GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Dan Goodin (dangoodin@infosec.exchange)

  1. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 05-Jun-2026 09:26:52 JST Dan Goodin Dan Goodin

    If it wasn't already, 2FA spraying is now a thing

    https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 04-Jun-2026 03:02:06 JST Dan Goodin Dan Goodin

    There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults.

    https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343

    What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacker to meaningfully exhaust key space before it resets all over -- unless the attacker has the ability to pump all 7,700 combinations in <90 seconds, and DL doesn't have any sort of rate limiting.

    Also, if the attacker is brute forcing 2fa, doesn't that by necessity mean the attacker already defeated the first factor? How did that occur?

    I don't know if my confusion is the result of me not knowing the how the Dashlane product works or if it's just Dashlane being opaque.

    Can anyone help me read the tea leaves?

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 16-May-2026 00:29:43 JST Dan Goodin Dan Goodin

    Are MP3 players even a thing these days? What are some good brands/models?

    In conversation about 3 months ago from infosec.exchange permalink
  4. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 26-Mar-2026 06:45:34 JST Dan Goodin Dan Goodin

    RE: https://mastodon.cthos.dev/@cthos/116291799262669611

    Wow, the cynicism in this thread is off the charts. Google's aggressive accelleration of its internal PQC deadline has gotten the attention of a bunch of very smart people working in the field. You may think it's propaganda, but lots of us are wondering what Google knows is coming down the pike that the rest of us don't. It'd be an error to let this development go unreported.

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      cthos 🐱 (@cthos@mastodon.cthos.dev)
      from cthos 🐱
      So, two articles from Ars Technica today that are both basically Google propaganda: - We quantized the models with *no performance loss* teehee, LLMs are great - Quantum is here, imminently, prepare now! Like, you're just advertising for "Google is still a growth company, trust us" at this point. Edit: That's a bit overly harsh because they both do call out "this is what Google is saying" but come on, the timing of this is "we're prepping for the next bubble"
  5. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 25-Mar-2026 03:17:06 JST Dan Goodin Dan Goodin

    Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.

    Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately.

    https://news.ycombinator.com/item?id=47501729

    In conversation about 4 months ago from infosec.exchange permalink
  6. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 04-Mar-2026 03:06:52 JST Dan Goodin Dan Goodin

    Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier. This allows anyone with affordable equipment like a low-cost spectrum receiver and a standard off-the-shelf antenna to capture and track them throughout time and space."

    https://www.securityweek.com/researchers-uncover-method-to-track-cars-via-tire-sensors/

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.securityweek.com
      Researchers Uncover Method to Track Cars via Tire Sensors
      from @https://twitter.com/IonutArghire
      Using low-cost receivers deployed along roads, academic researchers tracked drivers and their movement patterns.
  7. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 12-Feb-2026 07:56:24 JST Dan Goodin Dan Goodin

    I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages. Has anyone confirmed that these vulns were indeed high-severity and hadn't been discovered before? Is this development as big a deal as Anthropic says? Any other critiques?

    https://red.anthropic.com/2026/zero-days/

    In conversation about 6 months ago from infosec.exchange permalink
  8. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 06-Feb-2026 18:43:55 JST Dan Goodin Dan Goodin

    Am I the only journalist who would opt to go to jail rather than provide my biometrics to open a device when raided by law enforcement?

    In conversation about 6 months ago from infosec.exchange permalink
  9. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 29-Jan-2026 09:32:44 JST Dan Goodin Dan Goodin
    in reply to
    • Miakoda

    @hellomiakoda

    I take it you've never been a member of a union or non-technologist non-profit org.

    In conversation about 6 months ago from infosec.exchange permalink
  10. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 29-Jan-2026 04:41:35 JST Dan Goodin Dan Goodin
    in reply to

    I appreciate everyone who has taken time to respond. Unfortunately, some of the responses demonstrate how much many of us privacy-minded technologists live in ivory towers and have no idea how hard it is to get the rest of the world to take on the added friction of switching.

    In conversation about 6 months ago from infosec.exchange permalink
  11. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 29-Jan-2026 03:34:44 JST Dan Goodin Dan Goodin

    Even people with the most to lose continue to support and rely heavily on:

    -- Google
    -- Slack
    -- Meta
    -- Microsoft
    -- Apple
    -- Too many others to list

    These orgs cozy up to authoritarianism. They terminate your account for any reason or no reaso at all. They shove AI down your throat.

    And yet, my workplace, union, and so many of the orgs I value and need keep using them and have no plans to ween themselves off. Yes, I realize current dynamics make all of this inevitable.

    So I'm left feeling hopeless and helpless, which is a terrible place to be.

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


  12. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 24-Jan-2026 04:42:08 JST Dan Goodin Dan Goodin

    A techbro desperate for cash is detained for 13 hours after leaving a non-functioning, vibe-coded anti-fraud device in a Swiss hotel lobby during the Davos conf

    https://sfstandard.com/2026/01/22/tech-dude-davos-bomb-lookalike-device/

    In conversation about 6 months ago from infosec.exchange permalink
  13. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 03-Dec-2025 15:59:23 JST Dan Goodin Dan Goodin

    A belated thanks to this brave woman, whose defiance 70 years ago yesterday sparked a movement.

    https://www.youtube.com/watch?v=JKCsZc37esU

    In conversation about 8 months ago from infosec.exchange permalink
  14. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 22-Nov-2025 07:46:10 JST Dan Goodin Dan Goodin

    The International Association of Cryptologic Research has cancelled the results of its annual leadership election after an official lost an encryption key needed to unlock results stored in a "hyper-secure election system."

    https://www.nytimes.com/2025/11/21/world/cryptography-group-lost-election-results.html?unlocked_article_code=1.208._aCi.O706MR3i3l3K&smid=url-share

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments


  15. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 19-Nov-2025 10:13:07 JST Dan Goodin Dan Goodin

    To placate all "war-on-Chrismas" cranks, I'm going to start saying merry x-mas.

    In conversation about 8 months ago from infosec.exchange permalink
  16. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 19-Nov-2025 04:07:56 JST Dan Goodin Dan Goodin
    in reply to
    • Kevin Beaumont

    @GossiTheDog

    Good point!

    In conversation about 8 months ago from gnusocial.jp permalink
  17. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 19-Nov-2025 04:06:14 JST Dan Goodin Dan Goodin
    in reply to

    Microsoft says in the post (see toot above) that the agent isn't enabled by default and that only experienced users should enable it. What are these users to do to prevent the attacks Microsoft is warning of?

    In conversation about 8 months ago from infosec.exchange permalink
  18. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 19-Nov-2025 04:06:14 JST Dan Goodin Dan Goodin

    Thoughts about this Microsoft advisory?

    "Additionally, agentic AI applications introduce novel security risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation."

    https://support.microsoft.com/en-us/windows/experimental-agentic-features-a25ede8a-e4c2-4841-85a8-44839191dfb3

    In conversation about 8 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: support.microsoft.com
      Experimental Agentic Features - Microsoft Support
  19. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 18-Nov-2025 02:54:23 JST Dan Goodin Dan Goodin
    • Infoseepage

    @Infoseepage

    Respect.

    In conversation about 9 months ago from infosec.exchange permalink
  20. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 18-Nov-2025 02:49:34 JST Dan Goodin Dan Goodin

    RE: https://mastodon.social/@Dhmspector/115565843170649326

    In fairness 98% of the people who said they'd flee the US if Trump retook the White House didn't follow through either.

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: files.mastodon.social
      Dave Spector (@Dhmspector@mastodon.social)
      from Dave Spector
      Attached: 1 image As I said… a bunch of drama queens. Whiny, little, drama queens.
  • Before

User actions

    Dan Goodin

    Dan Goodin

    Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          92418
          Member since
          27 Jan 2023
          Notices
          182
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.