GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Steve Bellovin (stevebellovin@infosec.exchange)

  1. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 05-May-2026 06:15:12 JST Steve Bellovin Steve Bellovin

    Pro tip: be very careful about how you put an Apple Watch charger into a hotel safe. It's magnetic and can stick to mechanisms, jamming the safe so it won't open properly. No need to ask me how I learned this… (Yes, next time I'll disconnect the charger from the rats' nest of stuff I'm shoving into the safe.)

    In conversation about 13 hours ago from infosec.exchange permalink
  2. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 03-May-2026 09:43:59 JST Steve Bellovin Steve Bellovin
    in reply to
    • Matt Blaze
    • Xenotar

    @xenotar @mattblaze 17.5 kg isn't lightweight…

    In conversation about 2 days ago from infosec.exchange permalink
  3. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 03-May-2026 09:21:54 JST Steve Bellovin Steve Bellovin
    • Matt Blaze

    Hey, @mattblaze, did you see https://mastodon.nz/@joncounts/116507624340205226 ?

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Jon Sullivan (@joncounts@mastodon.nz)
      from Jon Sullivan
      That’s not a telephoto lens. *That’s* a telephoto lens: https://www.jogeier.com/blog/review-nikon-refelx-2000mm-f11/ #photography
  4. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 01-May-2026 11:33:32 JST Steve Bellovin Steve Bellovin

    New book, released under a Creative Commons BY-NC-ND license: "Don't Get Hacked! Protecting Yourself at Home": https://www.cs.columbia.edu/~smb/homesec/index.html

    Retoot for reach!

    #cybersecurity #homeCybersecurity #dontGetHacked

    In conversation about 4 days ago from infosec.exchange permalink

    Attachments


  5. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 27-Mar-2026 01:46:36 JST Steve Bellovin Steve Bellovin
    in reply to
    • Paul Cantrell

    @inthehands I hate grading and everything that goes with it, e.g., exams. (Aside: in Spring 2020, when we went fully remote under emergency circumstances and all classes were pass/fail, I tried to cancel the final by announcing that at that point, everyone in the class was passing and I was happy to stick with that. A fair number of students insisted on a final exam… I was *extremely* liberal with exemption requests.) And I categorically refused to use any of these remote proctoring solutions, for many different reasons.

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 27-Mar-2026 01:16:55 JST Steve Bellovin Steve Bellovin
    in reply to
    • Paul Cantrell

    @inthehands Reasonable approach! Once I document my script, I'll open-source it and let others add that enhancement…
    As for grade-recording: I first started teaching back when I was a grad student. Very early on, a student complained to me about her grade and showed me that I'd recorded it incorrectly. This horrified me, so I immediately wrote a grade-recording and calculation system (in APL…), and used it to create tear-sheets to hand to each student with their grades, there being no online way to send them in those days.

    In conversation about a month ago from infosec.exchange permalink
  7. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 27-Mar-2026 01:09:59 JST Steve Bellovin Steve Bellovin
    in reply to
    • Paul Cantrell

    @inthehands Let me know what your second-best choice is — I need to document my version (see https://www.cs.columbia.edu/~smb/classes/f23/lectures.html for sample output) and post it somewhere, and I haven't even thought about a name. I've always posted my course material online and freely available, which is one reason I don't lock it up inside Canvas, but I despise Canvas about as much as you despise Moodle. (I've used Canvas only for grade recording—I didn't want to deal with the privacy issues of managing students' access to their own grades, plus the integration with the university's final grade system—and for the in-class chat room, since like you I prefer static web sites.)
    Aside: my version started as a simple Python script to generate the list of dates for my lectures in any given semester, and it grew…

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      COMS E6184, LAW L7777-001: Anonymity and Privacy
  8. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 24-Mar-2026 23:46:58 JST Steve Bellovin Steve Bellovin

    I've been thinking about the FCC's insane new ban on foreign-made routers. Note the end of the BBC story at https://www.bbc.com/news/articles/c74787w149zo:
    "One exception to the general absence of US-made routers is the newer Starlink WiFi router. Starlink is part of Elon Musk's company SpaceX.

    "The company says the Starlink routers are made in Texas."

    And per the FCC's FAQ (https://www.fcc.gov/faqs-recent-updates-fcc-covered-list-regarding-routers-produced-foreign-countries), even US-written software (or, I assume, open source software like OpenWRT) won't exempt foreign-made routers from the ban.

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
      US bans new foreign-made consumer internet routers
      There are almost no major brands of internet routers that are manufactured in the US.

  9. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 10-Mar-2026 05:13:03 JST Steve Bellovin Steve Bellovin

    Here we go again: the FBI seizes 2020 (and maybe 2024!) voting records from Arizona: https://www.nytimes.com/2026/03/09/nyregion/fbi-subpoena-arizona-maricopa-county-election.html

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  10. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 03-Mar-2026 10:40:45 JST Steve Bellovin Steve Bellovin

    Not sure who needs to see this, but…

    From the Wikipedia page on the Nuremberg trials: "The International Military Tribunal agreed with the prosecution that aggression was the gravest charge, stating in its judgment that because "war is essentially an evil thing", "to initiate a war of aggression, therefore, is not only an international crime; it is the supreme international crime differing only from other war crimes in that it contains within itself the accumulated evil of the whole".

    From the Wikipedia page on Hideki Tojo: he was "found guilty of, among other actions, waging wars of aggression; war in violation of international law; unprovoked or aggressive war against various nations; and ordering, authorizing, and permitting inhumane treatment of prisoners of war".

    Is this at all relevant today?

    In conversation about 2 months ago from infosec.exchange permalink
  11. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 19-Feb-2026 06:05:48 JST Steve Bellovin Steve Bellovin

    I said it during his first term, and I'll repeat it now: what Trump really wants is to be able to prosecute people for lèse-majesté: https://bsky.app/profile/did:plc:fa3rwygrp2ebgwdiq6sjn2te/post/3mf5xgsebzk24

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.bsky.app
      Jennifer Ouellette (@jenlucpiquant.bsky.social)
      from Jennifer Ouellette (@jenlucpiquant.bsky.social)
      Economists contradicted Trump on tariffs. A White House adviser wants them 'disciplined' https://qz.com/ny-fed-trump-advisor-fed-research-discipline
  12. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 13-Feb-2026 23:44:37 JST Steve Bellovin Steve Bellovin

    Two stories, side by side, in the NY Times Technology section.

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/063/826/969/852/626/original/4b380f8365beb143.png
  13. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Wednesday, 07-Jan-2026 06:37:31 JST Steve Bellovin Steve Bellovin

    RE: https://flipboard.social/@newsguyusa/115850233260885949

    Denmark says that if the US attacks Greenland, it will be the end of NATO. Of course, to Trump, that's a feature. Better yet, to him, his BFF Vladimir would love it.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Steve Herman (@newsguyusa@flipboard.social)
      from Steve Herman
      President Trump is considering using military force to acquire Greenland, White House press secretary Karoline Leavitt tells CNBC. https://www.cnbc.com/2026/01/06/trump-greenland-military-white-house.html
  14. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 04-Jan-2026 04:30:39 JST Steve Bellovin Steve Bellovin

    Does Article 5 of the NATO treaty apply to insider attacks? Asking for a territory of Denmark's.

    In conversation about 4 months ago from infosec.exchange permalink
  15. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 29-Dec-2025 06:07:49 JST Steve Bellovin Steve Bellovin

    For the record, I hate git.

    In conversation about 4 months ago from infosec.exchange permalink
  16. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 20-Dec-2025 11:18:23 JST Steve Bellovin Steve Bellovin
    in reply to
    • Matt Blaze

    @mattblaze And take care of your students, both your advisees and classroom students. I've heard some truly horrific stories to accompany requests for short extensions on something. My response is always the same: take care of yourself, don't worry about the deadline, I'll do everything I can to support you if you have to appeal to the dean's office for an exception, and TAKE CARE OF YOURSELF—that's far more important than an arbitrary academic deadline. On more than one occasion, a student has asked for a one week extension due to a family tragedy that I knew was going to require them to get an Incomplete while they processed what happened and grieved—and I made sure that the dean's office knew how strongly I supported the request. People are important. Family is important. Close friends are important. Academic work? Much less so—and apart from anything else, you can't possibly do good academic work when your head and your heart are elsewhere.
    I can't make their pain go away. I can make sure I don't add to it.

    In conversation about 5 months ago from infosec.exchange permalink
  17. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 11-Dec-2025 01:30:37 JST Steve Bellovin Steve Bellovin

    So this is insane even by his Orangeness Administration's standards. DoJ successfully extradited a Belarusian woman to prosecute her for smuggling aviation components into Russia. She's eligible to be released to home detention pending trial—but if she is, DHS wants to deport her for being in the US illegally.
    https://www.washingtonpost.com/dc-md-va/2025/12/10/extradition-deportation-belarus-russia/

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


  18. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 11:56:24 JST Steve Bellovin Steve Bellovin
    in reply to
    • Lauren Weinstein
    • Rich Felker
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @lauren @dalias @huitema @lauerhahn @nikatjef Well, if we don't try we're certainly not going to find an answer. And again, unlike the GOP and Obamacare, I'm not saying "abolish it now while we think of something" (and remember that the part of Obamacare they objected to most, mandatory coverage, was essential to the financials of the scheme, which is why they could never find a replacement).
    There is a problem: checks are expensive, environmentally awful, insecure, and subject to all sorts of crimes. What are we going to do about it? DON'T flash-cut, don't announce a short-term deadline, but let's start seriously thinking about this as a systems problem. (Aside: many years ago, I saw an article, I think in CACM, discussing the costs of EFT versus checks. The problem was that no one knew what it cost banks to handle checks—the accounting systems were not set up to capture that kind of data; they broke down costs differently.)

    In conversation about 5 months ago from infosec.exchange permalink
  19. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 11:04:29 JST Steve Bellovin Steve Bellovin
    in reply to
    • Lauren Weinstein
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @huitema @lauerhahn @lauren @nikatjef In the UK, at least, checks are apparently all but extinct—everything seems to be done by EFT (or so I've been told by an American who lived there for about 10 years).

    In conversation about 5 months ago from infosec.exchange permalink
  20. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 07-Dec-2025 10:55:52 JST Steve Bellovin Steve Bellovin
    • Lauren Weinstein
    • Rich Felker
    • James Wells
    • Louise Auerhahn 🏳️‍🌈
    • Christian Huitema

    @dalias @lauren @huitema @lauerhahn @nikatjef Precisely. They're the legacy payment system; no one would invent anything like it today, but per the CNN article itself checks go back ~2400 years and in substantially modern form about 500 years.
    Fraud? Theft? Absolutely. True story: my father was a certified public accountant, and several decades ago he tried explaining to one of his clients that no, banks did not routinely verify signatures on checks. They made a bet: the client wrote a check to my father and signed it Mickey Mouse or some such, with the understanding that if my father could cash it the money was his. Guess who won the bet? (I think I heard this story from him in the 1970s.)
    Yes, we need a solution for the poor, the rural, the folks who can't cognitively handle something different than what they grew up with, etc. And no, I do not advocate a flash-cut to something other than checks. (I know of some very large, sophisticated institutions that are just starting to accept EFT payments, because their own internal systems are still legacy-based.) But we're dealing with theft of checks, forgeries, late or missed deliveries by the Postal Service, ridiculous floats by banks, and the environmental costs of moving around and handling all of that paper.
    Do I know the answer? No. But as folks used to say back during the anti-Vietnam War protests, you don't have to be a cobbler to know that the shoe doesn't fit.

    In conversation about 5 months ago from infosec.exchange permalink
  • Before

User actions

    Steve Bellovin

    Steve Bellovin

    I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          297340
          Member since
          17 Nov 2024
          Notices
          65
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.