Episode #329 - AI exploitability, IDOR prevention, Smart TV Proxies
Discussions cover an OpenAI security incident at Hugging Face, analyzing whether models exhibit novel offensive capabilities or just expensive vulnerability chaining. The conversation revisits AppSec fundamentals via an IDOR article, stressing framework-level authorization, typed IDs, and tenant checks over ad-hoc fixes. Finally, the focus turns to Krebs' report on LG banning residential proxy SDKs from smart TVs to stop IoT device exploitation.