GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Dan Goodin (dangoodin@infosec.exchange)

  1. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 08:16:18 JST Dan Goodin Dan Goodin
    in reply to

    Here's another reminder that it's best to resist as much as possible the siren's call of relying on AI and other services from Big Tech. Gemini is blocking questions about Trump showing signs of dementia even as it answers the same question when applied to Biden. When we turn to AI we are abdicating our own judgement and research responsibilities to a broligarchy that bends to the whims of billionaires.

    https://www.theverge.com/news/789152/google-ai-searches-blocking-trump-dementia-biden

    In conversation about 3 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/300/061/864/400/127/original/e4f45a53e42d7c4d.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/300/072/991/347/661/original/66812af424a32782.png
  2. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 08:16:17 JST Dan Goodin Dan Goodin
    in reply to

    Now that Marc Benioff, owner of Slack and Salesforce, has confirmed he sides with authoritarianism, it's more incumbent on us than ever to move off central platforms, which can dump communications we presumed were private or cut us off for any reason or no reason at all.

    https://sfstandard.com/2025/10/10/marc-benioff-national-guard-sf/

    In conversation about 3 days ago from infosec.exchange permalink
  3. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 02:07:44 JST Dan Goodin Dan Goodin

    The complexity and problem-solving required for making the Signal Protocol quantum safe are as daunting as any in modern-day engineering. In less adept hands, mucking about with an instrument as complex as the Signal protocol could have led to shortcuts or unintended consequences. Yet this latest post-quantum upgrade is nothing short of a triumph.

    https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineering-achievement/

    In conversation about 3 days ago from infosec.exchange permalink
  4. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 01-Oct-2025 08:49:03 JST Dan Goodin Dan Goodin

    After 25 years, I still struggle to find an intuitive way to describe computer "state" to non-techies. Such a simple thing and yet I still don't know how to give it a simple description/definition.

    In conversation about 16 days ago from infosec.exchange permalink
  5. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 18-Sep-2025 04:09:15 JST Dan Goodin Dan Goodin

    Can you imagine the huge bonanza espionage and ransomware threat actors are going to have when every service you use forces you to provide them with your ID? This is a disaster that 100% will happen. I can hardly wait.

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 12-Sep-2025 03:26:40 JST Dan Goodin Dan Goodin

    So many people jumping to confirmation-biased conclusions with each new assassination detail. Will y'all please stop?

    In conversation about a month ago from infosec.exchange permalink
  7. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 11-Sep-2025 05:05:56 JST Dan Goodin Dan Goodin

    A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default. Senator Ron Wyden went on to liken Microsoft to an "arsonist selling firefighting services to their victims.”

    https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/

    In conversation about a month ago from infosec.exchange permalink
  8. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 04-Sep-2025 04:56:20 JST Dan Goodin Dan Goodin
    in reply to
    • Rich Felker

    @dalias

    Sorry about that. Already fixed by the time you called it out.

    In conversation about a month ago from infosec.exchange permalink
  9. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 04-Sep-2025 03:53:15 JST Dan Goodin Dan Goodin

    People in Internet security circles are sounding the alarm over the issuance of three TLS certificates for 1.1.1.1, a widely used DNS service from Cloudflare. The three improperly issued certs escaped notice for 4 months.

    https://arstechnica.com/security/2025/09/mis-issued-certificates-for-1-1-1-1-dns-service-pose-a-threat-to-the-internet/

    In conversation about a month ago from infosec.exchange permalink
  10. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 03-Sep-2025 02:40:55 JST Dan Goodin Dan Goodin

    We hear several times a year about zero-click vulnerabilities being actively exploited in WhatsApp. I don't remember a single such incident affecting Signal. Why is that? Is the Signal userbase too small? Is the app more secure? Something else?

    https://www.whatsapp.com/security/advisories/2025/

    In conversation about a month ago from infosec.exchange permalink
  11. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Sunday, 31-Aug-2025 17:08:09 JST Dan Goodin Dan Goodin

    After more than a decade of receiving these sorts of messages, I still never know how to respond in a way that might be remotely helpful.

    UPDATE it's really disappointing to see how many responses here dismiss or make fun of people with mental illness. These are real people with real families and they're all suffering. There's nothing funny about any of this.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/119/156/406/510/317/original/ea591c6966351648.png
  12. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 08-Aug-2025 02:56:42 JST Dan Goodin Dan Goodin

    A reminder that software makers, hardware makers, cloud services, payment processors, and the like will throw their customers under the bus whenever it suits them. Your payment card, food delivery account, AWS instance, Gmail address -- all can be taken away on a whim for any reason or no reason. These providers are NOT your friend. Make plans now. Have backups in place. Practice self-reliance. Ween yourself off these one at a time.

    In conversation about 2 months ago from infosec.exchange permalink
  13. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 07-Aug-2025 07:05:37 JST Dan Goodin Dan Goodin
    • AI6YR Ben

    @pixelpusher220 @ai6yr

    I haven't been to a HD or Lowes in years. In SF, we have Discount Home Builders Supply & Hardware, a locally-owned place that's been in business for decades. The workers there monitor the isles and actively ask if you need/want help. All cities should be so lucky.

    https://www.discountbuilderssupplysf.com

    In conversation about 2 months ago from infosec.exchange permalink
  14. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 05-Aug-2025 05:12:50 JST Dan Goodin Dan Goodin
    • Marcus Hutchins :verified:

    Once again, @malwaretech nails it, this time calling out the "gluttony of myopic visionaries" shilling the wonders of AI.

    https://malwaretech.com/2025/08/every-reason-why-i-hate-ai.html

    In conversation about 2 months ago from infosec.exchange permalink
  15. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 05-Aug-2025 05:12:49 JST Dan Goodin Dan Goodin
    in reply to
    • Marcus Hutchins :verified:

    @malwaretech

    "In reality, all we’ve created is a bot which is almost perfect at mimicking human-like natural language use, and the rest is people just projecting other human qualities on to it. Quite simply, “LLMs are doing reasoning” is the “look, my dog is smiling” of technology. In exactly the same way that dogs don’t convey their emotions via human-like facial expressions, there’s no reason to believe that even if computer could think, it’d perfectly mirror what looks like human reasoning."

    In conversation about 2 months ago from infosec.exchange permalink
  16. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 17-Jul-2025 03:43:16 JST Dan Goodin Dan Goodin

    Am I the only one who can't bring themselves to delete contacts who are no longer living?

    In conversation about 3 months ago from infosec.exchange permalink
  17. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 08-Jul-2025 03:11:25 JST Dan Goodin Dan Goodin

    I'm all for moving off of centralized platforms controlled by broligarchies. That said, how do we know platforms like Proton are any less horrible? Genuine question with no snark intended.

    In conversation about 3 months ago from infosec.exchange permalink
  18. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 04-Jul-2025 01:45:51 JST Dan Goodin Dan Goodin

    Interesting article reporting that Android will soon give Gemini broadened access to phones and the apps they run, even when Gemini has not been turned on. Article gos on to say people who don't want this should "open the Gemini app from your Android device" and turn off each app extension. Sounds simple enough, but I'm not finding any Gemini app installed on my pixel. Can anyone help me figure out what precisely people must do too keep Gemini off of their android devices?

    https://tuta.com/blog/how-to-disable-gemini-on-android#_

    In conversation about 3 months ago from infosec.exchange permalink
  19. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 24-Jun-2025 02:53:38 JST Dan Goodin Dan Goodin

    Is it possible to opt out of all Substack invitations like this one? I'm so tired of having to unsubscribe from them one by one. It's 2025. Does Substack really require me to opt out each time someone subscribes me to a list I don't want to be on?

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/733/559/504/625/289/original/7a68061583d34194.png
  20. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 24-Jun-2025 02:53:37 JST Dan Goodin Dan Goodin
    in reply to
    • Brad Rubenstein “:verified:” [OLD ACCOUNT]

    @BradRubenstein

    I don't think I have a substack account. I really don't want one. I just want Substack to leave me alone.

    In conversation about 4 months ago from infosec.exchange permalink
  • Before

User actions

    Dan Goodin

    Dan Goodin

    Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          92418
          Member since
          27 Jan 2023
          Notices
          149
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.