GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Dan Goodin (dangoodin@infosec.exchange), page 2

  1. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 14-Nov-2025 04:15:27 JST Dan Goodin Dan Goodin
    • Kevin Beaumont

    @GossiTheDog

    The WSJ link is in the OP. A non-paywalled link is: https://web.archive.org/web/https://www.wsj.com/tech/ai/china-hackers-ai-cyberattacks-anthropic-41d7ce76

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: web.archive.org
      Exclusive | Chinese Hackers Used Anthropic’s AI to Automate Cyberattacks
      from https://www.wsj.com/news/author/robert-mcmillan
      The use of AI automation in hacks is a growing trend that gives hackers additional scale and speed
  2. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 14-Nov-2025 03:20:01 JST Dan Goodin Dan Goodin

    I could really benefit from experts' analysis of this WSJ article reporting that China-backed hackers used Anthropic’s Claude to automate 80% to 90% of a September hacking campaign targeting corporations and governments.

    There aren't a lot of specifics, but among those provided:

    The effort focused on dozens of targets and involved a level of automation that Anthropic’s cybersecurity investigators had not previously seen.

    In this instance 80% to 90% of the attack was automated, with humans only intervening in a handful of decision points.

    The hackers conducted their attacks “literally with the click of a button, and then with minimal human interaction."

    Anthropic disrupted the campaign and blocked the hackers’ accounts, but not before as many as four intrusions were successful.

    In one case, the hackers
    directed Claude tools to query internal databases and extract data independently.

    “The human was only involved in a few critical chokepoints, saying,
    doesn’t look right, Claude, are you sure?’”
    ‘Yes, continue,
    ’ ‘Don’t continue,
    ’ ‘Thank you for this information,
    ’ ‘Oh, that

    Stitching together hacking tasks into nearly autonomous attacks is a new step in a growing trend of automation that is giving hackers
    additional scale and speed.

    We've seen so many exaggerated accounts of AI-assisted hacks. Is this another one? Are there reasons to take this report more seriously? Any other thoughts?

    https://www.wsj.com/tech/ai/china-hackers-ai-cyberattacks-anthropic-41d7ce76

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://seen.In/
    2. No result found on File_thumbnail lookup.
      OTHAYOTH - Website Under Construction
      Website Under Construction
  3. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 13-Nov-2025 07:51:19 JST Dan Goodin Dan Goodin

    RE: https://infosec.exchange/@dangoodin/115538361125409018

    In 20 minutes NY AG Letitia James will participate in the Conde Nast union rally supporting 4 of our colleagues who were illegally fired. If you're near WTC in Manhattan, please show your support.

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      Dan Goodin (@dangoodin@infosec.exchange)
      from Dan Goodin
      Attached: 1 image ICYMI: 4 Conde Nast employees were illegally fired for exercising permitted speech in their workplace. Tonight, NY AG Letitia James will call out this union-busting move by Conde management. Please attend. Please also sign our petition to reinstate our fired colleagues. https://actionnetwork.org/petitions/tell-conde-bosses-to-reinstate-the-fired-four-reverse-the-suspensions-and-end-the-union-busting. Please boost for reach.
  4. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 13-Nov-2025 05:58:44 JST Dan Goodin Dan Goodin

    Wow, the lack of ANY factual support for such a claim amounts to hyperbole. And from a CEO peddling a service to "guarantee content integrity." File this one under "Umbrella salesman predicts torrential rain."

    https://www.wgcu.org/science-tech/2025-09-23/detection-expert-says-hackers-likely-used-ai-to-penetrate-airport-system

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: npr.brightspotcdn.com
      Detection expert says hackers likely used AI to penetrate airport system
      from https://www.wgcu.org/undetectable-ai
      As major airports across Europe have been targeted in a cyber-attack that began on Saturday, an expert is warning that artificial intelligence may have played a key role in the breach.The incident, which disrupted check-in and baggage systems at hubs including Dublin, London, Brussels and Berlin, left thousands of passengers stranded with canceled or delayed flights.Christian Perry, CEO of Undetectable AI, AI detection experts, explained how AI is reshaping the way cyber-attacks unfold.
  5. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 13-Nov-2025 04:32:03 JST Dan Goodin Dan Goodin

    ICYMI: 4 Conde Nast employees were illegally fired for exercising permitted speech in their workplace. Tonight, NY AG Letitia James will call out this union-busting move by Conde management. Please attend. Please also sign our petition to reinstate our fired colleagues. https://actionnetwork.org/petitions/tell-conde-bosses-to-reinstate-the-fired-four-reverse-the-suspensions-and-end-the-union-busting.

    Please boost for reach.

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/538/353/371/204/178/original/6f8993aeed3c4c01.jpg
    2. Domain not in remote thumbnail source whitelist: can2-prod.s3.amazonaws.com
      Tell Condé bosses to reinstate the Fired Four, reverse the suspensions and end the union-busting
      from The NewsGuild of New York
      On Nov. 5, 2025 in an egregious attempt at union-busting, Condé Nast management illegally terminated four union members – Alma Avalle, Jake Lahut, Jasper Lo and Ben Dewey – for participating in federally protected union activity. Management singled out the four union leaders from a group of nearly 20 Guild members who approached the head of human resources, Stan Duncan, to seek answers about the decision to dismantle Teen Vogue – a brand praised for its insightful political and cultural journalism often critical of the Trump administration – and related layoffs. Prior to this, union members made repeated attempts to meet with Duncan and other executives to talk through concerns about multiple rounds of layoffs and a seeming shift away from critical politics and identity coverage at several prominent Condé brands. Executives ignored those requests. On Nov. 7, management additionally suspended without pay five more employees who were present in the hallway while their colleagues asked Duncan questions about their workplace. Under Section 7 of the National Labor Relations Act, workers are guaranteed the right to self-organize and “to engage in other concerted activities for the purpose of collective bargaining or other mutual aid or protection.” The Fired Four, the five additional suspended workers and their coworkers were exercising that right. Make no mistake: This is Condé Nast taking advantage of the government shutdown and the Trump Administration’s repression of the National Labor Relations Board to illegally exploit and punish workers, to ignore the union contract they agreed to, and to try to scare the rest of their unionized workforce into silence. The company is attempting to silence its workers in any way possible while the Trump administration is openly muzzling the free press. It will not work. Approaching the head of Human Resources to ask questions about labor conditions is something union members at Condé — and at many other outlets — have done before, including at Conde, and have a right to do again. The true gross misconduct in this instance is the retaliation from the company in targeting union leaders instead of answering their employees’ questions.   Stand with the Condé and New Yorker workers and demand that Condé Nast executives reinstate Alma, Ben, Jake, and Jasper immediately, rescind all illegal retaliatory discipline, and stop union-busting — NOW.
  6. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 01-Nov-2025 02:19:21 JST Dan Goodin Dan Goodin
    • Kim Zetter

    "The former executive of Trenchant who pleaded guilty this week to selling his company's software hacking tools to a zero-day broker in Russia, sold at least one of these tools to the Russian firm even after learning that a previous tool he sold the broker was being used by a South Korean broker – indicating that the stolen tools were being passed on to others downstream."

    A reminder that if you're not following @kimzetter you should be.

    https://www.zetter-zeroday.com/former-trenchant-exec-sold-stolen-code-to-russian-buyer-even-after-learning-that-other-code-he-sold-was-being-utilized-by-different-broker-in-south-korea/

    In conversation about 9 months ago from infosec.exchange permalink
  7. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 31-Oct-2025 06:47:03 JST Dan Goodin Dan Goodin

    People working on post-quantum-proofing vulnerable encryption protocols (and curious onlookers) can find lots of value in this new post from Cloudflare. It discusses the herculean engineering challenges of revamping anonymous credentials that will be broken by a quantum computer. There's a growing need for this kind of privacy (for instance to make digital drivers licenses privacy preserving), which allows individuals to prove specific facts, like they have had a drivers license for more than 3 years, without divulging personal information like their birthday or place of birth. The long and short of of the challeng is that engineers can't simply drop quantum-resistant algorithms into AC protocols that currently use vulnerable ones. Instead, engineers will need to collaborate with standards bodies that build entirely new protocols, largely from scratch. The post goes on to name a few of the most promising approaches.

    https://blog.cloudflare.com/pq-anonymous-credentials/

    In conversation about 9 months ago from infosec.exchange permalink
  8. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 24-Oct-2025 06:43:58 JST Dan Goodin Dan Goodin
    • Kevin Beaumont
    • Kim Zetter

    @GossiTheDog

    As @kimzetter reported recently, a CISA official blamed democrats during a press call. very concerning that even securing the nations infrastructure isn't immune from politicization.

    In conversation about 9 months ago from infosec.exchange permalink
  9. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 22-Oct-2025 02:55:58 JST Dan Goodin Dan Goodin

    Can anyone recommend a free, secure way for someone with only a Chromebook to manage passwords? The person isn't very good with computers, so usability is a must.

    In conversation about 9 months ago from infosec.exchange permalink
  10. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 21-Oct-2025 02:10:33 JST Dan Goodin Dan Goodin
    • Adam Lashinsky

    "When you look closer at Benioff’s big investment [in San Francisco], it becomes clear that the move was as cartoonishly fake as the forest characters Salesforce uses in its branding. In real life, that $15-billion “investment” isn’t an investment at all, but rather business as usual for Salesforce, which is the city’s largest private employer and has been headquartered here since it was founded in 1999."

    by @adamlashinsky

    https://sfstandard.com/opinion/2025/10/20/audacity-marc-benioff/

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: assets.sfstandard.com
      The audacity of Marc Benioff
      from Adam Lashinsky
      To distract from his National Guard comments, the CEO tried to get San Franciscans to believe Salesforce was growing its local investments. It’s not even close to true.
  11. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 18-Oct-2025 02:03:54 JST Dan Goodin Dan Goodin
    in reply to
    • Signal

    As the wave of authoritarianism keeps cresting, I've been challenging myself and others to ween ourselves off of centralized platforms that leak our private data (through breaches or voluntarily) and deplatform us for any reason or no reason, leaving us high and dry with no warning. You know this is awful when labor unions, civil rights groups and other groups under threat continue to trust Slack, Gmail, Xitter and the rest now of the broligarch-owned gatekeepers more than ever.

    Some of you (and in some cases I) have responded with criticism of those still using these platforms. Many of you say unions should use decentralized alternatives such as Zulip, PGP on top of Slack, Mattermost, Matrix. Besides victim blaming, this response is misguided because it expects groups divert resources from their core missions to making immature and hard-to-use platforms work inside their organization.

    All of this reminds me of the struggles we had with our dependence on unencrypted email in the 2000s and early 2010s. Back then, the only alternative was PGP, which was unusable for 50% or more of email senders. Then @signalapp came along and solved most of the sticking points, almost overnight.

    The lesson: decentralized, privacy-preserving platforms don't happen by accident. And they can't be cobbled together in beta form. They require funding and smart engineering that prioritizes usability as much as security.

    I'm still not sure how we ween ourselves off of centralized platforms, but I think the success of Signal may serve as a useful model. Maybe we don't try to replace all platforms at once, Maybe for now we focus on finding an alternative to, say, Slack and use the momentum of that to tackle other platforms afterward.

    I obviously don't have answers yet. I don't think anyone does yet. But it's important we start asking questions and stop blaming non-technologists who just want a platform that works.

    In conversation about 10 months ago from infosec.exchange permalink
  12. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Saturday, 18-Oct-2025 02:03:53 JST Dan Goodin Dan Goodin
    in reply to

    The owner of Slack, the platform so many of us security and MAGA critics use both for work and other communications, is offering its AI capabilities to to help ICE staff up as it expands immigration raids and deportations around the US. Salesforce's CEO last week called for Trump to deploy the National Guard to San Francisco.

    https://www.nytimes.com/2025/10/16/us/salesforce-benioff-ice.html

    In conversation about 10 months ago from infosec.exchange permalink
  13. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 17-Oct-2025 06:25:38 JST Dan Goodin Dan Goodin

    "Godfather of Silicon Valley" Ron Conway resigns from Salesforce board after its CEO revealed his authoritarian leanings by calling on Tump to send national guards to San Francisco. "“It saddens me immensely to say that with your recent comments, and failure to understand their impact, I now barely recognize the person I have so long admired,” Conway tells Marc Benioff in an email.

    https://sfstandard.com/2025/10/16/ron-conway-resigns-salesforce-foundation-board-marc-benioff/

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: assets.sfstandard.com
      Billionaire angel investor quits Salesforce board over Benioff’s National Guard idea
      from George Kelly
      The Silicon Valley venture capitalist bashed CEO Marc Benioff’s political right turn in a passionate message shared with The Standard.
  14. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 08:16:18 JST Dan Goodin Dan Goodin
    in reply to

    Here's another reminder that it's best to resist as much as possible the siren's call of relying on AI and other services from Big Tech. Gemini is blocking questions about Trump showing signs of dementia even as it answers the same question when applied to Biden. When we turn to AI we are abdicating our own judgement and research responsibilities to a broligarchy that bends to the whims of billionaires.

    https://www.theverge.com/news/789152/google-ai-searches-blocking-trump-dementia-biden

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/300/061/864/400/127/original/e4f45a53e42d7c4d.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/300/072/991/347/661/original/66812af424a32782.png
  15. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 08:16:17 JST Dan Goodin Dan Goodin
    in reply to

    Now that Marc Benioff, owner of Slack and Salesforce, has confirmed he sides with authoritarianism, it's more incumbent on us than ever to move off central platforms, which can dump communications we presumed were private or cut us off for any reason or no reason at all.

    https://sfstandard.com/2025/10/10/marc-benioff-national-guard-sf/

    In conversation about 10 months ago from infosec.exchange permalink
  16. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Tuesday, 14-Oct-2025 02:07:44 JST Dan Goodin Dan Goodin

    The complexity and problem-solving required for making the Signal Protocol quantum safe are as daunting as any in modern-day engineering. In less adept hands, mucking about with an instrument as complex as the Signal protocol could have led to shortcuts or unintended consequences. Yet this latest post-quantum upgrade is nothing short of a triumph.

    https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineering-achievement/

    In conversation about 10 months ago from infosec.exchange permalink
  17. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Wednesday, 01-Oct-2025 08:49:03 JST Dan Goodin Dan Goodin

    After 25 years, I still struggle to find an intuitive way to describe computer "state" to non-techies. Such a simple thing and yet I still don't know how to give it a simple description/definition.

    In conversation about 10 months ago from infosec.exchange permalink
  18. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 18-Sep-2025 04:09:15 JST Dan Goodin Dan Goodin

    Can you imagine the huge bonanza espionage and ransomware threat actors are going to have when every service you use forces you to provide them with your ID? This is a disaster that 100% will happen. I can hardly wait.

    In conversation about 11 months ago from infosec.exchange permalink
  19. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Friday, 12-Sep-2025 03:26:40 JST Dan Goodin Dan Goodin

    So many people jumping to confirmation-biased conclusions with each new assassination detail. Will y'all please stop?

    In conversation about 11 months ago from infosec.exchange permalink
  20. Embed this notice
    Dan Goodin (dangoodin@infosec.exchange)'s status on Thursday, 11-Sep-2025 05:05:56 JST Dan Goodin Dan Goodin

    A prominent US Senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of the obsolete and vulnerable RC4 encryption cipher that Windows uses by default. Senator Ron Wyden went on to liken Microsoft to an "arsonist selling firefighting services to their victims.”

    https://arstechnica.com/security/2025/09/senator-blasts-microsoft-for-making-default-windows-vulnerable-to-kerberoasting/

    In conversation about 11 months ago from infosec.exchange permalink
  • After
  • Before

User actions

    Dan Goodin

    Dan Goodin

    Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          92418
          Member since
          27 Jan 2023
          Notices
          182
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.