13 Followers
152 Following
15 Posts

The Fires of History: Trolls Saving the World

This has been a draft for years as I post this now, but I have finished the book already. For today, I thought that interviewing various AI should help set the stage for a treatise on trolling. After all, they are the end product of a lot of intentional methodologic thinking, content filters, and ingrained biases which are then handwaved around as objective and material. 

http://gorrie.org/2026/03/12/the-fires-of-history-trolls-saving-the-world/

The Fires of History: Trolls Saving the World

This has been a draft for years as I post this now, but I have finished the book already. For today, I thought that interviewing various AI should help set the stage for a treatise on trolling. Aft…

Bad Penny
Nice whiff on the palantir middle earth lore by the article author.

@adamshostack I'm surprised to see you on board with this stuff. With AI timelines, I don't see how any of these things matter anymore.

Is it wishful thinking that people can constrain webapps and data leakage with a banhammer? Have we learned nothing?

Disappointed that it's current year and we're still having these dumb conversations about propping up the legal profession.

Imagine not getting to say no to everything.

https://x.com/gorrie/status/1955785088232480944

Ian Gorrie (@gorrie) on X

Was just at @USENIXSecurity and realized how irrelevant all the lawyers are in disclosure programs. And they had the wrong examples. The correct examples are the @Cisco Blackhat heap vuln they hid as a noncritical update and silenced with lawyers And RFP posting xss on

X (formerly Twitter)
These are my tips. Which one are yours? https://thc.org/tips
The Hacker’s Choice

Founded in 1995

The Hacker’s Choice

Additionally:

"Apple can no longer offer Advanced Data Protection (ADP) in the United Kingdom to new users and current UK users will eventually need to disable this security feature. ADP protects iCloud data with end-to-end encryption, which means the data can only be decrypted by the user who owns it, and only on their trusted devices. We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy. Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before. Apple remains committed to offering our users the highest level of security for their personal data and are hopeful that we will be able to do so in the future in the United Kingdom. As we have said many times before, we have never built a backdoor or master key to any of our products or services and we never will.”

I was wondering when the Atlantic Council would join the lawfare.

Pretty sure they'll Lessig it.

@kfh It's the Ryan Reynolds bucks.

Drop what you are doing and read this incredible story from Wired, if you can. After that, come back here.

https://www.wired.com/story/edward-coristine-tesla-sexy-path-networks-doge/

It mentions that a 19 y/o man who's assisting Musk's team and who has access to sensitive government systems is Edward Coristine. Wired said Coristine, who apparently goes by the nickname "Big Balls," runs a number of companies, including one called Tesla.Sexy LLC

"Tesla.Sexy controls dozens of web domains, including at least two Russian-registered domains. One of those domains, which is still active, offers a service called Helfie, which is an AI bot for Discord servers targeting the Russian market.While the operation of a Russian website would not violate US sanctions preventing Americans doing business with Russian companies, it could potentially be a factor in a security clearance review."

The really interesting part for me is Coristine's work history at a company called Path Networks, which Wired describes generously as a company "known for hiring reformed black-hat hackers."

"At Path Network, Coristine worked as a systems engineer from April to June of 2022, according to his now-deleted LinkedIn resume. Path has at times listed as employees Eric Taylor, also known as Cosmo the God, a well-known former cybercriminal and member of the hacker group UGNazis, as well as Matthew Flannery, an Australian convicted hacker whom police allege was a member of the hacker group LulzSec. It’s unclear whether Coristine worked at Path concurrently with those hackers, and WIRED found no evidence that either Coristine or other Path employees engaged in illegal activity while at the company."

The founder of Path is a young man named Marshal Webb. I wrote about Webb back in 2016, in a story about a DDoS defense company he co-founded called BackConnect LLC. Working with Doug Madory, we determined that BackConnect had a long history of hijacking Internet address space that it didn't own.

https://krebsonsecurity.com/2016/09/ddos-mitigation-firm-has-history-of-hijacks/

Incidentally, less than 24 hours after that story ran, my site KrebsOnSecurity.com was hit with the biggest DDoS attack the Internet had ever seen at the time. That sustained attack kept my site offline for nearly 4 days.

https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/

Here's the real story behind why Coristine only worked at Path for a few months. He was fired after Webb accused him of making it known that one of Path's employees was Curtis Gervais, a serial swatter from Canada who was convicted of perpetrating dozens of swattings and bomb threats -- including at least two attempts on our home in 2014. [BTW the aforementioned Eric Taylor was convicted of a separate (successful) swatting against our home in 2013.

https://krebsonsecurity.com/2017/09/canadian-man-gets-9-months-detention-for-serial-swattings-bomb-threats/

https://krebsonsecurity.com/2017/02/men-who-sent-swat-team-heroin-to-my-home-sentenced/

In the screenshot here, we can see Webb replying to a message from Gervais stating that "Edward has been terminated for leaking internal information to the competitors."

Wired cited experts saying it's unlikely Coristine could have passed a security clearance needed to view the sensitive government information he now has access to.

Want to learn more about Path? Check out the website https://pathtruths.com/

DOGE Teen Owns ‘Tesla.Sexy LLC’ and Worked at Startup That Has Hired Convicted Hackers

Experts question whether Edward Coristine, a DOGE staffer who has gone by “Big Balls” online, would pass the background check typically required for access to sensitive US government systems.

WIRED

Has this really thought through all of the systems that use SHA-256 as a part of other cryptographic algorithms? TLS, DKIM, X.509, DNSSEC, S/MIME, Bitcoin, OpenSSH, PGP, JWT, IPsec IKEv2, DMARC, Git, ODF, OOXML, Signal and I'm sure there are more...

That's what we have to drop or redesign in the next five years to not use SHA-256 according to this directive.

https://www.theregister.com/2024/12/17/australia_dropping_crypto_keys/

Australia moves to drop some cryptography by 2030 – before quantum carves it up

The likes of SHA-256, RSA, ECDSA and ECDH won't be welcome in just five years

The Register