.7hrs): Dyckman St&lt;br /&gt;506 (16.8hrs): 207 St&lt;br /&gt;507 (16.8hrs): 215 St&lt;br /&gt;508 (16.8hrs): Marble Hill-225 St&lt;br /&gt;509 (16.8hrs): 231 St&lt;br /&gt;510 (16.9hrs): 238 St&lt;br /&gt;511 (16.9hrs): Van Cortlandt Park-242 St&lt;br /&gt;512 (16.9hrs): 238 St (visit 2)&lt;br /&gt;513 (17.0hrs): 231 St (visit 2)&lt;br /&gt;514 (17.0hrs): Marble Hill-225 St (visit 2)&lt;br /&gt;515 (17.0hrs): 215 St (visit 2)&lt;br /&gt;516 (17.0hrs): 207 St (visit 2)&lt;br /&gt;517 (17.1hrs): Dyckman St (visit 2)&lt;br /&gt;518 (17.1hrs): 191 St (visit 2)&lt;br /&gt;519 (17.1hrs): 181 St (visit 2)&lt;br /&gt;520 (17.1hrs): 168 St-Washington Hts (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;521 (17.2hrs): 168 St&lt;br /&gt;522 (17.3hrs): 175 St&lt;br /&gt;523 (17.3hrs): 181 St&lt;br /&gt;524 (17.3hrs): 190 St&lt;br /&gt;525 (17.4hrs): Dyckman St&lt;br /&gt;526 (17.4hrs): Inwood-207 St&lt;br /&gt;527 (17.5hrs): Dyckman St (visit 2)&lt;br /&gt;528 (17.5hrs): 190 St (visit 2)&lt;br /&gt;529 (17.5hrs): 181 St (visit 2)&lt;br /&gt;530 (17.5hrs): 175 St (visit 2)&lt;br /&gt;531 (17.6hrs): 168 St (visit 2)&lt;br /&gt;532 (17.6hrs): 163 St-Amsterdam Av&lt;br /&gt;533 (17.6hrs): 155 St&lt;br /&gt;534 (17.6hrs): 145 St&lt;br /&gt;535 (17.7hrs): 135 St&lt;br /&gt;536 (17.7hrs): 145 St&lt;br /&gt;537 (17.8hrs): Tremont Av&lt;br /&gt;538 (17.9hrs): Fordham Rd&lt;br /&gt;539 (17.9hrs): Kingsbridge Rd&lt;br /&gt;540 (18.0hrs): Bedford Park Blvd&lt;br /&gt;541 (18.0hrs): Norwood-205 St&lt;br /&gt;542 (18.0hrs): Bedford Park Blvd (visit 2)&lt;br /&gt;543 (18.1hrs): Kingsbridge Rd (visit 2)&lt;br /&gt;544 (18.1hrs): Fordham Rd (visit 2)&lt;br /&gt;545 (18.2hrs): 182-183 Sts&lt;br /&gt;546 (18.2hrs): Tremont Av (visit 2)&lt;br /&gt;547 (18.2hrs): 174-175 Sts&lt;br /&gt;548 (18.2hrs): 170 St&lt;br /&gt;549 (18.3hrs): 167 St&lt;br /&gt;550 (18.3hrs): 161 St-Yankee Stadium&lt;br /&gt;transfer lines&lt;br /&gt;551 (18.4hrs): 161 St-Yankee Stadium&lt;br /&gt;552 (18.4hrs): 167 St&lt;br /&gt;553 (18.4hrs): 170 St&lt;br /&gt;554 (18.4hrs): Mt Eden Av&lt;br /&gt;555 (18.5hrs): 176 St&lt;br /&gt;556 (18.5hrs): Burnside Av&lt;br /&gt;557 (18.5hrs): 183 St&lt;br /&gt;558 (18.5hrs): Fordham Rd&lt;br /&gt;559 (18.6hrs): Kingsbridge Rd&lt;br /&gt;560 (18.6hrs): Bedford Park Blvd-Lehman College&lt;br /&gt;561 (18.6hrs): Mosholu Pkwy&lt;br /&gt;562 (18.7hrs): Woodlawn&lt;br /&gt;563 (18.7hrs): Mosholu Pkwy (visit 2)&lt;br /&gt;564 (18.7hrs): Bedford Park Blvd-Lehman College (visit 2)&lt;br /&gt;565 (18.8hrs): Kingsbridge Rd (visit 2)&lt;br /&gt;566 (18.8hrs): Fordham Rd (visit 2)&lt;br /&gt;567 (18.8hrs): 183 St (visit 2)&lt;br /&gt;568 (18.8hrs): Burnside Av (visit 2)&lt;br /&gt;569 (18.9hrs): 167 St (visit 2)&lt;br /&gt;570 (19.0hrs): 161 St-Yankee Stadium (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;571 (19.0hrs): 161 St-Yankee Stadium (visit 2)&lt;br /&gt;572 (19.0hrs): 155 St&lt;br /&gt;573 (19.1hrs): 145 St (visit 2)&lt;br /&gt;574 (19.1hrs): 125 St&lt;br /&gt;575 (19.1hrs): 116 St&lt;br /&gt;576 (19.2hrs): Cathedral Pkwy (110 St)&lt;br /&gt;577 (19.2hrs): 103 St&lt;br /&gt;578 (19.2hrs): 96 St&lt;br /&gt;579 (19.2hrs): 86 St&lt;br /&gt;580 (19.3hrs): 81 St-Museum of Natural History&lt;br /&gt;581 (19.3hrs): 72 St&lt;br /&gt;582 (19.3hrs): 59 St-Columbus Circle (visit 2)&lt;br /&gt;583 (19.3hrs): 42 St-Port Authority Bus Terminal (visit 2)&lt;br /&gt;584 (19.4hrs): 34 St-Penn Station (visit 2)&lt;br /&gt;585 (19.4hrs): 14 St (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;586 (19.4hrs): 8 Av&lt;br /&gt;587 (19.5hrs): 6 Av&lt;br /&gt;588 (19.5hrs): 14 St-Union Sq&lt;br /&gt;589 (19.5hrs): 3 Av&lt;br /&gt;590 (19.5hrs): 1 Av&lt;br /&gt;591 (19.6hrs): Bedford Av&lt;br /&gt;592 (19.6hrs): Lorimer St&lt;br /&gt;593 (19.6hrs): Graham Av&lt;br /&gt;594 (19.7hrs): Grand St&lt;br /&gt;595 (19.7hrs): Montrose Av&lt;br /&gt;596 (19.7hrs): Morgan Av&lt;br /&gt;597 (19.7hrs): Jefferson St&lt;br /&gt;598 (19.8hrs): DeKalb Av&lt;br /&gt;599 (19.8hrs): Myrtle-Wyckoff Avs&lt;br /&gt;600 (19.8hrs): Halsey St&lt;br /&gt;601 (19.9hrs): Wilson Av&lt;br /&gt;602 (19.9hrs): Bushwick Av-Aberdeen St&lt;br /&gt;603 (19.9hrs): Broadway Junction (visit 2)&lt;br /&gt;604 (19.9hrs): Bushwick Av-Aberdeen St (visit 2)&lt;br /&gt;605 (20.0hrs): Wilson Av (visit 2)&lt;br /&gt;606 (20.0hrs): Halsey St (visit 2)&lt;br /&gt;607 (20.0hrs): Myrtle-Wyckoff Avs (visit 2)&lt;br /&gt;transfer lines&lt;br /&gt;608 (20.1hrs): Myrtle-Wyckoff Avs&lt;br /&gt;609 (20.1hrs): Seneca Av&lt;br /&gt;610 (20.1hrs): Forest Av&lt;br /&gt;611 (20.2hrs): Fresh Pond Rd&lt;br /&gt;612 (20.2hrs): Middle Village-Metropolitan Av&lt;br /&gt;613 (20.2hrs): Fresh Pond Rd (visit 2)&lt;br /&gt;614 (20.3hrs): Forest Av (visit 2)&lt;br /&gt;615 (20.3hrs): Seneca Av (visit 2)&lt;br /&gt;616 (20.3hrs): Myrtle-Wyckoff Avs (visit 2)&lt;br /&gt;617 (20.3hrs): Knickerbocker Av&lt;br /&gt;618 (20.4hrs): Central Av&lt;br /&gt;619 (20.4hrs): Myrtle Av&lt;br /&gt;620 (20.5hrs): Marcy Av&lt;br /&gt;621 (20.5hrs): Hewes St&lt;br /&gt;622 (20.5hrs): Lorimer St&lt;br /&gt;623 (20.6hrs): Flushing Av&lt;br /&gt;624 (20.6hrs): Myrtle Av (visit 2)&lt;br /&gt;625 (20.6hrs): Kosciuszko St&lt;br /&gt;626 (20.6hrs): Gates Av&lt;br /&gt;627 (20.7hrs): Halsey St&lt;br /&gt;628 (20.7hrs): Chauncey St&lt;br /&gt;629 (20.7hrs): Broadway Junction (visit 2)&lt;br /&gt;&lt;/details&gt;
&lt;br /&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2025/08/25/speedrunning-the-new-york-subway/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Detecting code copying at scale with Vendetect</title>
    <id>https://www.sultanik.com/blog/vendetect</id>
    <updated>2025-07-21T07:00:00Z</updated>
    <published>2025-07-21T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/vendetect" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;Earlier this month, the maintainer of &lt;a href=&#34;https://cheatingdaddy.com/&#34;&gt;Cheating-Daddy&lt;/a&gt; &lt;a href=&#34;https://x.com/soham_btw/status/1940952786491027886&#34;&gt;discovered&lt;/a&gt; that a Y-Combinator-funded startup had copied their GPL-licensed codebase, stripped out the comments, and re-released it as “&lt;a href=&#34;https://pickle.com/glass&#34;&gt;Glass&lt;/a&gt;” under an incompatible license. This isn’t an isolated incident; we see code theft and improper vendoring constantly during security assessments. So we built a tool to catch it automatically.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://github.com/trailofbits/vendetect&#34;&gt;Vendetect&lt;/a&gt; is our new open-source tool for detecting copied and vendored code between repositories. It uses semantic fingerprinting to identify similar code even when variable names change or comments disappear. More importantly, unlike academic plagiarism detectors, it understands version control history, helping you trace vendored code back to its exact source commit.&lt;/p&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2025/07/21/detecting-code-copying-at-scale-with-vendetect/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Investigate your dependencies with Deptective</title>
    <id>https://www.sultanik.com/blog/deptective</id>
    <updated>2025-07-08T07:00:00Z</updated>
    <published>2025-07-08T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/deptective" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;Have you ever tried compiling a piece of open-source software, only to discover that you neglected to install one of its native dependencies? Or maybe a binary “fell off the back of a truck” and you want to try running it but have no idea what shared libraries it needs. Or maybe you need to use a poorly packaged piece of software whose maintainers neglected to list a native dependency.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://github.com/trailofbits/deptective&#34;&gt;Deptective&lt;/a&gt;, our new open-source tool, solves these problems. You can give it any program, script, or command, and it will find a set of packages sufficient to run the software successfully.&lt;/p&gt;&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2025/07/08/investigate-your-dependencies-with-deptective/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Preventing account takeover</title>
    <id>https://www.sultanik.com/blog/account_takeover</id>
    <updated>2025-02-05T07:00:00Z</updated>
    <published>2025-02-05T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/account_takeover" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
This blog post highlights key points from our new white paper &lt;a href=&#34;https://resources.trailofbits.com/hubfs/Resources/trailofbits-20250205-account-takeover-recommended-practices.pdf&#34; target=&#34;_blank&#34;&gt;&lt;i&gt;Preventing Account Takeovers on Centralized Cryptocurrency Exchanges&lt;/i&gt;&lt;/a&gt;, which documents ATO-related attack vectors and defenses tailored to CEXes.
&lt;/p&gt;
&lt;p&gt;
Imagine trying to log in to your centralized cryptocurrency exchange (CEX) account and your password and username just… don’t work. You try them again. Same problem. Your heart rate increases a little bit at this point, especially since you are using a password manager. Maybe a service outage is all that’s responsible (knock on wood), and your password will work again as soon as it’s fixed? But it is becoming increasingly likely that you’re the victim of an account takeover (ATO).
&lt;/p&gt;
&lt;p&gt;CEXes’ choices dictate how (or if) the people who use them can secure their funds. Since account security features vary between platforms and are not always documented, the user might not know what to expect nor how to configure their account best for their personal threat model. Design choices like not supporting &lt;a href=&#34;https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf&#34;&gt;phishing-resistant&lt;/a&gt; multifactor authentication (&lt;a href=&#34;https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4#:~:text=Implement%20multi%2Dfactor%20authentication%20for%20any%20individual%20accessing%20any%20information%20system&#34;&gt;MFA&lt;/a&gt;) methods like &lt;a href=&#34;https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html#:~:text=In%20fact%2C%20zero%20users%20that%20exclusively%20use%20security%20keys%20fell%20victim%20to%20targeted%20phishing%20during%20our%20investigation.&#34;&gt;U2F hardware security keys&lt;/a&gt;, or not tracking user events in order to push in-app “&lt;a href=&#34;https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html#:~:text=Here%E2%80%99s%20how%20it%20works%3A%20if%20we%20detect%20a%20suspicious%20sign%2Din%20attempt%20(say%2C%20from%20a%20new%20location%20or%20device)%2C%20we%E2%80%99ll%20ask%20for%20additional%20proof%20that%20it%E2%80%99s%20really%20you.%20This%20proof%20might%20be%20confirming%20you%20have%20access%20to%20a%20trusted%20phone%20or%20answering%20a%20question%20where%20only%20you%20know%20the%20correct%20response.&#34;&gt;was this you?&lt;/a&gt;” account lockdown prompts when anomalies happen invite the attacker in.&lt;/p&gt;
&lt;p&gt;Our white paper’s goal is to inform and enable CEXes to provide a &lt;a href=&#34;https://www.cisa.gov/sites/default/files/2023-10/SecureByDesign_1025_508c.pdf&#34;&gt;secure-by-design&lt;/a&gt; platform for their users. Executives can get a high-level overview of the vulnerabilities and entities involved in user account takeover. We recommend a set of overlapping security controls that they can bring to team leads and technical product managers to check for and prioritize if not yet implemented. Security engineers and software engineers can also use our work as a reference for the risks of not integrating, maintaining, and documenting appropriate ATO mitigations.&lt;/p&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2025/02/05/preventing-account-takeover-on-centralized-cryptocurrency-exchanges-in-2025/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">Cruising Through Paradoxes</title>
    <id>https://www.sultanik.com/blog/cruising</id>
    <updated>2024-08-01T19:55:00Z</updated>
    <published>2024-08-01T19:55:00Z</published>
    <link href="https://www.sultanik.com/blog/cruising" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
    I grew up on the fringes of suburbia, at the cusp of what most would consider rural Pennsylvania.
    In the Spring, we gagged from the stench of manure.
    In the Fall, Schools closed on the first day of hunting season.
    In the Winter, fresh, out-of-season fruits were missing from the grocer.
    All year round, procuring exotic ingredients like avocados entailed a forty-five-minute drive toward civilization.
    During the school year, I was the first to be picked up and last to be dropped off by the bus,
    enduring a ride that was well over an hour each way.
&lt;/p&gt;
&lt;p&gt;
    I also grew up in tandem with the burgeoning cruise line industry.
    My parents quickly adopted that mode of travel, and it eventually became our sole form of vacation.
    As a kid, it was great: I had the freedom to roam the decks on my own, there were innumerable activities,
    and an unlimited supply of delicious foods with exotic names like &amp;ldquo;Consommé Madrilene&amp;rdquo; and &amp;ldquo;Contrefilet of Prime
    Beef Périgueux&amp;rdquo;.
    My parents loved it because it kept their kids busy, was very affordable (relative to equivalent landed resorts),
    and had sufficient calories to satisfy their growing boy’s voracious appetite.
    This was also a transitional period when cruises were holding onto the vestiges and traditions of luxury ocean
    liners. All cruise lines had strict dress codes, requiring formal attire some evenings (people brought tuxedos!).
    The crew were largely Southern and Eastern European. As a kid who had never traveled outside North America, it felt
    like I was LARPing as James Bond.
&lt;/p&gt;
&lt;p&gt;
    When I moved out of my parents&amp;rsquo; house for college, I wanted a change of scenery.
    While I had the option to move to a &amp;ldquo;college town&amp;rdquo;, I instead chose to live in a large city.
    And I loved it.
    It was like living on a cruise, all year round: Activities galore, amazing food, and all within a short distance of
    each other.
    A friend could call me up and say, &amp;ldquo;Hey, we are hanging out at [X], would you like to join us?&amp;rdquo; And, regardless of
    where X was in the city, I could meet them there within fifteen minutes either by walking, biking, or taking public
    transport.
&lt;/p&gt;
&lt;p&gt;
    I didn&amp;rsquo;t &lt;em&gt;need&lt;/em&gt; cruises anymore.
&lt;/p&gt;
&lt;hr /&gt;
&lt;h3&gt;Preface&lt;/h3&gt;
&lt;p&gt;
    This year, for his birthday, my father only had one request: that he and his extended family take a cruise to
    celebrate. I just returned from that cruise, and it was a very different experience from the ones of my youth.
&lt;/p&gt;
&lt;p&gt;
    As an adult who had by this point lived the majority of his life in large cities,
    all I wanted to do was lay by a pool or, preferably, the beach all day and read a book.
    Those are both difficult things when you&amp;rsquo;re sharing a crowded pool space with over six thousand other people,
    and the ship doesn&amp;rsquo;t typically dock close to a good beach.
    Skating rink? Gimmicky specialty restaurants? Luxury shopping spree? Laser tag? Pub trivia? Theater productions?
    Comedy shows?
    I can do all of those things any day of the week a short distance from my house.
    When I vacation, I want to escape all that freneticism.
&lt;/p&gt;
&lt;p&gt;
    My wife, kids, and I were the only urbanites in our group, and my parents didn&amp;rsquo;t seem to comprehend why we
    had such little interest in all the activities. And then it dawned on me: &lt;b&gt;A cruise is just a simulated city.&lt;/b&gt;
    &lt;em&gt;Why would I want an artificial version of what I already have?&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
    So, lying down on a deck chair, instead of reading my book, I started writing.
    The idea of &lt;em&gt;simulated urbanism&lt;/em&gt; &lt;a href=&#34;https://www.youtube.com/watch?v=aGjc-gsh834&#34;&gt;isn&amp;rsquo;t new&lt;/a&gt;,
    but it&amp;rsquo;s typically discussed in terms of curated amusement parks like Disney and the emergence of suburban
    &amp;ldquo;lifestyle center&amp;rdquo; developments. Therefore, initially, my goal was to channel this insight into as obnoxious a
    treatise as possible, in order to trigger my suburbanite traveling companions. &lt;em&gt;Simulated&lt;/em&gt; urbanism? That
    reminded me of &lt;a href=&#34;https://en.wikipedia.org/wiki/Jean_Baudrillard&#34;&gt;Baudrillard&lt;/a&gt;!
    I would make it a completely over-the-top academic analysis of the topic.
&lt;/p&gt;
&lt;img src=&#34;/images/simulacrum.png&#34; alt=&#34;Simulacra and Simulation&#34; style=&#34;max-width: 80%; display: block; margin-top: 16px; margin-bottom: 12px; margin-left: auto; margin-right: auto; padding: 4px; background-color: #fff; border: 1px solid #ddd; border-radius: 4px;&#34;/&gt;
&lt;p&gt;
    The following was compiled from a series of texts I sent to our group
    chat throughout the cruise.
&lt;/p&gt;
&lt;hr style=&#34;height:0px;border: none;border-top: 3px solid black;&#34; /&gt;
&lt;h4&gt;Abstract&lt;/h4&gt;
&lt;p&gt;
    This article explores the paradox of vacation preferences among suburban Americans who gravitate toward densely populated environments such as cruises, European cities, and amusement parks, despite residing in sparsely populated areas. It examines how cruises and lifestyle centers, which mimic urban density while offering suburban convenience, satisfy the suburban desire for urban-like experiences. The article contrasts these preferences with those of urban Americans, who experience density daily and may seek different vacation experiences. By analyzing the dynamics of suburban and urban vacation choices, we highlight the complex interplay between suburban living and the pursuit of urban escapism.
&lt;/p&gt;
&lt;h2&gt;Simulated Urbanism&lt;/h2&gt;

&lt;h3&gt;Simulacra and Simulation&lt;/h3&gt;

The concept of &amp;ldquo;simulated urbanism,&amp;rdquo; as seen in cruise ships and lifestyle centers, can be analyzed through the lens
of Jean Baudrillard&amp;rsquo;s philosophy, particularly his ideas on simulation and hyperreality. Baudrillard argues that in
contemporary society, simulations—representations or imitations of reality—have become so pervasive that they blur the
distinction between what is real and what is artificially constructed. In the context of simulated urbanism, lifestyle
centers and cruise ships serve as hyperreal environments that imitate the vibrancy and density of urban life without the
complexities and inconveniences associated with real urban spaces. They provide an experience that is more accessible,
manageable, and, in some ways, more appealing than the genuine urban environments they emulate.

According to Baudrillard, these simulations can create a sense of hyperreality, where the imitation becomes more
influential or desirable than reality itself. Suburban Americans, who are accustomed to the sprawling, car-dependent
landscapes of suburbia, find in these simulated urban environments a curated and sanitized version of city life. This
artificial urbanism allows them to engage with the aesthetics and experiences of urban density—such as walkability,
diverse entertainment, and social interaction—without the perceived drawbacks of real urban living, like congestion,
pollution, and crime. Thus, simulated urbanism not only fulfills a desire for the excitement and dynamism of city life
but also constructs a hyperreal experience that is tailored to the preferences and comfort of suburban consumers,
aligning with Baudrillard’s notion of a society increasingly detached from the authenticity of the real world.

&lt;h3&gt;Metamodernism&lt;/h3&gt;

&lt;p&gt;
    Suburbanites’ predilections for cruising can be interpreted through the theoretical framework of metamodernism, which posits an oscillation between opposing cultural and experiential paradigms. The cruise experience encapsulates a synthesis of modernist aspirations for progress, order, and structured entertainment, alongside a postmodern sensibility characterized by irony and skepticism towards mass consumerism and the spectacle. This dialectical tension aligns with metamodernism’s core principle of navigating and reconciling contradictions. Within the confines of a cruise, suburbanites engage with the modernist ideal of escape and luxury, encountering a curated simulacrum that offers both adventure and novelty. Simultaneously, they remain cognizant of the inherent artifice and commodification intrinsic to the cruise experience, reflecting a postmodern consciousness of the limitations and constructed nature of such escapism.
&lt;/p&gt;
&lt;p&gt;
    Furthermore, the pragmatic idealism inherent in metamodernism is evident in the suburban pursuit of cruising, representing a quest for authenticity within a meticulously orchestrated environment. Suburbanites partake in cruising as a form of meaningful escapism that, although commodified, facilitates genuine opportunities for relaxation, social interaction, and cultural exploration. This dynamic reflects a metamodern synthesis of sincerity and irony, wherein participants seek genuine engagement and fulfillment while maintaining an awareness of the artificial and consumerist underpinnings of the cruise industry. The cruise, thus, serves as a microcosm of metamodern cultural hybridity, integrating diverse influences and experiences into a cohesive assemblage that enables suburbanites to navigate the complexities of contemporary existence with both optimism and reflexivity. This exemplifies the metamodern tension between the yearning for authentic connection and the recognition of its mediated nature, embodying a dialectical interplay that is central to metamodern thought.
&lt;/p&gt;

&lt;h3&gt;Dialectics&lt;/h3&gt;

&lt;p style=&#34;color:gray;&#34;&gt;
(To be read as if dictated by &lt;a href=&#34;https://en.wikipedia.org/wiki/Slavoj_%C5%BDi%C5%BEek&#34;&gt;Slavoj Žižek&lt;/a&gt;.)
&lt;/p&gt;

&lt;p&gt;
From a Hegelian perspective, urbanites&amp;rsquo; preferences for relaxing vacations can be understood through the lens of dialectical progression and the quest for synthesis between opposing elements in their lives. Hegel&amp;rsquo;s philosophy emphasizes the process of thesis, antithesis, and synthesis, &lt;span style=&#34;color:gray;&#34;&gt;[sniff]&lt;/span&gt; where the contradictions and tensions between different aspects of existence lead to the development of higher levels of understanding and being. A dance of contradictions and tensions.
&lt;/p&gt;

&lt;!--&lt;p&gt;Urbanites, who live in environments characterized by constant activity, complexity, and stimulation, may seek vacations as a form of antithesis to their daily experiences. These relaxing retreats provide a counterbalance, allowing them to reconcile the tension between the fast-paced nature of urban life and the human need for rest and tranquility.&lt;/p&gt;--&gt;

&lt;p&gt;
Urbanites are like rats in a maze of their &lt;em&gt;own&lt;/em&gt; making, living in this frenetic environment of constant stimulation and complexity. So, what do they do? They escape to a vacation that provides the antithesis of urban life, a necessary counterbalance that allows them to confront the contradictions of their daily existence.
&lt;/p&gt;

&lt;p&gt;
In this dialectical process, the vacation can be seen as a moment of synthesis, where urbanites integrate the contrasting aspects of their existence—work and leisure, complexity and simplicity, stimulation and relaxation. Through this synthesis, they achieve a more harmonious state of being, temporarily resolving the contradictions inherent in their lives. &lt;span style=&#34;color:gray;&#34;&gt;[nose pull]&lt;/span&gt; Hegel might argue that this pursuit of balance is part of a broader process of self-realization and development, as individuals continually seek to reconcile opposing forces within themselves and their environments. This dialectical movement reflects a deeper philosophical journey toward self-awareness and fulfillment, where each vacation experience contributes to a more nuanced understanding of personal and existential needs.
&lt;/p&gt;

&lt;p&gt;
Moreover, Hegel would likely emphasize that this process is not static but dynamic, as urbanites constantly redefine and re-evaluate their desires and experiences in pursuit of higher forms of understanding and contentment. &lt;span style=&#34;color:gray;&#34;&gt;[sniff]&lt;/span&gt; This ongoing dialectical interaction between urban life and vacation preferences underscores the complexity of human existence and the continuous evolution of individual consciousness within the broader historical and cultural context.
&lt;/p&gt;

&lt;h3&gt;What Would Marx Say?&lt;/h3&gt;

&lt;p style=&#34;color:gray;&#34;&gt;
(For extra fun, to be read as if dictated by Jordan Peterson.)
&lt;/p&gt;

&lt;p&gt;
When we examine the suburbanite&amp;rsquo;s preference for urban-like vacation experiences—such as cruising or visiting bustling cities—through the lens of Marxist theory, we uncover something quite profound about the alienation inherent in capitalist societies. Suburban life is often marked by routine and compartmentalization, a strong reliance on cars, and an emphasis on private space. This creates an environment of isolation and fragmentation, which Marx identified as symptomatic of capitalist production. The sprawling nature of suburbia physically separates individuals from their workplaces, social hubs, and cultural activities, generating a dichotomy between home life and community engagement. This alienation from collective social experiences mirrors the detachment workers feel from the products of their labor and from each other in a capitalist framework.
&lt;/p&gt;

&lt;p&gt;
Thus, when suburbanites seek out vacations in dense, walkable environments, they&amp;rsquo;re searching for a temporary reprieve from this isolation. These vacations allow them to engage with the social interactions and cultural experiences that are often missing from their everyday lives. In this way, vacations become a commodified form of leisure within capitalist society, packaged and sold as products designed to alleviate the stresses of alienation and labor. Suburbanites, who feel the pressures of maintaining a lifestyle dictated by capitalist norms—like homeownership and consumerism—turn to vacations as a form of respite from these demands. Cruises and urban vacations offer a concentrated form of entertainment and cultural engagement, providing an illusion of freedom and choice that contrasts with the regulated and constrained nature of suburban life. While these vacations temporarily satisfy the need for genuine human connection and cultural enrichment, Marxist theory would argue that they also reinforce the capitalist cycle, as individuals must return to their suburban routines to earn the means to participate in such leisure activities. Thus, vacations, though they offer a brief escape from alienation, ultimately underscore the pervasive influence of capitalism on leisure and personal fulfillment.
&lt;/p&gt;

&lt;h3&gt;Conclusions&lt;/h3&gt;

&lt;p&gt;
    As I reflect on the whirlwind of contradictions, philosophies, and cultural dynamics explored in this article, I must
admit that I find myself utterly exhausted. Much like the aftermath of a cruise, where the buffet line feels both
endless and insurmountable, I am too fatigued to draw any tidy conclusions. So, dear reader, as I lean back in my
metaphorical deck chair, I invite you to navigate these intellectual waters and draw your own conclusions. Like the
    towel animals on your cabin bed, reality might be folded and shaped in surprising ways, but the essence remains
    yours to unravel. Bon voyage in your own journey of trolling! Or is it trawling?
&lt;/p&gt;
</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">PoC‖GTFO Issue 0x22</title>
    <id>https://www.sultanik.com/pocorgtfo/#0x22</id>
    <updated>2024-02-03T00:00:00Z</updated>
    <published>2024-02-03T00:00:00Z</published>
    <link href="https://www.sultanik.com/pocorgtfo/#0x22" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">&lt;a href=&#34;/pocorgtfo/#0x22&#34;&gt;&lt;center style=&#34;padding-top:9px&#34;&gt;&lt;div style=&#34;width:80%;overflow:hidden;border:1px solid #021a40;background:white;&#34;&gt;&lt;img style=&#34;width:100%;padding: 0px;&#34;
               srcset=&#34;/pocorgtfo/pocorgtfo22_large.png  700w,
                       /pocorgtfo/pocorgtfo22_medium.png 500w,
                       /pocorgtfo/pocorgtfo22_small.png  350w&#34;
               sizes=&#34;(min-width: 768px) 730px,
                      100vw&#34;
               src=&#34;/pocorgtfo/pocorgtfo22.png&#34; alt=&#34;International Journal of PoC$\|$GTFO&#34; /&gt;&lt;/div&gt;&lt;/center&gt;&lt;/a&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">How to avoid the aCropalypse</title>
    <id>https://www.sultanik.com/blog/acropalypse</id>
    <updated>2023-03-30T07:00:00Z</updated>
    <published>2023-03-30T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/acropalypse" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
Last week, news about CVE-2023-21036, nicknamed the
“&lt;a href=&#34;https://www.da.vidbuchanan.co.uk/blog/exploiting-acropalypse.html&#34; target=&#34;_blank&#34;&gt;aCropalypse&lt;/a&gt;,” spread
across &lt;a href=&#34;https://twitter.com/ItsSimonTime/status/1636857478263750656&#34; target=&#34;_blank&#34;&gt;Twitter&lt;/a&gt; and other
media, and my colleague Henrik Brodin quickly realized that the underlying flaw could be detected by our tool,
&lt;a href=&#34;https://github.com/trailofbits/polytracker&#34; target=&#34;_blank&#34;&gt;PolyTracker&lt;/a&gt;.
Coincidentally, Henrik Brodin, Marek Surovič, and I &lt;a href=&#34;https://arxiv.org/abs/2301.08700&#34; target=&#34;_blank&#34;&gt;wrote&lt;/a&gt;
 a paper that describes this class of bugs, defines a novel approach for detecting them, and introduces our
 implementation and tooling. It will appear at this year’s workshop on Language-Theoretic Security
 (&lt;a href=&#34;https://langsec.org/spw23/&#34; target=&#34;_blank&#34;&gt;LangSec&lt;/a&gt;) at the IEEE Security and Privacy Symposium.
&lt;/p&gt;
&lt;p&gt;
The remainder of this blog post describes the bug and how it could have been detected or even prevented using our tools.
&lt;/p&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2023/03/30/acropalypse-polytracker-blind-spots/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">libmagic</title>
    <id>https://www.sultanik.com/blog/libmagic</id>
    <updated>2022-08-01T07:00:00Z</updated>
    <published>2022-08-01T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/libmagic" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
A &lt;a href=&#34;https://blog.trailofbits.com/2019/11/01/two-new-tools-that-tame-the-treachery-of-files/&#34;&gt;couple of years
ago&lt;/a&gt; I released &lt;a href=&#34;https://github.com/trailofbits/polyfile&#34;&gt;PolyFile&lt;/a&gt;: a utility to identify and map the
semantic structure of files, including polyglots, chimeras, and schizophrenic files. It’s a bit like file, binwalk, and
Kaitai Struct all rolled into one. PolyFile initially used the &lt;a href=&#34;https://mark0.net/soft-trid-deflist.html&#34;&gt;TRiD
definition database&lt;/a&gt; for file identification. However, this database was both too slow and prone to
misclassification, so we decided to switch to libmagic, the ubiquitous library behind the file command.
&lt;/p&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2022/07/01/libmagic-the-blathering/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">PoC‖GTFO Issue 0x21</title>
    <id>https://www.sultanik.com/pocorgtfo/#0x21</id>
    <updated>2022-02-15T00:00:00Z</updated>
    <published>2022-02-15T00:00:00Z</published>
    <link href="https://www.sultanik.com/pocorgtfo/#0x21" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">&lt;a href=&#34;/pocorgtfo/#0x21&#34;&gt;&lt;center style=&#34;padding-top:9px&#34;&gt;&lt;div style=&#34;width:80%;overflow:hidden;border:1px solid #021a40;background:white;&#34;&gt;&lt;img style=&#34;width:100%;padding: 0px;&#34;
               srcset=&#34;/pocorgtfo/pocorgtfo21_large.png  700w,
                       /pocorgtfo/pocorgtfo21_medium.png 500w,
                       /pocorgtfo/pocorgtfo21_small.png  350w&#34;
               sizes=&#34;(min-width: 768px) 730px,
                      100vw&#34;
               src=&#34;/pocorgtfo/pocorgtfo21.png&#34; alt=&#34;International Journal of PoC$\|$GTFO&#34; /&gt;&lt;/div&gt;&lt;/center&gt;&lt;/a&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">What does your code use, and is it vulnerable?</title>
    <id>https://www.sultanik.com/blog/it_depends</id>
    <updated>2021-12-16T07:00:00Z</updated>
    <published>2021-12-16T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/it_depends" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
I am proud to announce the release of
&lt;a href=&#34;https://github.com/trailofbits/it-depends&#34; target=&#34;_blank&#34;&gt;it-depends&lt;/a&gt;, an open-source tool for automatic
enumeration of dependencies. You simply point it to a source code repository, and it will build a graph with the
required dependencies. It-depends currently supports cargo, npm, pip, go, CMake, and autotools codebases, packages in
their associated package managers, and Ubuntu apt.
&lt;/p&gt;
&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2021/12/16/it-depends/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">PDF is Broken: a justCTF Challenge</title>
    <id>https://www.sultanik.com/blog/PDF_is_broken</id>
    <updated>2021-02-02T07:00:00Z</updated>
    <published>2021-02-02T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/PDF_is_broken" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
&lt;p&gt;
I recently created a challenge for the &lt;a href=&#34;https://2020.justctf.team/&#34; target=&#34;_blank&#34;&gt;justCTF competition&lt;/a&gt;
titled &lt;a href=&#34;https://2020.justctf.team/challenges/1&#34; target=&#34;_blank&#34;&gt;&lt;i&gt;PDF is broken, and so is this file&lt;/i&gt;&lt;/a&gt;.
It demonstrates some of the PDF file format’s idiosyncrasies in a bit of an unusual steganographic puzzle. CTF
challenges that amount to finding a steganographic needle in a haystack are rarely enlightening, let alone enjoyable.
LiveOverflow recently had &lt;a href=&#34;https://www.youtube.com/watch?v=VVdmmN0su6E#t=11m32s&#34; target=&#34;_blank&#34;&gt;an excellent
video on file format tricks&lt;/a&gt; and concludes with a similar sentiment. Therefore, I designed this challenge to teach
justCTF participants some PDF tricks and how some of the open source tools I&amp;rsquo;ve helped develop can make easy work of
these forensic challenges.
&lt;/p&gt;
&lt;p&gt;
Read the full post on the Trail of Bits blog for spoilers on how to solve the puzzle.
&lt;/p&gt;&lt;div class=&#34;alert tob-alert&#34;&gt;
&lt;img src=&#34;/images/logos/Trail-of-Bits-main-dark-background.png&#34; height=&#34;32px&#34;/&gt;
This is an excerpt from the &lt;a href=&#34;https://www.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;Trail of Bits&lt;/a&gt;
&lt;a href=&#34;https://blog.trailofbits.com/&#34; target=&#34;_blank&#34;&gt;blog&lt;/a&gt;.
You can read the full post &lt;a href=&#34;https://blog.trailofbits.com/2021/02/02/pdf-is-broken-a-justctf-challenge/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.
&lt;/div&gt;</content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">So, you’re thinking about getting a Ph.D.</title>
    <id>https://www.sultanik.com/blog/PhDCurious</id>
    <updated>2020-04-08T07:00:00Z</updated>
    <published>2020-04-08T07:00:00Z</published>
    <link href="https://www.sultanik.com/blog/PhDCurious" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">
            &lt;div&gt;
            &lt;style scoped&gt;
            .content img {max-width: 80%; display: block; margin-top: 16px; margin-bottom: 12px; margin-left: auto; margin-right: auto; padding: 4px; background-color: #fff; border: 1px solid #ddd; border-radius: 4px;}
            &lt;/style&gt;
            
&lt;p&gt;
    &lt;b&gt;Note:&lt;/b&gt; My advice is specifically related to the higher education system in the US; other countries have very different systems.
    My advice is also solely based on experience in the field of Computer Science; this may translate to other STEM fields, but certainly not all academic fields.
&lt;/p&gt;
&lt;h2&gt;Do you really want a Ph.D.?&lt;/h2&gt;
&lt;p&gt;
    Make sure you are doing this for the right reasons!
&lt;/p&gt;
&lt;h3&gt;Reasons &lt;em&gt;to&lt;/em&gt; get a Ph.D.&lt;/h3&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;b&gt;You want to work in academia.&lt;/b&gt; If you want to get a tenure track research position at a university, you need a Ph.D.&lt;/li&gt;
    &lt;li&gt;&lt;b&gt;You need it to get a promotion at work.&lt;/b&gt;
        This is typically only true at larger corporations, where having
        certain credentials is necessary to progress through the ranks.
    &lt;/li&gt;
    &lt;li&gt;&lt;b&gt;You enjoy being in an academic environment and solely want the experience.&lt;/b&gt;
        This is perfectly valid. Being in grad school can (but isn’t guaranteed to) be incredibly invigorating.
    &lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Reasons &lt;em&gt;not&lt;/em&gt; to get a Ph.D.&lt;/h3&gt;

&lt;h4&gt;Dat Phizzle Dizzle Doh&lt;/h4&gt;
The novelty of putting those letters after your name and/or being called “Doctor” wears off real quick.

&lt;h4&gt;You just want to teach at a university&lt;/h4&gt;
Universities are really hungry for adjunct professors these days. You usually don’t need a Ph.D. to teach.
Try teaching a class or two before you commit to getting a Ph.D. and making that your career.
I’ve taught a bunch of classes, both at the undergraduate and graduate levels, including developing the entire syllabus,
assignments, and slides all from scratch. It is &lt;em&gt;a lot&lt;/em&gt; of work, and usually not worth what they pay you.

&lt;h4&gt;You want to work on your dissertation topic for the rest of your career&lt;/h4&gt;
I know dozens, maybe hundreds of Ph.D.s, and I can count on one hand the number of people who continued research related
to their dissertation topic after graduation.

&lt;h4&gt;Imposter Syndrome&lt;/h4&gt;
I’ve worked with plenty of people with &lt;em&gt;no degree&lt;/em&gt; who are far more capable than people with multiple grad
degrees.

&lt;h4&gt;You’re probably not going to get a job in academia&lt;/h4&gt;
I know &lt;em&gt;several&lt;/em&gt; people who got Ph.D.s from top tier schools like CMU and MIT and all of them either ended up
in industry or teaching at small liberal arts schools with no graduate program (because they were dead set on ascending
the ivory tower). The academic market is super tough, and will only get tougher thanks to the inevitable closure of
smaller schools and a general preference for adjuncts over tenure-track professors. Ph.D. programs do not limit the
number of students they accept based on the anticipated number of professorial job openings. There are many more
Ph.D.s than professorships!

&lt;h4&gt;Even if you do get your dream job in academia, you’ll probably hate it and/or lose it&lt;/h4&gt;
I don’t think I know of a single professor, tenured or otherwise, who loves their job.
They need to take on a huge teaching load thanks to the dearth of adjuncts and/or assume administrative positions that
do not incur an increased salary.

&lt;h4&gt;The financial implications and opportunity cost of leaving your job for three to ten years&lt;/h4&gt;
Some studies have concluded that getting a Ph.D. will
&lt;a href=&#34;https://web.cs.ucdavis.edu/~matloff/itaa.real.html&#34;&gt;require up to &lt;em&gt;fifty&lt;/em&gt; years&lt;/a&gt; to outweigh the
opportunity cost of staying in the workforce and advancing your career. But in some circumstances
&lt;a href=&#34;/blog/Economics_of_Education&#34;&gt;it can be as few as five years&lt;/a&gt;. This is because there is a lot of variance in
the compensation for graduate students. Be prepared for three to ten years of significantly reduced income.

&lt;h4&gt;The Snake Fight&lt;/h4&gt;
&lt;a href=&#34;https://www.mcsweeneys.net/articles/faq-the-snake-fight-portion-of-your-thesis-defense&#34;&gt;Beware&lt;/a&gt;.

&lt;h3&gt;Common reasons you will fail&lt;/h3&gt;

There are myriad reasons why you might fail to complete your Ph.D. that are almost all completely out of your control.

&lt;h4&gt;Survivor bias is real. Trust me, I’m a survivor.&lt;/h4&gt;
Only two out of the ~dozen students in my research lab ever completed their degree. Keep that in mind when you take
advice from the survivors.

&lt;h4&gt;Someone “scoops” your research&lt;/h4&gt;
This is typically more of an issue in the more theoretical specializations, but it does happen. If someone solves your
problem before you, you’ve got to start over. &lt;a href=&#34;/blog/Retirement_planning&#34;&gt;I’ve written an essay about this.&lt;/a&gt;

&lt;h4&gt;Your advisor switches schools&lt;/h4&gt;
Sometimes this can be a good thing; for example, a friend of mine’s advisor transferred from an average school to MIT
right before my friend graduated, and he was able to transfer over all of his credits, defend at MIT, and get MIT on his
diploma. But I also know a bunch of people who were bitten by this, where the new school would not accept their credits
and/or there was no funding at the new school for tuition remission and a stipend, so they basically had to drop out.

&lt;h4&gt;Your advisor goes on sabbatical&lt;/h4&gt;
It’s hard to be advised if your advisor is off galavanting for a year or two. Good advisors plan for this, but I know of
several cases where students had to drop out because their advisor didn’t plan ahead.

&lt;h4&gt;You don’t get along with your advisor, or they go AWOL, or their tenure application is denied, (or they die)&lt;/h4&gt;

Ever look at a 101-level STEM textbook? There are usually at least two authors: The one who knows what they’re talking
about, and the one who speaks English as a native language. I had two advisors for basically the same reason. My first
advisor had lots of research grants and contracts which afforded me tuition remission and a good stipend. But that work
was mostly applied science; nothing was deep enough to turn into a thesis topic. So I took on a co-advisor who had just
been hired as a new tenure-track professor and was full of cool ideas. A few months later he unfortunately, suddenly,
died. Then I took on a &lt;em&gt;third&lt;/em&gt; co-advisor (who was happy to take me on because he didn’t have to worry about
paying me from his own grants). This amounted to more work for me, since I had to do the work to “pay the bills” with my
original advisor &lt;em&gt;as well as&lt;/em&gt; my &lt;em&gt;actual&lt;/em&gt; research with my new co-advisor. But it also gave me a bunch of
freedom to just work on what I wanted. With that said, I had two labmates who were working under my late co-advisor who
were unable to find a place for themselves after his death, and never completed their dissertations. A lot of it is
luck.

If a professor’s tenure application is denied, they are usually given a year to wrap up their business and leave the
school. Most departments have contingency plans to pair orphaned graduate students with new advisors, but this can be
a devastating blow to most students, for all intents and purposes similar to their passing away.

&lt;h4&gt;You don’t have enough time to focus on your research&lt;/h4&gt;
In my case, I was effectively working a full time job doing applied research for my first advisor &lt;em&gt;in addition&lt;/em&gt;
to being a “regular” graduate student with my co-advisor. This entailed 60+ hour work weeks for basically my entire
Ph.D. It’s super hard to focus on research if you have a full time job; I only know of one or two people who
successfully completed a part-time Ph.D. while working a full time job at the same time.

&lt;h2&gt;You still want to get a Ph.D.?&lt;/h2&gt;
&lt;h3&gt;Things you need to do before applying&lt;/h3&gt;
&lt;h4&gt;Do you already have a master’s degree?&lt;/h4&gt;
Some schools in the US do not require you to take &lt;em&gt;any&lt;/em&gt; classes, while most others require you to effectively
earn a Master’s in the process of getting your Ph.D.

If you &lt;em&gt;do not&lt;/em&gt; have a Master’s yet, try and choose a school that effectively forces you to earn a Master’s in
the process of getting a Ph.D., as that will be a nice consolation prize in the event that you do not complete your
dissertation.

If you &lt;em&gt;do&lt;/em&gt; have a Master’s, check on your prospective school’s degree requirements and whether they will accept
your existing credits. If a school requires you to take a bunch of classes and you don’t want to earn a second Master’s,
make sure they will waive that requirement for you. This affected me when I was deciding on which program to join, since
I already had a Master’s and many schools wouldn’t budge on forcing me to re-do all of my Master’s classes.

&lt;h4&gt;Decide in what you want to specialize&lt;/h4&gt;

More on this below, but it’s best if you know what you want to research &lt;em&gt;before&lt;/em&gt; you apply to a program.
You don’t choose a school for a Ph.D. the same way you choose a school for an undergrad or even a Master’s degree.
Choose the school based upon how your desired research aligns with what the professors there are doing, &lt;em&gt;not&lt;/em&gt;
based upon the name or prestige of the school.

&lt;h4&gt;Read the entire Ph.D. Comics archive&lt;/h4&gt;

&lt;a href=&#34;https://phdcomics.com/comics/archive_list.php&#34;&gt;Seriously, it’s really good, and completely accurate.&lt;/a&gt;

&lt;h3&gt;How to get into a good program&lt;/h3&gt;

&lt;h4&gt;Find potential advisors first&lt;/h4&gt;
Compile a list of everyone who is actively doing research in an area related to your desired specialization.
Send them an E-mail stating your desire to pursue a Ph.D. Ask them if they are taking on new students, and, if so, what
their time frame is. The easiest way to get accepted to a Ph.D. program is to have a professor advocating on your
behalf. If a professor wants to work with you, they can guide and even fast-track you through the admissions process.

&lt;h4&gt;You should not have to pay your way through a Computer Science Ph.D.&lt;/h4&gt;
Don’t expect to be rich, but every decent computer science Ph.D. program should offer tuition remission &lt;em&gt;and&lt;/em&gt; a
slightly-above-the-poverty-line stipend, either by acting as a teaching assistant (TA) or as a research assistant (RA).
Do not accept any less. If the school wants you to pay for your Ph.D., something is wrong.
Being an RA is preferable to a TA.

&lt;h4&gt;Having a source of external funding lined up will get you into almost any school&lt;/h4&gt;
The biggest limiting factor in taking on new students both at the departmental and professorial levels is funding.
A professor will not advise a new student unless they have enough funding (either through grants/contracts that fund
RA-ship, or through departmental TA-ships). If there are no TA openings and/or the professor doesn’t have enough grant
funding to pay for your stipend and tuition remission, then they won’t take you on as a student.
In such situations, you can either pay for your own tuition and forego a stipend (never, ever, do this!),
or you can come to the table with &lt;em&gt;your own&lt;/em&gt; external source of funding! This can be through a grant
program (&lt;i&gt;e.g.&lt;/i&gt;, the &lt;a href=&#34;https://www.nsf.gov/funding/pgm_summ.jsp?pims_id=6201&#34;&gt;NSF GRFP&lt;/a&gt;).
If a professor doesn’t have to worry about how to “feed” you, they’ll be thrilled to work with you, and it will give you
a lot more freedom in directing your own research.

&lt;h3&gt;How to minimize your chances of failing&lt;/h3&gt;

&lt;h4&gt;Talk to your potential advisor’s current and past students&lt;/h4&gt;

Do this preferably before even applying. How many of the professor’s students actually graduate?
Where do they end up after graduation? How many papers does each student publish per year?
How is travel to conferences funded?

&lt;a href=&#34;https://phdcomics.com/comics/archive.php?comicid=997&#34;&gt;&lt;img src=&#34;/images/phdcomics/997.gif&#34;
                                                                    alt=&#34;PhD Comics Number 997&#34;/&gt;&lt;/a&gt;

What is the professor’s advising style like? This will vary drastically from professor to professor.
I’d be lucky to talk to one of my co-advisors once a month.

&lt;a href=&#34;https://phdcomics.com/comics/archive.php?comicid=851&#34;&gt;&lt;img src=&#34;/images/phdcomics/851.gif&#34;
                                                                    alt=&#34;PhD Comics Number 851&#34;/&gt;&lt;/a&gt;

My other co-advisor would actually sit down with me 1-on-1 and we’d read aloud a new paper together,
sentence-by-sentence, ensuring that we each understood what was written before moving on. Some people might hate that,
though. Different styles work for different kinds of students. Some professors demand that you work on a specific
problem they have defined, whereas others expect you to carve out your research topic yourself. Determine what type of
advisor you &lt;em&gt;think&lt;/em&gt; you need, and interview existing students to see if the professor meets your needs.

&lt;h4&gt;Interview your potential advisor in advance&lt;/h4&gt;
What is a typical week in the life of an advisee like? How many regular meetings are there? How often do students
typically meet with their advisor 1-on-1? Will the professor expect you to take any specific classes, regardless of the
school’s degree requirements? Professors will often require you to take certain classes they think are really good. Is
the professor planning to go on sabbatical any time soon? Do they have tenure? (Typically, professors will earn and
usually take a sabbatical shortly after earning tenure. If a professor applies for tenure and is denied, they usually
only get a year before they are fired. Some schools give professors two chances at getting tenure.) What is the
professor’s teaching load like? Would they expect you to teach and/or TA? Or could you be an RA full time? What is their
research grant pipeline like? When do their current grants end?

&lt;h4&gt;Choose a topic that is unlikely to be “scooped”&lt;/h4&gt;

I already linked to this above, but please &lt;a href=&#34;/blog/Retirement_planning&#34;&gt;read this essay I wrote&lt;/a&gt;.
Try and choose a dissertation topic that can’t be duplicated by someone else first. This usually means choosing a topic
that—even if it is inherently theoretical—could worst-case be “proven” &lt;em&gt;empirically&lt;/em&gt; in the event that you can’t
prove it &lt;em&gt;formally&lt;/em&gt;.

&lt;h4&gt;Remember that your dissertation is unlikely to ever be read by anyone other than your committee members&lt;/h4&gt;

It is, in a sense, a rite of passage. If you don’t intend to go into academia, there is no shame in doing the minimum
amount possible that can get you graduated. With that said,
&lt;a href=&#34;/files/ESultanikPhDDissertationBook.pdf&#34;&gt;my dissertation is super awesome and you should totally read it right
    now&lt;/a&gt;. Plz, become the sixth person to have ever read it.

&lt;a href=&#34;https://phdcomics.com/comics/archive.php?comicid=1164&#34;&gt;&lt;img src=&#34;/images/phdcomics/1164.gif&#34;
                                                                    alt=&#34;PhD Comics Number 1164&#34;/&gt;&lt;/a&gt;

&lt;h2&gt;What to expect after you have a Ph.D.&lt;/h2&gt;

&lt;a href=&#34;https://phdcomics.com/comics/archive.php?comicid=844&#34;&gt;&lt;img src=&#34;/images/phdcomics/844.gif&#34;
                                                                    alt=&#34;PhD Comics Number 844&#34;/&gt;&lt;/a&gt;
&lt;a href=&#34;https://phdcomics.com/comics/archive.php?comicid=994&#34;&gt;&lt;img src=&#34;/images/phdcomics/994.gif&#34;
                                                                    alt=&#34;PhD Comics Number 994&#34;/&gt;&lt;/a&gt;

            &lt;/div&gt;
            </content>
  </entry>
  <entry xml:base="https://www.sultanik.com/recent.atom">
    <title type="text">PoC‖GTFO Issue 0x20</title>
    <id>https://www.sultanik.com/pocorgtfo/#0x20</id>
    <updated>2020-01-21T00:00:00Z</updated>
    <published>2020-01-21T00:00:00Z</published>
    <link href="https://www.sultanik.com/pocorgtfo/#0x20" />
    <author>
      <name>Evan Sultanik</name>
      <uri>https://www.sultanik.com/</uri>
    </author>
    <content type="html">&lt;a href=&#34;/pocorgtfo/#0x20&#34;&gt;&lt;center style=&#34;padding-top:9px&#34;&gt;&lt;div style=&#34;width:80%;overflow:hidden;border:1px solid #021a40;background:white;&#34;&gt;&lt;img style=&#34;width:100%;padding: 0px;&#34;
               srcset=&#34;/pocorgtfo/pocorgtfo20_large.png  700w,
                       /pocorgtfo/pocorgtfo20_medium.png 500w,
                       /pocorgtfo/pocorgtfo20_small.png  350w&#34;
               sizes=&#34;(min-width: 768px) 730px,
                      100vw&#34;
               src=&#34;/pocorgtfo/pocorgtfo20.png&#34; alt=&#34;Grab gifts from the genizah, reading every last page! And write in their margins! And give them all again!&#34; /&gt;&lt;/div&gt;&lt;/center&gt;&lt;/a&gt;</content>
  </entry>
</feed>
