Lojicholia enshrines triumph

@lojikil
521 Followers
418 Following
414 Posts
Brains in the "trying to be a good dad despite having a bad dad" gang. ☦️|Father|Philosopher|Offensive Security|PLT
I work in offensive security, but my research interests are actually around Multics, ML dialects (including the two I’ve written, carML and coastML), and formal verification (esp Hoare Logic). Also anything gardening or hiking related
#magyar #balkanci #securityresearch #formalverification
GitHubhttps://github.com/lojikil
Homepagehttps://lojikil.github.io
Twitterhttps://twitter.com/lojikil

RE: https://mastodon.social/@Electrospaces/116177619999380943

It’s fascinating too that the proposed solution is “AI.” If they mean ML, sure, you can probably do some decent training there; but they likely mean LLMs which is… problematic, for various reasons

Again, it feels like the “post things on open forums and anyone can use it so long as they adhere to the license” has failed as a social contract, however strong it ever was. But the proposition for writing and maintaining FLOSS seems very painful for very little gain, especially now with the added corporate LLM issues. I might feel different with OSS models (training energy aside), but I feel little desire to post anything publicly of late, even blogs.

This paper just came up on lobste.rs:

https://arxiv.org/pdf/2507.12713

But the issue seems moot if all you’ll get is scrapers hitting whatever forge or storage system. My thought is I’d much rather have source that is licensed such that community members can use it for various purposes, as defined by authors (or even community), and cannot be posted externally. Like TLP:GREEN for source code.

RE: https://mastodon.social/@jeffjarvis/116041242464510649

Watching from the outside, it’s wild to me to see how quickly the Post has started to shift and decline of late; stranding journos in eg Ukraine during layoffs is a wild position to take

Has anyone switched to community source licensing in light of LLMs? I feel like the calculus has changed now that companies are asserting that hosting gives them exclusive rights to reuse regardless of license, and open source is no longer really what I want (I know open source folks have said for years that companies will just use it to devalue software, but still).

Folks like @stevelord may have thoughts already on this.

I keep seeing “IT: welcome to Derry,” and think “the I.T. Crowd NI reboot” and then am disappointed

In case you missed it, my piece yesterday on the 176 CISA employees fired last Friday, which will not go behind the customary archive paywall.

It's critical to note that sources told me more RIFs are in store for the nation's embattled cybersecurity agency.
https://www.metacurity.com/the-white-house-fired-176-cisa-employees-on-friday-with-more-layoffs-feared/

The White House fired 176 CISA employees on Friday, with more layoffs feared

Scattered Lapsus$ Hunters leaked 5m Qantas, 23m Vietnam Air customers' records, Spanish cops dismantle GXC Team, Dutch gov't warns of China's Nexperia security risks, Breach of crypto betting platform Shuffle exposes user data, FCC chair says sites have removed barred Chinese electronics, much more

Metacurity
I haven’t needed to run a pure web vuln scanner in years; I’ve don’t targeted stuff or had burp/zap. But looking around at the space, it’s wild to me how much it’s died off. Even the tools that do have updates seem not to have much other updates to how they work.

@lojikil

For us, the major issues are still the basics, such as infrastructure exposure, and maintaining an inventory of software or third-party services.

As an example, we provide vulnerability.circl.lu , where organisations can register their software/vendors for notifications but many still fail at that level.

In "hunting" (detection engineering), the main challenge is often the basic TI (from free MISP communities) integration with existing equipment and services.

@claushoumann

A reminder that canonically in Lord of the Rings, Denethor went mad from doomscrolling on his palantir all night long.