GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Steve Bellovin (stevebellovin@infosec.exchange)

  1. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 12-May-2025 01:58:20 JST Steve Bellovin Steve Bellovin

    Getting increasingly more concerned about my flight from EWR in a couple of weeks …
    https://mstdn.social/@GottaLaff/114489610461646639

    In conversation about 5 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Laffy (@GottaLaff@mstdn.social)
      from Laffy
      😳 “Another air traffic control equipment outage caused the FAA to implement a ground stop for Newark Liberty International Airport bound flights Sunday morning.” https://www.cnn.com/2025/05/11/us/another-equipment-outage-impacts-newark-airport?cid=ios_app
  2. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 06-May-2025 15:42:33 JST Steve Bellovin Steve Bellovin
    in reply to
    • holga
    • Poul-Henning Kamp

    @hpk @bsdphk Absolutely correct. My phrasing, to my students, is "what are you trying to protect, and against whom?"

    In conversation about 11 days ago from infosec.exchange permalink
  3. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 28-Apr-2025 22:47:31 JST Steve Bellovin Steve Bellovin
    in reply to
    • Lesley Carhart :unverified:

    @hacks4pancakes Yup. Some years ago, after a cascading failure blacked out a good chunk of the US, several people asked me if "hackers" had done it. My response was that power grid dynamics were so complex that there was no way attackers could predict what would happen. Sure enough, the eventual investigation showed that a series of improbable events had coincided; that plus the cascade effect did it. To quote myself, "complex systems fail in complex ways".

    In conversation about 18 days ago from infosec.exchange permalink
  4. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 24-Apr-2025 13:59:55 JST Steve Bellovin Steve Bellovin

    From the article: ‘Nara Milanich, a Barnard history professor, said it reminded her of her research into 1930s Italy, when lists of Jews were put together by the local government. “We’ve seen this movie before, and it ends with yellow stars,” she said.’

    https://www.nytimes.com/2025/04/23/nyregion/barnard-faculty-eeoc-text-jewish.html

    In conversation about 23 days ago from infosec.exchange permalink
  5. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 10-Apr-2025 01:29:26 JST Steve Bellovin Steve Bellovin
    in reply to
    • Paul Cantrell

    @inthehands Sorry—that's slide 27 of https://www.cs.columbia.edu/~smb/classes/f23/l_ml.pdf

    In conversation about a month ago from infosec.exchange permalink

    Attachments


  6. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 10-Apr-2025 01:25:58 JST Steve Bellovin Steve Bellovin
    in reply to
    • Paul Cantrell

    @inthehands Yes. See slides 21-25 of https://www.cs.columbia.edu/~smb/classes/f23/l_intro.pdf

    In conversation about a month ago from infosec.exchange permalink

    Attachments


  7. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 10-Apr-2025 01:11:52 JST Steve Bellovin Steve Bellovin

    Worth noting: combining different databases is generally regarded as the single most dangerous thing to do from a privacy perspective. Here's what Paul Ohm wrote a few years ago (https://hbr.org/2012/08/dont-build-a-database-of-ruin):

    In my work, I’ve argued that these databases will grow to connect every individual to at least one closely guarded secret. This might be a secret about a medical condition, family history, or personal preference. It is a secret that, if revealed, would cause more than embarrassment or shame; it would lead to serious, concrete, devastating harm. And these companies are combining their data stores, which will give rise to a single, massive database. I call this the Database of Ruin.
    https://flipboard.com/@newyorktimes/the-upshot-imovb8bqz/-/a-pvsZrW8uTLKxDaAmALYvXw%3Aa%3A3195393-%2F0

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: ic-cdn.flipboard.com
      Trump Wants to Merge Government Data. Here Are 314 Things It Might Know About You. | Flipboard
      The New York Times - Elon Musk’s team is leading an effort to link government databases, to the alarm of privacy and security experts. The federal government knows your mother’s maiden name and your bank account number. The student debt you hold. Your disability status. The company that employs you and the wages you …
  8. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Tuesday, 08-Apr-2025 09:29:42 JST Steve Bellovin Steve Bellovin
    in reply to
    • Adam Shostack :donor: :rebelverified:

    @adamshostack Like so much else in the US constitution, there is a provision specifically aimed at that abuse. In particular, the Sixth Amendment starts "In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the State and district wherein the crime shall have been committed, which district shall have been previously ascertained by law."

    In conversation about a month ago from infosec.exchange permalink
  9. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 06-Apr-2025 10:56:26 JST Steve Bellovin Steve Bellovin

    I was at the midtown Manhattan demonstration today. I don't know how large the crowd was, but it was large. It did skew older—my partner and I were not the only ones who were veterans of the anti-Vietnam War protests decades ago. But youth was well-represented, too, including a store employee who climbed into the store window to show a large “FUCK TRUMP” on her phone. There were very few preprinted signs, which made for a lot of creative homemade signs. They ran the gamut of issues, and of course there are many. (My favorite sign: “IKEA HAS A BETTER CABINET”.) Naturally, although Trump was the primary target, Musk came in for a lot, too: “F-ELON”, “YOU CAN’T SPELL FELON WITHOUT ELON”, “DEPORT MUSK, LOCK UP TRUMP”, and more.
    Will Trump pay attention? No, of course not. But apart from the importance of showing up and being counted, I hope that members of Congress will see the anger. They've already learned that open town halls are a bad idea, and last Tuesday's election results had to be scary for the GOP.
    (Photos? No, out of respect for the privacy of other demonstrators.)

    In conversation about a month ago from infosec.exchange permalink
  10. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Friday, 04-Apr-2025 11:15:27 JST Steve Bellovin Steve Bellovin
    in reply to
    • Ars Technica

    @arstechnica There's another problem here. If the encryption is being done client-side by *any* browser, it's being done by JavaScript—and who knows what the JavaScript is doing? I call this the trust-binding problem. When you download software or an update to it, you're making your decision to trust the vendor at that point. With JavaScript encryption and decryption, you're making that decision every time you load the page. This is a very different concept, and one that isn't make clear to users. (In theory, there could be browser extensions to do the encryption and decryption, but that's not easy for users, and there are many different browsers out there, with very different policies on extensions.)

    In conversation about a month ago from infosec.exchange permalink
  11. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 03-Apr-2025 23:10:51 JST Steve Bellovin Steve Bellovin

    What new device did this elevator discover? Is there another car in the shaft?

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/274/180/993/971/633/original/485fa9ae7cdfc84a.jpeg
  12. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Thursday, 03-Apr-2025 13:25:10 JST Steve Bellovin Steve Bellovin
    • Matt Blaze
    • nomad :verified_pride:
    • Kim Scheinberg
    • Live, Laugh, Punch Nazis
    • Kat O’Brien

    @nomad @mattblaze @20002ist @kims @obrien_kat Some of them don't seem to believe that they’ll die: https://www.vanityfair.com/news/2016/08/peter-thiel-wants-to-inject-himself-with-young-peoples-blood?srsltid=AfmBOooG7anMeF5BrlAkDh7gJM3yDCJEH5Fxe2xA5wtLKujGIXZUaJJP

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.vanityfair.com
      Peter Thiel Wants to Inject Himself With Young People’s Blood
      from Maya Kosoff
      The Silicon Valley billionaire reportedly sees blood transfusions as the pathway to radical life extension.
  13. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 30-Mar-2025 04:51:35 JST Steve Bellovin Steve Bellovin
    • Live, Laugh, Punch Nazis

    @thetnholler.bsky.social @20002ist When you look at the population of Greenland, it's clear that if the US did own it, it would be a "territory" where the people have fewer rights to self-government, no ability to vote for president, etc.

    In conversation about 2 months ago from infosec.exchange permalink
  14. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 22-Mar-2025 07:00:54 JST Steve Bellovin Steve Bellovin

    The official statement from Columbia is at https://president.columbia.edu/content/fulfilling-our-commitments. The link to that was in an email so bland and uninformative that I ignored the links (one of which doesn't work anyway).

    My undergrad degree is from Columbia, and I'm a faculty member for a few more months, though no longer teaching. I intend to continue wearing my mask, since I wear it for health reasons and not “for the purpose of concealing one’s identity in the commission of violations of University policies or state, municipal or federal laws.” After all, it's for health reasons, which is explicitly permitted by policy. My next step: an email to my chair and the dean. I have two thesis defenses coming up this semester; other than those, I don't need to be inside any campus buildings, and I'll run the defenses over Zoom if I have to.
    https://flipboard.com/@newyorktimes/new-york-bat3un55z/-/a-0zIWJwAfQXmPJsJLILatFg%3Aa%3A3195393-%2F0

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: ic-cdn.flipboard.com
      Columbia Makes Concessions to Trump Amid Bid to Reclaim Federal Funds | Flipboard
      The New York Times - Columbia University agreed on Friday to overhaul its protest policies, security practices and Middle Eastern studies department in a remarkable concession to the Trump administration, which has refused to consider restoring $400 million in federal funds without major changes. The agreement, detailed …
  15. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 02-Mar-2025 08:40:34 JST Steve Bellovin Steve Bellovin
    in reply to
    • Adam Shostack :donor: :rebelverified:

    @adamshostack One reason I use slides for almost all of my class lectures is your #2: there are many such students, especially in our graduate programs. I also make the slides available to the students (and everyone else in the world…), ever since I saw non-English speakers at IETF meetings taking pictures of the screen.

    In conversation about 3 months ago from infosec.exchange permalink
  16. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Sunday, 02-Mar-2025 07:15:54 JST Steve Bellovin Steve Bellovin

    Costa Rica doesn't have an army, but it does have a strategic feline reserve.
    #Caturday

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/089/465/371/292/774/original/5624777e242e891e.jpeg
  17. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Wednesday, 19-Feb-2025 08:02:05 JST Steve Bellovin Steve Bellovin

    Starting to wonder when the Reichstag—sorry, I mean Capitol—fire will be.
    https://journa.host/@w7voa/114027235487063134

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Steve Herman (@w7voa@journa.host)
      from Steve Herman
      The director of presidential libraries (from White House/ DOGE) instructed the JFK library to fire probationary staff effective immediately and until further notice, according to Jack Schlossberg, grandson of the former president. https://www.instagram.com/p/DGOpB_Jyvmb/
  18. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 10-Feb-2025 22:22:26 JST Steve Bellovin Steve Bellovin

    To paraphrase and merge two Churchill speeches, we shall go on to the end, we shall fight in America, we shall fight on the streets and parks, we shall fight with growing confidence and growing strength on the Internet, we shall defend our democracy, whatever the cost may be, we shall fight in the courtrooms, we shall fight in the Congress, we shall fight in the voting booth, we shall fight in the hills; we shall never surrender. But if we fail, then the whole world, including the United States, including all that we have known and cared for, will sink into the abyss of a new Dark Age made more sinister, and perhaps more protracted, by the lights of perverted science. Let us therefore brace ourselves to our duties, and so bear ourselves that, if the United States lasts for a thousand years, people will still say, "This was their finest hour."

    In conversation about 3 months ago from infosec.exchange permalink
  19. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Saturday, 01-Feb-2025 04:35:47 JST Steve Bellovin Steve Bellovin

    Waiting for the Orange Chaos Monkey to ban smartphones because the original ARM chip they run on was co-designed by a trans woman, Sophie Wilson.

    In conversation about 4 months ago from infosec.exchange permalink
  20. Embed this notice
    Steve Bellovin (stevebellovin@infosec.exchange)'s status on Monday, 27-Jan-2025 02:21:36 JST Steve Bellovin Steve Bellovin

    Read https://www.nytimes.com/2025/01/18/opinion/immigration-trump-ww2-japanese-internment.html for the last time the US government tried—successfully, at least at first—to eliminate birthright citizenship.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: static01.nyt.com
      Opinion | A Racist Purge Almost Destroyed My Family. Another One Is Coming.
      from By Timothy Soseki Kudo
      If Trump issues his own order on Day 1, as he’s vowed, the first people could enter detention camps by February.
  • Before

User actions

    Steve Bellovin

    Steve Bellovin

    I'm a computer science professor and affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          297340
          Member since
          17 Nov 2024
          Notices
          29
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.