@adamshostack@infosec.exchange avatar

adamshostack

@adamshostack@infosec.exchange

Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books include Threats: What Every Engineer Should Learn from Star Wars (2023), Threat Modeling: Designing for Security, and The New School of Information Security.

Following back if you have content.

This profile is from a federated server and may be incomplete. For a complete list of posts, browse on the original instance.

adamshostack , to random
@adamshostack@infosec.exchange avatar

I look forward to the polymorphic malware that literally writes itself https://fuglede.github.io/llama.ttf/

adamshostack , to random
@adamshostack@infosec.exchange avatar

In the week that has transpired since Adam's announcement regarding his stalker Sean -- https://shostack.org/stalker -- the entire community's response has been something to truly behold. Your words of support (not to mention several of you finding the strength to share that you, too, have been the subject of this person's unwanted attention and problematic behavior) have been so encouraging to read.

During our time managing his social media accounts, we have been communicating many of your messages to Adam and he appreciates you all very much. We'll keep monitoring things here for a while, but we're certain Adam will convey his own words of thanks when he returns to social media in the near future.

Thank you, and keep taking care of one another.

  • Tanya and Deviant

https://infosec.exchange/@adamshostack/112615749912327802

adamshostack , to random
@adamshostack@infosec.exchange avatar

Now that I'm out of the woods, I want to talk about my latest bout of covid, which lasted about 7 days.

I've been being careful, masking in taxis, on airplanes and when out. I have been eating out now and then, and using enovid when I do.

American society is not being careful. Getting good information on incidence is hard, we keep dismantling the surveillance and reporting systems that could inform risk decisions.

When I got Paxlovid (now $400!) I specifically asked my doctor about reporting my case to contribute to societal information, and he said "The WA dept of health is no longer collecting this data from individual tests."

franktaber ,
@franktaber@mas.to avatar

@jerry @adamshostack Sorry to hear about both your cases. This is a societal failure of epic proportions.

Unfortunately as I was writing just a day ago it looks like H5N1 is nearing the point that it can cause a human pandemic given its clear evolution over the last year. We may have a year before that hits.

nazokiyoubinbou ,
@nazokiyoubinbou@mastodon.social avatar

@jerry @adamshostack I think we already are. There is significant evidence COVID-19 does long term damage. We're just waiting for the long term to actually come around to find out. I mean, we could have studied it to find out, but instead the entirety of humanity is one giant guinea pig cage I guess.

I'm particularly concerned about the fact SARS-CoV-2 seems to pass the blood-brain barrier.

adamshostack , to random
@adamshostack@infosec.exchange avatar

A group of leading AI researchers have released a letter about a "Right to Warn" advocating that staff can warn the public about risks from their employer’s products, without being sued for disparagement or retaliated against. It’s specific and thought provoking, and perhaps we should have a broader conversation about it, including not just AI, but security and privacy.

https://righttowarn.ai/

adamshostack , to random
@adamshostack@infosec.exchange avatar

Remind me to give @jerry extra money for the traffic surge.

jerry ,
@jerry@infosec.exchange avatar

@adamshostack I wondered where all the new accounts were coming from

adamshostack , to random
@adamshostack@infosec.exchange avatar

If you’ve held “leadership positions” and you’re saying “employees are the root of the problem” and “it’s people and their egos at the nexus of industry failing” I’m going to have questions about your leadership.

(Firm redacted, I’m not looking to pick a fight with the author. Maybe they’ll have useful stuff to say.)

jerry ,
@jerry@infosec.exchange avatar

@adamshostack technically the executive could be talking about themselves.

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry They own up to that somewhat a few pages later.

adamshostack , to random
@adamshostack@infosec.exchange avatar

I admit to wondering what the National Pregnancy Database bill was all about, and according to this, it's government handouts to anti-choice organizations.

(Not to mention additional handouts to data brokers after each inevitable breach of the database.)

https://hachyderm.io/@cyberlyra/112428575610501862

adamshostack , to random
@adamshostack@infosec.exchange avatar

(I'm experimenting with short videos about blog posts like this one on the CSRB on Microsoft. I have no idea how video uploaded to Mastodon works.)

Edit: apparently it doesn't work 🤷

jerry ,
@jerry@infosec.exchange avatar

@adamshostack @dostalcody ok. Let me see if perhaps ffmpeg is choking on the file

adamshostack OP ,
@adamshostack@infosec.exchange avatar

@jerry @dostalcody if you give me the CLI I can see if it runs locally. Also, Jerry, this is like Pri3. I appreciate the work and chose not to tag you or @ support.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines