Lucas Gonze (infosec posts)

46 Followers
36 Following
146 Posts

Infosec-focused account. See @lucasgonze for OSS posts.

I'm Security TPM for magmacore.org. I advise corporate clients on securing their open source open-source project . My clients include New Relic, Toyota, eBay, Cisco, and Meta.

Githubhttps://github.com/lucasgonze/
Tech bloghttps://writing.gonze.com/
Emailmailto:[email protected]?subjection=infosec.exchange

Detecting Backdoors with Meta-Models

"It is widely known that it is possible to implant backdoors into neural networks, by which an attacker can choose an input to produce a particular undesirable output (e.g. misclassify an image). We propose to use meta-models, neural networks that take another network's parameters as input, to detect backdoors directly from model weights. To this end we present a meta-model architecture and train it on a dataset of ~4000 clean and backdoored CNNs trained on CIFAR-10. Our approach is simple and scalable, and is able to detect the presence of a backdoor with accuracy"

https://openreview.net/forum?id=cmJiEqniEc

#infosec #ai

Detecting Backdoors with Meta-Models

It is widely known that it is possible to implant backdoors into neural networks, by which an attacker can choose an input to produce a particular undesirable output (e.g.\ misclassify an...

OpenReview
The best Slack channel is the "thanks" Slack channel. If your organization doesn't have one, set one up as a place for people to share praise and shout-outs and appreciation for big & small things

I was about to increase the inactivity timeout on my phone, and realized it was better to make my PIN shorter and more crackable.

If the device isn't locking on failed attempts then all is lost, and if it is locking then an extra-hard password will lead to insecure practices like a longer inactivity timeout.

Most of the value of the OpenSSF Best Practices Badge and Security Scorecard is influence over your project's roadmap. You use them to find, organize, and prioritize security improvements.

But neither of those projects thinks of itself that way.

What their UX *should* be is a Kanban board for evaluating each criteria, then doing project management to mitigate work items you find.

We did #barbie and #oppenheimer over the weekend. One of them is a salutary warning about man creating something that inevitably leads to the end of life as we know it, and the other is about some fella making a nuclear bomb
The Fediverse is dying so fast that the media storage on Infosec.exchange is growing by 1GB every 15 minutes and I am going to have to add another app server for the US region.
Pleasantly shocked when a banker sent confidential information using a plausibly security tool, https://www.virtru.com/.
Data Encryption For Email & File Sharing | Virtru

Virtru data encryption protects data, through email and file-sharing, Cloud, SaaS, CRM solutions and across internal and external ecosystems.

I must not engage with the discourse
Discourse is the time-killer
Discourse is the little error that leads to table-flipping
I will ignore the discourse
I will permit it to pass through me and over me
When it has gone past, I will turn to my timeline and see no posts
Where the discourse was, there will be nothing
Only cat pics will remain
Repeat after me: Blocking paste on a form textbox is not a security feature.
Most people have probably already forgotten that several months ago, the Biden admin stopped a nationwide rail strike (over sick days) that might have screwed the economy. This made unions and union supporters very unhappy, and few believed the President when he said he’d get them their sick days. But with the help of Bernie Sanders, he has done it. They got the RR workers what they needed AND avoided a crippling strike. This is a big win for everyone that will probably go unnoticed. http://www.ibew.org/media-center/Articles/23Daily/2306/230620_IBEWandPaid
‘We Never Stopped Applying Pressure’: Hard-Fought Success on Rail Sick Days

After months of negotiations, the IBEW’s Railroad members at four of the largest U.S. freight carriers finally have what they’ve long sought but that many working people take for granted: paid sick days.