Allan Friedman

871 Followers
373 Following
830 Posts
#SBOM Champion. Full service technocrat. Now at @Cisagov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.
Ramp season! So delicious, but can be a bit of a pain to clean.

it is genuinely very funny that despite all the press releases and mouth foaming, people are now routinely blaming any outage or computer errors on vibe coding

or if you will:

insufficiently advanced technology is indistinguishable from slop

I was trying to tell a friend how thorny an issue e-bikes are for cities trying to regulate them and spent the whole day writing this blog post explaining all the ins-and-outs and what-have-yous involved in e-bike regulation https://a.wholelottanothing.org/e-bikes-are-a-thorny-issue-for-trails-and-parks/
E-bikes are a thorny issue for trails and parks

I ran across this article on the LA Times site about the friction developing around shared trails in the Los Angeles area between e-bikes, bikes, horses, hikers, and dog walkers. It does a good job summing up everyone's issues but it barely scratches the surface of just how complicated trying

A Whole Lotta Nothing
Aw yeah. ‘Bout to get Nonna up in here.

Hi Friends! You have one week to submit to The Diana Initiative, an amazing infosec conference aimed at fostering more inclusive information security industry. I understand that they are particularly interested in Red Team talks, so please circulate to those who would be interested.

https://sessionize.com/tdi-online-2026/

@DianaInitiative

The Diana Initiative 2026 (Online Event): Call for Speakers

The Diana Initiative​ is hosting a one-day, online, diversity-driven conference with the goal to create a more inclusive information security industry...

A very happy birthday to everyone who spent time to pick something other than Jan 1 for their fake birthday!

Many happy returns, and I hope you get a free ice cream cone somewhere. (Do they still do that?)

I'm embarrassed that we still need to say this, but:
Trans rights are human rights.

I have trans friends, and they are every bit as annoying and wonderful as all my other friends. Many of them are way better hackers.

And we should all be annoyed that, in the US, even just flying through a major transit airport could be a real threat to their lives and wellbeing.

Last day of RSAC conference. Once more into the breach [response and recovery AI tooling sales talks]!
Anyone know of research on how people “discover” new open source that they want to use? Does one search GitHub for strings relevant to what they are looking for? See code used in other projects? Are there other registries?
“Shadow AI is like regular AI, but with cooler hair and music.”