GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)

  1. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 17-Jun-2025 01:54:53 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell
    • BeyondMachines :verified:
    • rk: it’s hyphen-minus actually

    @inthehands @rk @beyondmachines1 💯 % agree. I've tried to show this visually in https://shostack.org/blog/strategy-for-threat-modeling-ai/ would appreciate your feedback.

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: shostack.org
      Shostack + Friends Blog > Strategy for threat modeling AI
      from @adamshostack
      Clarifying how to threat model AI
  2. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 17-Jun-2025 01:45:55 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell
    • BeyondMachines :verified:
    • rk: it’s hyphen-minus actually

    @rk @inthehands @beyondmachines1 In the sense of LLMs being good at generating clocks at 10:10, it would not surprise me to discover that LLMs have preferences for certain MFA values that were used in a google blog post.

    In conversation about 2 days ago from infosec.exchange permalink
  3. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 10-Jun-2025 23:11:37 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    • Matt Blaze

    @mattblaze speaking about voting at security and human behavior #shb

    In conversation about 8 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/659/246/816/204/930/original/eb86ebd08eb08cdf.jpeg
  4. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 01-Jun-2025 23:45:06 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    This is a really awful situation for many authors. If you like an author whose books are available anywhere else, buy elsewhere. (There’s an argument in thread for buying through Boundless, but I think it throws good money at bad actors.) https://wandering.shop/@clacksee/114606754167072778

    In conversation about 17 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Shouty person (@clacksee@wandering.shop)
      from Shouty person
      Over on BlueSky, authors are sharing their #unbound horror stories. It’s awful. So much worse than I imagined. It’s Alan Dean Foster vs Disney all over again. Unbound went into liquidation and immediately a new company, Boundless, popped up. They now own all of Unbound’s assets … and none of its debts. There are so many authors owed tens of thousands of pounds each. Many of them have no other source of income and this represents a year’s worth of royalties. @bookstodon@a.gup.pe @lgbtqbookstodon@a.gup.pe
  5. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 26-May-2025 09:16:45 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Gary McGraw

    @cigitalgem BUT ALIGNMENT AND GUARDRA1LZ and Firewulls will fix it, right?

    In conversation about 23 days ago from infosec.exchange permalink
  6. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 21-May-2025 22:41:11 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    New blog: Free Threat Modeling Training for Displaced Federal Workers

    US Government employees (and former employees) are going through a lot of chaos. Many of our colleagues, collaborators, and friends are out of work — suddenly and unexpectedly.

    At Shostack + Associates, we can’t fix that. But we can offer something concrete.

    In times of uncertainty, we focus on what we know, and what we know is threat modeling and how to teach it. It’s what we do best, and it’s how we can help.

    (1/4) full post, links: https://is.gd/nYz3y2

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/541/893/461/943/588/original/6cb05095ee8cad8b.png


    2. Domain not in remote thumbnail source whitelist: shostack.org
      Shostack + Friends Blog > Free Threat Modeling Training for Displaced Federal Workers
      from @adamshostack
      Free training for displaced government employees
  7. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Thursday, 15-May-2025 11:53:00 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Heidi Li Feldman
    • Paul_IPv6

    @paul_ipv6 @heidilifeldman I believe you have to wait for the beauty of watching a court struggle to square originalism with immunity.

    It’s going to be glorious. I mean in the sense of “this shall not stand” and bad for the republic but nice violin music.

    In conversation about a month ago from infosec.exchange permalink
  8. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Thursday, 15-May-2025 11:52:53 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Heidi Li Feldman
    • Paul_IPv6

    @heidilifeldman @paul_ipv6 Who could have predicted that absolute immunity would be a tarpit?!?

    In conversation about a month ago from infosec.exchange permalink
  9. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 13-May-2025 05:50:08 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    This season of #andor sets aside childish things, and brings great writing, acting, and cinematography to #starwars in a way that the universe has always deserved and rarely gotten.

    If you're not watching it, this is some of the best TV I've ever seen. I enjoy a lot of Star Wars, and do so understanding that most of it is fun and somewhat lighthearted in a very dystopian world.

    Eric Geller has an amazing 11000 word analysis of this week's 3 episodes of #Andor.

    https://ericgeller.wordpress.com/2025/05/10/andor-season-2-review-episodes-7-9/

    In conversation about a month ago from infosec.exchange permalink
  10. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 12-May-2025 03:53:54 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    Folks it’s very unreasonable to claim the #qatar plane will be covered in microphones.

    The Qataris are experienced surveillance experts.

    The plane will be full of microphones.

    In conversation about a month ago from infosec.exchange permalink
  11. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 05-May-2025 12:30:59 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    • Matt Blaze
    • Steve Bellovin

    This is literally the message of 30 years of reporting on wiretap laws by @mattblaze @SteveBellovin Susan Landau and many others: designing these systems is exceptionally hard. That’s part of why the systems to handle classified data are so expensive. https://newsie.social/@bespacific/114451910633689677

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      beSpacific (@bespacific@newsie.social)
      from beSpacific
      #TeleMessage, that app used by the #Trump administration to archive Signal messages, has been #hacked. The #hacker managed to get some users' #Signal group chats and messages too. This is a hugely significant #breach not just for those individual customers, but also for the U.S. government more widely. #natsec #nationalsecurity https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/ #government #democracy #trump #hegseth
  12. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 05-May-2025 07:17:35 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    This May the Fourth, remember that rebellions are built on hope.

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/451/210/248/434/838/original/d24f6a6a700c26b9.png
  13. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 11-Apr-2025 03:05:37 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    How can they have "an abundance of caution" but not be able to handle the "complexity and scope" of understanding what they've done?

    That doesn't sound like an abundance to me.

    https://masto.deoan.org/@neurovagrant/114314578899331634

    In conversation about 2 months ago from infosec.exchange permalink
  14. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Tuesday, 08-Apr-2025 09:29:43 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    Today's "history is boring" lesson: The Declaration of Independence lists "For transporting us beyond Seas to be tried for pretended offences" as one of the reasons Independence was important.

    In conversation about 2 months ago from infosec.exchange permalink
  15. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 30-Mar-2025 03:00:30 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    • Matthew Green

    @matthew_d_green Is it normal for a university to memory hole a former professor's pages? I thought the norm was to keep scholarship present, but possibly mark it as an inactive page.

    In conversation about 3 months ago from infosec.exchange permalink
  16. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Saturday, 22-Mar-2025 05:17:07 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell
    • Brian Vastag

    @brianvastag
    @inthehands had a thread on better ways to bet against Tesla stock

    In conversation about 3 months ago from infosec.exchange permalink
  17. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Saturday, 22-Mar-2025 05:17:05 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell
    • Brian Vastag

    @brianvastag @inthehands yeah, short 😇 form: retail investors should never short any stock. It's one of the few forms that has potentially larger downside than the investment.

    In conversation about 3 months ago from infosec.exchange permalink
  18. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 21-Mar-2025 02:59:31 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell

    @inthehands Also: realize that this is a bad investment but may be a good or fun gamble.

    In conversation about 3 months ago from infosec.exchange permalink
  19. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 03-Mar-2025 02:43:45 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:
    in reply to
    • Paul Cantrell

    @inthehands Let it go Paul, it's mastodon and the HOA members need you to understand they have never made a mistake, and also their hobby-horse explains that thing perfectly.

    (1/n)

    In conversation about 4 months ago from infosec.exchange permalink
  20. Embed this notice
    Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 02-Mar-2025 08:40:35 JST Adam Shostack :donor: :rebelverified: Adam Shostack :donor: :rebelverified:

    I prefer text heavy slides, because they're useful to an audience who (1) loses the thread (2) doesn't speak english as a first language (3) wants to tweet screenshots.

    Does anyone actually prefer a technical conference talk where the slides are all pictures? (Assuming clipart, LLM-generated, etc, not custom graphics)

    In conversation about 4 months ago from infosec.exchange permalink
  • Before

User actions

    Adam Shostack :donor: :rebelverified:

    Adam Shostack :donor: :rebelverified:

    Author, game designer, technologist, teacher.Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security.Following back if you have content.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          102150
          Member since
          27 Feb 2023
          Notices
          66
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.