@ryanc Hey look I’m not the one who under specified the requirements! 😂
Notices by Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 03-Nov-2024 06:54:55 JST Adam Shostack :donor: :rebelverified: -
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 03-Nov-2024 06:22:44 JST Adam Shostack :donor: :rebelverified: @ryanc a trapdoor?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 30-Sep-2024 01:10:07 JST Adam Shostack :donor: :rebelverified: I find myself really irked by the headline here. The problem is not a "simple website bug", the problem is that they wrote thousands of lines of code without ever thinking about what the trust boundaries are, or should be.
This is a massive design flaw. The idea that cars should be controllable from some mothership is bizarre (and not needed for app control - have a digital signature from the mobile device). The idea that cars are enrolled even if the user didn't set up an account is similarly broken. This isn't a "simple website bug" but a massive failure to consider the security implications of features.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Saturday, 21-Sep-2024 10:37:17 JST Adam Shostack :donor: :rebelverified: @luckytran @inthehands In reading about this, I learned there are already nasal vaccines, which no one had ever mentioned to me. They require administering by a professional, what’s new is the “at home?”
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 09-Sep-2024 11:45:55 JST Adam Shostack :donor: :rebelverified: @noondlyt @inthehands Why is that, Leon?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 08-Sep-2024 08:15:51 JST Adam Shostack :donor: :rebelverified: @ryanc I don't do this because the 30-60 second lag to get the email, plus all the shiny distractions in my email, but, yeah, it's not stupid.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 01-Sep-2024 23:45:57 JST Adam Shostack :donor: :rebelverified: @patrickcmiller "Sinister Sysadmin" is my new threat actor/prog rock band name.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 01-Sep-2024 05:58:03 JST Adam Shostack :donor: :rebelverified: Hmmm, no thank you I think I don't want to run this code
sudo rm -rf "${studio_path}/" -mindepth 1 -maxdepth 1 ! -name "ldraw" -exec rm -rf {} +
(Bricklink studio /scripts/preinstall)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 26-Aug-2024 04:03:03 JST Adam Shostack :donor: :rebelverified: @inthehands @paul_ipv6 Did you try youtube or tiktok (or something else?) I've found that fix it videos are MUCH better on tt because they impose time limits rather than using minutes watched as a signal of quality.
I don't know if that applies to explainers like you're looking for, but I watched 5 minutes of a YT video on Alcatraz doors and learned exactly nothing.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 24-Apr-2024 11:27:52 JST Adam Shostack :donor: :rebelverified: @ryanc Thank you.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 27-Mar-2024 08:08:34 JST Adam Shostack :donor: :rebelverified: @ryanc @tess @sophieschmieg @david_chisnall @Vrimj I'm fond of asking "are you asking that because you don't know how to fix it, or because you really think it'll never happen?" (1/3)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 18-Mar-2024 01:18:13 JST Adam Shostack :donor: :rebelverified: "They are requesting $22 million this year, up from $5 million last year, to test autonomous weapons software against complex scenarios involving ethical decisions. "
I can guess the answer for only $50,000. Why so much? Editing my "You idiots" into acceptable text is going to be expensive.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 11-Feb-2024 04:56:14 JST Adam Shostack :donor: :rebelverified: @paul_ipv6 @inthehands I was thinking about Paul’s comment as I wondered why a ^ disappeared between generative2 in a post here
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 11-Feb-2024 04:56:12 JST Adam Shostack :donor: :rebelverified: @paul_ipv6 @inthehands Well, correct fractions or not, no one would ever have struggled with underfull hboxes like they have to in css
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 27-Dec-2023 10:50:40 JST Adam Shostack :donor: :rebelverified: @inthehands @Haste IANALE, but if you're relying on a tool that says "Hey, this thing is full of errors" maybe that's a sign that you should be.
Of course, fancy lawyers will make a case that it's unsettled law
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 26-Dec-2023 13:01:52 JST Adam Shostack :donor: :rebelverified: @Haste @inthehands We don’t need a new law. There’s no reason to think “the devil made me do it” is a defense.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 20-Nov-2023 12:24:07 JST Adam Shostack :donor: :rebelverified: @eaton I’ve found the ui in happyscribe to be really helpful even if I can get transcription elsewhere.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 10-Nov-2023 04:28:29 JST Adam Shostack :donor: :rebelverified: @petergleick @inthehands I see this is CPI adjusted (cool!). Is there a version that normalizes against population growth?
(Yes there’s complexity of overall growth vs growth in high danger areas).
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 10-Oct-2023 11:40:06 JST Adam Shostack :donor: :rebelverified: @linear @irenes The US office of science and tech policy has an open call for comments about the future of open source security. I want to encourage you to tell them about your choices so they don’t randomly default to “of course wallet names are a fine thing”
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 18-Jun-2023 15:00:52 JST Adam Shostack :donor: :rebelverified: This is next level APT TTP right here. https://twitter.com/llm_sec/status/1667573374426701824
“* People ask LLMs to write code
- LLMs recommend imports that don't actually exist
- Attackers work out what these imports' names are, and create & upload them with malicious payloads
- People using LLM-written code then auto-add malware themselves”