{"generator":"GNU social 2.0.2-dev","title":"Conversation","totalItems":3,"items":[{"actor":{"id":"https:\/\/tilde.zone\/@es0mhi","displayName":"es0mhi","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/19434-original-tmp20250930225421.webp","rel":"avatar","type":"image\/webp","width":386,"height":386},{"url":"https:\/\/gnusocial.jp\/avatar\/19434-96-20251004073126.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/19434-48-20250930234415.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/19434-24-20251004073126.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"19434"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/19434-96-20251004073126.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"homo universalis, radio amateur, unix enthusiast, floss advocate, emacs user, bibliophile, anarchist, teaching at the Estonian Academy of Arts","url":"https:\/\/tilde.zone\/@es0mhi","portablecontacts_net":{"preferredUsername":"es0mhi","displayName":"es0mhi","note":"homo universalis, radio amateur, unix enthusiast, floss advocate, emacs user, bibliophile, anarchist, teaching at the Estonian Academy of Arts"}},"content":"RT @es0mhi @buherator @drwhax I sometimes advise investors (poor life choices I guess) on how to deal with the increased risk of Mythos &amp; others. And this was the bottom line.I don't even need AI specifically to argue for that. The time-to-exploit has been dropping forever. We've built better catalogs and more versatile infrastructure and complex automations. It's very clear that this includes vuln research as well.We had this already with static analysis hitting the field. We answered with &quot;shift left&quot;: Building security into the dev process, since the earlier you do it, the less issues you'll end up with. Every step earlier has more downstream impact.We've finally reached the stage where security as part of your design &amp; architecture is not only best practice but becoming a hard requirement. Our automations (including LLMs) pushed us there and we need to deal with the outcome.Or should. Because I'm a cynic and I've seen what's happened, I doubt that engineering will follow through with this. I see two paths and we'll move along both, and I don't like either: Acceptance and few centralized Oligopols.1\/2","generator":{"id":"tag:gnusocial.jp,2026-09-07:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/tilde.zone\/users\/es0mhi\/statuses\/116997369988777188\/activity","object":{"id":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","objectType":"note","content":"<a class=\"u-url mention\" href=\"https:\/\/infosec.exchange\/@drwhax\">@drwhax<\/a> Maybe the advice of the wiser among us will be heard after all these decades: focus on robust mitigations and attack surface reduction, because the moles can't be whacked anymore.","url":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","status_net":{"notice_id":null}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-07-28:objectType=thread:nonce=c43a830d39affe5f","notice_info":{"local_id":"12960222","source":"ActivityPub","repeat_of":"12960220"}},"published":"2026-07-28T11:30:08+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"title":"es0mhi repeated a notice by buherator","verb":"share","url":"https:\/\/tilde.zone\/users\/es0mhi\/statuses\/116997369988777188\/activity"},{"actor":{"id":"https:\/\/infosec.place\/users\/buherator","displayName":"buherator","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/105742-original-tmp20230309202713.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/105742-96-20230309202713.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/105742-48-20230309202713.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/105742-24-20230309202713.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"105742"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/105742-96-20230309202713.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"A drunken debugger","url":"https:\/\/infosec.place\/users\/buherator","portablecontacts_net":{"preferredUsername":"buherator","displayName":"buherator","note":"A drunken debugger"}},"content":"<a class=\"u-url mention\" href=\"https:\/\/infosec.exchange\/@drwhax\">@drwhax<\/a> Maybe the advice of the wiser among us will be heard after all these decades: focus on robust mitigations and attack surface reduction, because the moles can't be whacked anymore.","generator":{"id":"tag:gnusocial.jp,2026-09-07:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","object":{"id":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","objectType":"note","content":"<a class=\"u-url mention\" href=\"https:\/\/infosec.exchange\/@drwhax\">@drwhax<\/a> Maybe the advice of the wiser among us will be heard after all these decades: focus on robust mitigations and attack surface reduction, because the moles can't be whacked anymore.","url":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","status_net":{"notice_id":null}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/person","id":"https:\/\/infosec.exchange\/users\/drwhax"},{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-07-28:objectType=thread:nonce=c43a830d39affe5f","notice_info":{"local_id":"12960220","source":"ActivityPub"}},"published":"2026-07-28T11:29:54+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34"},{"actor":{"id":"https:\/\/todon.eu\/users\/ljrk","displayName":"lj\u00b7rk","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/105402-original-tmp20260818212841.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/105402-96-20260821001514.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/105402-48-20260819181313.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/105402-24-20260821001514.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"105402"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/105402-96-20260821001514.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"gecos\/CN: Janis Joan K\u00f6nigSAN: ElleJay (lj), Leo(nard) Robert K\u00f6nigNyanbinary femby \ud83d\udc08\u200d\u2b1bBragging Rights: Made a former German conservative minister greet me in full cat girl outfit. \u2022 tech-savvy luddite \u2022 gender-overwhelmed gender-bender \u2022 energy-seeping sleepy-head \u2022 serious goofballSee pinned post for more #intro and what to expect here","url":"https:\/\/todon.eu\/@ljrk","portablecontacts_net":{"preferredUsername":"ljrk","displayName":"lj\u00b7rk","note":"gecos\/CN: Janis Joan K\u00f6nigSAN: ElleJay (lj), Leo(nard) Robert K\u00f6nigNyanbinary femby \ud83d\udc08\u200d\u2b1bBragging Rights: Made a former German conservative minister greet me in full cat girl outfit. \u2022 tech-savvy luddite \u2022 gender-overwhelmed gender-bender \u2022 energy-seeping sleepy-head \u2022 serious goofballSee pinned post for more #intro and what to expect here"}},"content":"<p><a href=\"https:\/\/infosec.place\/users\/buherator\" class=\"u-url mention\">@buherator<\/a> <a href=\"https:\/\/infosec.exchange\/@drwhax\" class=\"u-url mention\">@drwhax<\/a> I sometimes advise investors (poor life choices I guess) on how to deal with the increased risk of Mythos &amp; others. And this was the bottom line.<\/p><p>I don't even need AI specifically to argue for that. The time-to-exploit has been dropping forever. We've built better catalogs and more versatile infrastructure and complex automations. It's very clear that this includes vuln research as well.<\/p><p>We had this already with static analysis hitting the field. We answered with \"shift left\": Building security into the dev process, since the earlier you do it, the less issues you'll end up with. Every step earlier has more downstream impact.<\/p><p>We've finally reached the stage where security as part of your design &amp; architecture is not only best practice but becoming a hard requirement. Our automations (including LLMs) pushed us there and we need to deal with the outcome.<\/p><p>Or should. Because I'm a cynic and I've seen what's happened, I doubt that engineering will follow through with this. I see two paths and we'll move along both, and I don't like either: Acceptance and few centralized Oligopols.<\/p><p>1\/2<\/p>","generator":{"id":"tag:gnusocial.jp,2026-09-07:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/todon.eu\/users\/ljrk\/statuses\/116997333273553968","object":{"id":"https:\/\/todon.eu\/users\/ljrk\/statuses\/116997333273553968","objectType":"note","content":"<p><a href=\"https:\/\/infosec.place\/users\/buherator\" class=\"u-url mention\">@buherator<\/a> <a href=\"https:\/\/infosec.exchange\/@drwhax\" class=\"u-url mention\">@drwhax<\/a> I sometimes advise investors (poor life choices I guess) on how to deal with the increased risk of Mythos &amp; others. And this was the bottom line.<\/p><p>I don't even need AI specifically to argue for that. The time-to-exploit has been dropping forever. We've built better catalogs and more versatile infrastructure and complex automations. It's very clear that this includes vuln research as well.<\/p><p>We had this already with static analysis hitting the field. We answered with \"shift left\": Building security into the dev process, since the earlier you do it, the less issues you'll end up with. Every step earlier has more downstream impact.<\/p><p>We've finally reached the stage where security as part of your design &amp; architecture is not only best practice but becoming a hard requirement. Our automations (including LLMs) pushed us there and we need to deal with the outcome.<\/p><p>Or should. Because I'm a cynic and I've seen what's happened, I doubt that engineering will follow through with this. I see two paths and we'll move along both, and I don't like either: Acceptance and few centralized Oligopols.<\/p><p>1\/2<\/p>","url":"https:\/\/todon.eu\/@ljrk\/116997333273553968","status_net":{"notice_id":null},"inReplyTo":{"objectType":"note","id":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34","url":"https:\/\/infosec.place\/objects\/cd1478c3-3bf9-4a16-ab0b-9b34c20bad34"}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/person","id":"https:\/\/infosec.exchange\/users\/drwhax"},{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/person","id":"https:\/\/infosec.place\/users\/buherator"},{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-07-28:objectType=thread:nonce=c43a830d39affe5f","notice_info":{"local_id":"12960221","source":"ActivityPub"}},"published":"2026-07-28T11:29:53+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/todon.eu\/@ljrk\/116997333273553968"}],"links":[{"url":"https:\/\/gnusocial.jp\/conversation\/6582967","rel":"alternate","type":"text\/html"}]}