@adamshostack@infosec.exchange avatar

adamshostack

@adamshostack@infosec.exchange

Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security.

Following back if you have content.

This profile is from a federated server and may be incomplete. For a complete list of posts, browse on the original instance.

adamshostack , to random
@adamshostack@infosec.exchange avatar

I look forward to the polymorphic malware that literally writes itself https://fuglede.github.io/llama.ttf/

adamshostack , to random
@adamshostack@infosec.exchange avatar

In the week that has transpired since Adam's announcement regarding his stalker Sean -- https://shostack.org/stalker -- the entire community's response has been something to truly behold. Your words of support (not to mention several of you finding the strength to share that you, too, have been the subject of this person's unwanted attention and problematic behavior) have been so encouraging to read.

During our time managing his social media accounts, we have been communicating many of your messages to Adam and he appreciates you all very much. We'll keep monitoring things here for a while, but we're certain Adam will convey his own words of thanks when he returns to social media in the near future.

Thank you, and keep taking care of one another.

  • Tanya and Deviant

https://infosec.exchange/@adamshostack/112615749912327802

adamshostack , to random
@adamshostack@infosec.exchange avatar

Now that I'm out of the woods, I want to talk about my latest bout of covid, which lasted about 7 days.

I've been being careful, masking in taxis, on airplanes and when out. I have been eating out now and then, and using enovid when I do.

American society is not being careful. Getting good information on incidence is hard, we keep dismantling the surveillance and reporting systems that could inform risk decisions.

When I got Paxlovid (now $400!) I specifically asked my doctor about reporting my case to contribute to societal information, and he said "The WA dept of health is no longer collecting this data from individual tests."

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry Thank you and, wow, 5 times! I'm fortunate, this case was less bad than my Blackhat case.

I'm fortunate, I don't have to be concerned about a $400 expense cropping up, but that's not the case for many folks.

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry Also, the responses I wanted to type were like "stay safe" and "be careful," but that's really implying that the fault is yours. The key point I want to make is that (1) it's still out there and serious and (2) the societal tools we could build to help people manage risk are under assault.

adamshostack , to random
@adamshostack@infosec.exchange avatar

A group of leading AI researchers have released a letter about a "Right to Warn" advocating that staff can warn the public about risks from their employer’s products, without being sued for disparagement or retaliated against. It’s specific and thought provoking, and perhaps we should have a broader conversation about it, including not just AI, but security and privacy.

https://righttowarn.ai/

jerry , to random
@jerry@infosec.exchange avatar

I just started reading/listening to the book “Threats” by @adamshostack. It’s really good.

adamshostack ,
@adamshostack@infosec.exchange avatar

@jerry Glad you're enjoying it!

adamshostack , to random
@adamshostack@infosec.exchange avatar

Remind me to give @jerry extra money for the traffic surge.

adamshostack , to random
@adamshostack@infosec.exchange avatar

If you’ve held “leadership positions” and you’re saying “employees are the root of the problem” and “it’s people and their egos at the nexus of industry failing” I’m going to have questions about your leadership.

(Firm redacted, I’m not looking to pick a fight with the author. Maybe they’ll have useful stuff to say.)

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry They own up to that somewhat a few pages later.

adamshostack , to random
@adamshostack@infosec.exchange avatar

I admit to wondering what the National Pregnancy Database bill was all about, and according to this, it's government handouts to anti-choice organizations.

(Not to mention additional handouts to data brokers after each inevitable breach of the database.)

https://hachyderm.io/@cyberlyra/112428575610501862

adamshostack , to random
@adamshostack@infosec.exchange avatar

(I'm experimenting with short videos about blog posts like this one on the CSRB on Microsoft. I have no idea how video uploaded to Mastodon works.)

Edit: apparently it doesn't work 🤷

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@dostalcody yeah, i hit the 'attach' button, got a progress bar, then nothing.

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry @dostalcody 319,552,038 bytes of mp4

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry @dostalcody if you give me the CLI I can see if it runs locally. Also, Jerry, this is like Pri3. I appreciate the work and chose not to tag you or @ support.

ElenLeFoll , to random
@ElenLeFoll@fediscience.org avatar
adamshostack ,
@adamshostack@infosec.exchange avatar

@ElenLeFoll @academicsunite I'm enjoying the series; there's clearly a paper mill aspect that we should worry about; and the for-profit publishers are showing how much value they subtract.

Is there a legit use for LLMs in writing better summaries, abstracts, and other parts of papers?

I certainly read a fair number of papers where the authors can't write, and even an LLM can help make their work readable.

adamshostack ,
@adamshostack@infosec.exchange avatar

@nicolaromano @ElenLeFoll @academicsunite Interesting -- I've been using template papers for a long time so haven't needed a structure.

claudius , to random
@claudius@darmstadt.social avatar

I find few human-made things as awe-inspiring as the Voyager probes. I really hope Voyager 1 can be fixed.

adamshostack ,
@adamshostack@infosec.exchange avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines