Loren Kohnfelder

60 Followers
163 Following
478 Posts
Author of Designing Secure Software: A guide for developers
#securedesign
日本語ローレン・コンフェルダー
Bookhttps://designingsecuresoftware.com/
I was thinking about an zero cost and easy way to prove primacy creating a document. While there's no serious security here, at all, thanks to federation a post gets quickly propagated publicly so it would be very hard to hack all the host servers later. Like this, but etiquette requires only occasional use, this isn't a blockchain. Hashtag #dibs
12036e414db4c1ec821f7b1f21f72afced91562248d1c8c1690d4a99f091a06b00f3e9fbfa25469d17102a2911283da79e7b57eecb682e10b441e4f6f7673db1 (sha512) or 6bfc959c1abeed8c9b1d832824cf0083302b6f7cc1951178cae06217cfe785ed (sha256)
The LLM grammar fixer I use acts silly in that doesn't seem to know about threat models. It may correct "threat model" to "threaten the model" or "threaten to model", neither of which I would ever do but it's fun trying to imagine.

"Every day computers are making people easier to use"

--Masthead on In Formation Magazine

RE: https://sigmoid.social/@cigitalgem/116000745386699840

Progress since 1993: one easy way to sell more ads.

There are a lot of stories right now about #microsoft, the #FBI and #bitlocker

I've expanded my comments from this morning into a longer post.

https://shostack.org/blog/bitlocker-the-fbi-and-risk/

cc @lorenzofb @boblord @GossiTheDog

Shostack + Friends Blog > Bitlocker, the FBI, and Risk

What can bitlocker tell us about risk?

Embarrassing: "After installing the August 2025 non-security preview update (KB5064081) or later updates, you might notice that the password icon is not visible in the sign-in options on the lock screen."
Rather than ridicule, I have one question: How does this kind of bug get released with professional testing?
https://support.microsoft.com/en-us/topic/august-29-2025-kb5064081-os-build-26100-5074-preview-3f9eb9e1-72ca-4b42-af97-39aace788d93
August 29, 2025—KB5064081 (OS Build 26100.5074) Preview - Microsoft Support

With all due respect, the hubris of an AI leader not listening to critics is mindblowing to me. Even if the critics are wrong, help them, don't dismiss them, especially your customers. Of course his book The Coming Wave Book ignored the obvious downsides, too.
If AI is such a powerful transformative technology that's ready for primetime, why all the mandates to use it, excessive hype, and insistence that adoption is inevitable?
[quote] "Jeez there so many cynics! It cracks me up when I hear people call AI underwhelming," tweeted Mustafa Suleyman, the CEO for Microsoft's AI group. "The fact that people are unimpressed that we can have a fluent conversation with a super smart AI that can generate any image/video is mindblowing to me"
https://slashdot.org/story/25/11/20/1441200/microsoft-exec-asks-why-arent-more-people-impressed-with-ai
Microsoft Exec Asks: Why Aren't More People Impressed With AI? - Slashdot

An anonymous reader shares a report: A Microsoft executive is questioning why more people aren't impressed with AI, a week after the company touted the evolution of Windows into an "agentic OS," which immediately triggered backlash. "Jeez there so many cynics! It cracks me up when I hear people ca...

We're so back!

Join us October 29th, 14:00 CST, for a meetup with @adamshostack about publishing threat models: the reasons why, the arguments why not, and how open source can set the precedent. One month away from this awesome presentation and discussion!

RSVP at https://luma.com/6fvp6orm

It really says something about what the web has become and the level of influence social media commands that the inventor of the web chooses instagram to promote his memoir. https://w3c.social/@timbl/115152737851885485
Tim Berners-Lee (@[email protected])

In 4 days my memoir 📕 'This Is for Everyone' will be published. The book tour kicks off the same day with many more events following. Follow the journey on the book's Instagram - https://instagram.com/sirtimbernersleeforeveryone/

w3c.social
In the excellent Fundamentals, Frank Wilczek writes, "Science can help us attain our goals … but it does not choose our goals for us." The book is a serious but non-mathematical overview of modern fundamental physics for general readers. That nicely expresses my take on generative AI (substitute for "Science").