GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Steve Bellovin (stevebellovin@infosec.exchange)

  1. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Wednesday, 07-Jan-2026 06:37:31 JST Steve Bellovin Steve Bellovin

    RE: https://flipboard.social/@newsguyusa/115850233260885949

    Denmark says that if the US attacks Greenland, it will be the end of NATO. Of course, to Trump, that's a feature. Better yet, to him, his BFF Vladimir would love it.

    In conversation about 22 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Steve Herman (@newsguyusa@flipboard.social)
      from Steve Herman
      President Trump is considering using military force to acquire Greenland, White House press secretary Karoline Leavitt tells CNBC. https://www.cnbc.com/2026/01/06/trump-greenland-military-white-house.html
  2. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 04-Jan-2026 04:30:39 JST Steve Bellovin Steve Bellovin

    Does Article 5 of the NATO treaty apply to insider attacks? Asking for a territory of Denmark's.

    In conversation about a month ago from infosec.exchange permalink
  3. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 29-Dec-2025 06:07:49 JST Steve Bellovin Steve Bellovin

    For the record, I hate git.

    In conversation about a month ago from infosec.exchange permalink
  4. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 20-Dec-2025 11:18:23 JST Steve Bellovin Steve Bellovin
    in reply to
    • Matt Blaze

    @mattblaze And take care of your students, both your advisees and classroom students. I've heard some truly horrific stories to accompany requests for short extensions on something. My response is always the same: take care of yourself, don't worry about the deadline, I'll do everything I can to support you if you have to appeal to the dean's office for an exception, and TAKE CARE OF YOURSELF—that's far more important than an arbitrary academic deadline. On more than one occasion, a student has asked for a one week extension due to a family tragedy that I knew was going to require them to get an Incomplete while they processed what happened and grieved—and I made sure that the dean's office knew how strongly I supported the request. People are important. Family is important. Close friends are important. Academic work? Much less so—and apart from anything else, you can't possibly do good academic work when your head and your heart are elsewhere.
    I can't make their pain go away. I can make sure I don't add to it.

    In conversation about a month ago from infosec.exchange permalink
  5. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 11-Dec-2025 01:30:37 JST Steve Bellovin Steve Bellovin

    So this is insane even by his Orangeness Administration's standards. DoJ successfully extradited a Belarusian woman to prosecute her for smuggling aviation components into Russia. She's eligible to be released to home detention pending trial—but if she is, DHS wants to deport her for being in the US illegally.
    https://www.washingtonpost.com/dc-md-va/2025/12/10/extradition-deportation-belarus-russia/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  6. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 11:56:24 JST Steve Bellovin Steve Bellovin
    in reply to
    • Lauren Weinstein
    • Rich Felker
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @lauren @dalias @huitema @lauerhahn @nikatjef Well, if we don't try we're certainly not going to find an answer. And again, unlike the GOP and Obamacare, I'm not saying "abolish it now while we think of something" (and remember that the part of Obamacare they objected to most, mandatory coverage, was essential to the financials of the scheme, which is why they could never find a replacement).
    There is a problem: checks are expensive, environmentally awful, insecure, and subject to all sorts of crimes. What are we going to do about it? DON'T flash-cut, don't announce a short-term deadline, but let's start seriously thinking about this as a systems problem. (Aside: many years ago, I saw an article, I think in CACM, discussing the costs of EFT versus checks. The problem was that no one knew what it cost banks to handle checks—the accounting systems were not set up to capture that kind of data; they broke down costs differently.)

    In conversation about 2 months ago from infosec.exchange permalink
  7. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 11:04:29 JST Steve Bellovin Steve Bellovin
    in reply to
    • Lauren Weinstein
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @huitema @lauerhahn @lauren @nikatjef In the UK, at least, checks are apparently all but extinct—everything seems to be done by EFT (or so I've been told by an American who lived there for about 10 years).

    In conversation about 2 months ago from infosec.exchange permalink
  8. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 10:55:52 JST Steve Bellovin Steve Bellovin
    • Lauren Weinstein
    • Rich Felker
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @dalias @lauren @huitema @lauerhahn @nikatjef Precisely. They're the legacy payment system; no one would invent anything like it today, but per the CNN article itself checks go back ~2400 years and in substantially modern form about 500 years.
    Fraud? Theft? Absolutely. True story: my father was a certified public accountant, and several decades ago he tried explaining to one of his clients that no, banks did not routinely verify signatures on checks. They made a bet: the client wrote a check to my father and signed it Mickey Mouse or some such, with the understanding that if my father could cash it the money was his. Guess who won the bet? (I think I heard this story from him in the 1970s.)
    Yes, we need a solution for the poor, the rural, the folks who can't cognitively handle something different than what they grew up with, etc. And no, I do not advocate a flash-cut to something other than checks. (I know of some very large, sophisticated institutions that are just starting to accept EFT payments, because their own internal systems are still legacy-based.) But we're dealing with theft of checks, forgeries, late or missed deliveries by the Postal Service, ridiculous floats by banks, and the environmental costs of moving around and handling all of that paper.
    Do I know the answer? No. But as folks used to say back during the anti-Vietnam War protests, you don't have to be a cobbler to know that the shoe doesn't fit.

    In conversation about 2 months ago from infosec.exchange permalink
  9. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 23-Nov-2025 06:06:05 JST Steve Bellovin Steve Bellovin

    The Trump regime wants to start making a list of Jews (https://www.nytimes.com/2025/11/21/us/eeoc-university-pennsylvania-antisemitism-jewish.html). Now where have I heard that one before?

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  10. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 14-Nov-2025 02:49:13 JST Steve Bellovin Steve Bellovin

    Just got an email from Medicare warning me of scams during Open Enrollment season. Naturally, the email has embedded URLs to click—and the links don't point to medicare.gov, they point to a .com that will forward the HTTPS request. (The email was also sent by that .com, but at least there's a valid DKIM signature.)

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.medicare.gov
      Welcome to Medicare
      The official U.S. government website for Medicare, a health insurance program for people age 65 or older and younger people with disabilities.
  11. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 08-Nov-2025 06:56:18 JST Steve Bellovin Steve Bellovin

    A more subtle way that the Trump regime is going to kill people.
    https://flipboard.com/@npr/health-930k6cv1z/-/a-beDov0XYRSOWB869HhFprQ%3Aa%3A3195441-%2F0

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ic-cdn.flipboard.com
      Why next year's flu shot might not be as good as it should be | Flipboard
      NPR - In a typical year, several thousand samples from flu patients around the world arrive at the U.S. Centers for Disease Control and Prevention. They're crucial for understanding the virus's evolution and help form the bedrock of the World Health Organization's effort to design the next annual flu …
  12. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 21-Oct-2025 04:55:44 JST Steve Bellovin Steve Bellovin
    in reply to
    • Matt Blaze

    @mattblaze N-version programming, where N=1

    In conversation about 3 months ago from infosec.exchange permalink
  13. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 19-Oct-2025 09:25:35 JST Steve Bellovin Steve Bellovin

    Best sign I’ve seen thus far: “United we ribbet. Divided we croak.”

    In conversation about 3 months ago from infosec.exchange permalink
  14. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 18-Oct-2025 23:14:43 JST Steve Bellovin Steve Bellovin

    For the next No King demonstration, I’m going to wear a tricorn hat.

    In conversation about 3 months ago from infosec.exchange permalink
  15. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 12-Oct-2025 02:03:21 JST Steve Bellovin Steve Bellovin

    Part of an art installation outside Waterloo Station in London.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/332/186/914/203/430/original/a822506b8defa30e.jpeg
  16. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 15-Sep-2025 12:38:15 JST Steve Bellovin Steve Bellovin
    in reply to
    • Adam Shostack :donor: :rebelverified:

    @adamshostack The op-ed isn't just calling for no payment for publishing, it's calling for no journals at all, because if you just abolish publication charges, the journal owners will simply charge more for subscriptions, and she doesn't want that, either. Note these near the end: "At Arcadia Science, a biotechnology company, we publish everything immediately, openly. Real peer review happens in public, where any expert can contribute. Our work gets tested, challenged, and built on in real time" and "Alternatives exist: preprint servers, public peer review, data repositories. Redirect the millions from publishers to these systems."
    I've long complained about today's peer review (see, e.g., https://www.cs.columbia.edu/~smb/papers/04336288.pdf, near the end). But I'm not clear on what the alternative is—major papers might get reviewed, but most won't, and readers have no way to judge the merits of reviews that are done. Are they honest or corrupt? Properly reviewing papers is *hard*, and there are so many papers written that it's impossible to keep up with all of the ones that aren't obviously of great significance if correct. You were at Usenix Security last month, which had 490 members on the program committee. (By contract, my first program committee, in 1984, was *4*, plus two co-chairs…) Even so, you often get unqualified reviewers. (I just got back reviews for a paper where all of the reviewers indicated "some familiarity" with the subject—none of them are experts, but they control if this paper will appear in that venue.)
    In a sense, it's the same as the open source problem: you need many eyes, but they have to be competent and motivated. Today's peer review solves the motivation problem, but not always the competence problem. I won't even go into the problem of making sure that links survive when some volunteer gets tired of running an archive.
    This is a hard problem and I don't pretend to know the answer. But let's be clear on that that op-ed is really saying.

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


  17. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 08-Aug-2025 00:19:01 JST Steve Bellovin Steve Bellovin

    This quote from the article has gotten far too little attention: "The second person said that roughly a dozen court dockets were tampered with in one court district as a result of the hack. The first person was not aware of any tampering but said it was theoretically possible."
    https://mastodon.laurenweinstein.org/@lauren/114987795151116380

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: mastodon.laurenweinstein.org
      Lauren Weinstein (@lauren@mastodon.laurenweinstein.org)
      from Lauren Weinstein
      Attached: 1 image BREAKING: Massive hack against federal court filing system exposing confidential information https://www.politico.com/news/2025/08/06/federal-court-filing-system-pacer-hack-00496916
  18. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 27-Jul-2025 05:58:47 JST Steve Bellovin Steve Bellovin

    Where are we going, and why are we in this handbasket?

    In conversation about 6 months ago from infosec.exchange permalink
  19. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 26-Jul-2025 13:46:03 JST Steve Bellovin Steve Bellovin
    in reply to
    • Cory Doctorow
    • Jack Daniel (often offline)
    • Angus McIntyre

    @angusm @jack_daniel @pluralistic Yup. (Years ago, I was at a NANOG (North American Network Operators Group) meeting where a nearby street had a line of backhoes parked. I think it was a warning.)

    In conversation about 6 months ago from infosec.exchange permalink
  20. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 04-Jul-2025 20:12:58 JST Steve Bellovin Steve Bellovin

    I swear, as I was scrolling I thought this was an Onion headline.
    https://flipboard.com/@newyorktimes/science-jpuunj5gz/-/a-KhzVHy5QRYm-yk515emFNQ%3Aa%3A3195393-%2F0

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ic-cdn.flipboard.com
      E.P.A. Employees Are Invited to Adopt Soon-to-Be Homeless Lab Rats | Flipboard
      The New York Times - The agency is cutting animal testing of chemicals. Some scientists are concerned, but in the meantime the rats (and zebra fish) need new homes. Employees at the Environmental Protection Agency’s research campus in North Carolina are preparing to take on a new responsibility. Bring home lab rats as …
  • Before

User actions

    Steve Bellovin

    Steve Bellovin

    I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          297340
          Member since
          17 Nov 2024
          Notices
          53
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.