449 Followers
232 Following
7.7K Posts
design, build, teach threat-informed information security programs and techniques. Also: boosts of interesting classes, tools, research. (they/them)
Bloghttp://dfirnotes.net
Resource linkshttp://www.dfirnotes.net/about/
Congress should say NO to the NO FAKES Act. Read more about why: https://www.eff.org/deeplinks/2026/06/no-fakes-act-could-silence-satire-commentary-and-news
The NO FAKES Act Could Silence Satire, Commentary, And News

The NO FAKES Act is supposed to target harmful AI-generated impersonations. But in reality, it will make it easier to suppress commentary, satire, and other lawful speech. That's why EFF has signed a letter urging the Senate Judiciary Committee not to advance the bill in its current form.Take...

Electronic Frontier Foundation

Time for a new series: #HolyHOA !

I live in a converted church, which was built in 1849 and is now 63 condos (conversion "completed" around 2021). I have since learned that these conversions are ... somewhat cursed, in general.

I'm on the board of trustees, and I'm effectively the building superintendent as well. You may have seen me posting about the various pains here before, but I figured if I'm going to post more about them, I needed a catch hashtag - and thus, #HolyHOA !

@gurkan @dalias
Now with alt text

What's the deal with some of the packages in the #Fedora Atomic images seemingly not being built from the same spec as the regular RPMs?

curl, as an example, has a completely different featureset on the Atomic distros despite the same package version, and this filters all the way through the UBlue ecosystem into downstreams like Bazzite.

Are *you* "In The Weights"?¹

https://intheweights.com/

¹If you are, it's not a good thing IMO.

Worst. Timeline. Ever.

Nerdsnipe time.

What was the first work of fiction to feature the World Wide Web?

I don't mean some 1950's sci-fi with pan-Earth info system. I mean a story with a character literally visiting "www. something" on a computer.

Any ideas?

Anyone else noticing how pattern recognition processes and tools that have been around for a very long time (like optical character recognition and speech-to-text) are suddenly being referred to as “AI”? 🤷‍♂️

The one bright spot of LLMs is that we've learned exactly how morally and creatively bankrupt this industry is, and how fast people are willing to throw away everything they said they cared about for decades - craft, understanding, efficiency, detail, all of it - just to cosplay competence and bandwagon their way to groupthink targets they don't even realize were made up to manipulate them.

Christ it's embarassing.

@europlus @davidgerard That's the feeling I get from a lot of discussions of AI ethics which end on something like

"You should consider these factors carefully before deciding whether to use an LLM."

"OK, I've considered them and I've chosen not to use an LLM."

"Oh. We didn't actually expect anyone to take that option."

Listen: I care about security and don't want people running malware on their phones, but everybody's threat model is different.

If you care about security and privacy, you should also care about giving people the option to pick what security means for THEM personally.

There aren't a ton of options for degoogled android phones out there for people that don't live in China, which means that the vast majority of people are essentially being forced into this.