@libreoffice Where is that “board report”? Where can we find release histories?
Notices by Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange), page 2
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 25-Dec-2024 17:01:58 JST Adam Shostack :donor: :rebelverified:
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 25-Dec-2024 17:01:58 JST Adam Shostack :donor: :rebelverified:
@libreoffice Also: citation needed please?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 13-Dec-2024 06:20:17 JST Adam Shostack :donor: :rebelverified:
@ryanc Surely…
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 13-Dec-2024 06:11:03 JST Adam Shostack :donor: :rebelverified:
@ryanc Well that’ll teach me to take you seriously! 😂
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 13-Dec-2024 04:21:00 JST Adam Shostack :donor: :rebelverified:
@ryanc I don't mean to be snarky, but, really? Is this a studied thing?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 13-Dec-2024 04:19:48 JST Adam Shostack :donor: :rebelverified:
Is there any meaningful security benefit to one time codes being more than 4-6 digits?
(For any of TOTP, email, or sms delivery.)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 02-Dec-2024 12:05:55 JST Adam Shostack :donor: :rebelverified:
@joshbressers Even in 14 the macl and quarantine bits were over the tip
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Friday, 29-Nov-2024 05:25:09 JST Adam Shostack :donor: :rebelverified:
@GossiTheDog We used to get data like that from the malicious software removal tool and Defender... it wouldn't surprise me if there was a ~50% drop from version to version.. we saw that order of improvement from XP to Vista to 7. Some of it's better code and architecture. some of it is the folks who upgrade are more likely to be on top of other parts of managing their systems.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 03-Nov-2024 06:54:55 JST Adam Shostack :donor: :rebelverified:
@ryanc Hey look I’m not the one who under specified the requirements! 😂
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 03-Nov-2024 06:22:44 JST Adam Shostack :donor: :rebelverified:
@ryanc a trapdoor?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 30-Sep-2024 01:10:07 JST Adam Shostack :donor: :rebelverified:
I find myself really irked by the headline here. The problem is not a "simple website bug", the problem is that they wrote thousands of lines of code without ever thinking about what the trust boundaries are, or should be.
This is a massive design flaw. The idea that cars should be controllable from some mothership is bizarre (and not needed for app control - have a digital signature from the mobile device). The idea that cars are enrolled even if the user didn't set up an account is similarly broken. This isn't a "simple website bug" but a massive failure to consider the security implications of features.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Saturday, 21-Sep-2024 10:37:17 JST Adam Shostack :donor: :rebelverified:
@luckytran @inthehands In reading about this, I learned there are already nasal vaccines, which no one had ever mentioned to me. They require administering by a professional, what’s new is the “at home?”
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 09-Sep-2024 11:45:55 JST Adam Shostack :donor: :rebelverified:
@noondlyt @inthehands Why is that, Leon?
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 08-Sep-2024 08:15:51 JST Adam Shostack :donor: :rebelverified:
@ryanc I don't do this because the 30-60 second lag to get the email, plus all the shiny distractions in my email, but, yeah, it's not stupid.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 01-Sep-2024 23:45:57 JST Adam Shostack :donor: :rebelverified:
@patrickcmiller "Sinister Sysadmin" is my new threat actor/prog rock band name.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Sunday, 01-Sep-2024 05:58:03 JST Adam Shostack :donor: :rebelverified:
Hmmm, no thank you I think I don't want to run this code
sudo rm -rf "${studio_path}/" -mindepth 1 -maxdepth 1 ! -name "ldraw" -exec rm -rf {} +
(Bricklink studio /scripts/preinstall)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 26-Aug-2024 04:03:03 JST Adam Shostack :donor: :rebelverified:
@inthehands @paul_ipv6 Did you try youtube or tiktok (or something else?) I've found that fix it videos are MUCH better on tt because they impose time limits rather than using minutes watched as a signal of quality.
I don't know if that applies to explainers like you're looking for, but I watched 5 minutes of a YT video on Alcatraz doors and learned exactly nothing.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 24-Apr-2024 11:27:52 JST Adam Shostack :donor: :rebelverified:
@ryanc Thank you.
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Wednesday, 27-Mar-2024 08:08:34 JST Adam Shostack :donor: :rebelverified:
@ryanc @tess @sophieschmieg @david_chisnall @Vrimj I'm fond of asking "are you asking that because you don't know how to fix it, or because you really think it'll never happen?" (1/3)
-
Embed this notice
Adam Shostack :donor: :rebelverified: (adamshostack@infosec.exchange)'s status on Monday, 18-Mar-2024 01:18:13 JST Adam Shostack :donor: :rebelverified:
"They are requesting $22 million this year, up from $5 million last year, to test autonomous weapons software against complex scenarios involving ethical decisions. "
I can guess the answer for only $50,000. Why so much? Editing my "You idiots" into acceptable text is going to be expensive.