Adam Shostack
@adamshostack.bsky.social
2.9K followers 360 following 530 posts
Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE. Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack
Posts Media Videos Starter Packs
adamshostack.bsky.social
I think that's v2. Microsoft's on v3 of the immutable laws!
adamshostack.bsky.social
Thanks! I’m on my phone and was having trouble diving in
adamshostack.bsky.social
I haven’t had a chance to compare the details but sounds really similar to a bh talk in 2021 https://www.pcmag.com/news/sensitive-satellite-internet-data-is-easily-accessible
adamshostack.bsky.social
Publish your threat models!

Not convinced?

I'll be hosting a talk with OSTIF on Oct 29 @ 2pm CT for you to ask me questions.

Register now and have your questions, thoughts, and comments ready!

luma.com/6fvp6orm
Threat Modeling w/ Adam Shostack · Zoom · Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open source…
luma.com
adamshostack.bsky.social
What other countries have bases in the United States?
atrupar.com
Hegseth: "I'm also proud that today we're signing a letter of acceptance to build a Qatari Emeri air force facility at the Mountain Home Airbase in Idaho."
Reposted by Adam Shostack
ericacbarnett.bsky.social
Both Ducksworth and Lin oppose police surveillance cameras; Ducksworth notes that when his house got broken into, the guy looked up at the camera and broke the door in anyway. He also opposes SOAP/SODA banishment zones; someone could get sober and jaywalk in an area 2 years later and get arrested.
adamshostack.bsky.social
For them? Nothing. I'm betting their terms of service weren't written by their AI.

🤷
Reposted by Adam Shostack
dethveggie.bsky.social
WHAT COULD POSSIBLY GO WRONG.
izzos.us
git.law
Oh FUCK no...just no no no no
Screenshot of git.law showing a sample AI prompt of "I need a privacy policy for my SaaS website"
And buttons for "Draft a Contract" "Review a Contract" "Summarize a Contract"
Reposted by Adam Shostack
sbisson.com
"Tell me you haven't listened to the American albums without telling me you haven't listened to the American albums."
wsj.com
Compared to Dylan and Springsteen, country-music legend Johnny Cash can seem deeply uncool. It took time for me to appreciate his profound, plainspoken strength, writes Jon Fasman.
Essay | Can We Finally Give Johnny Cash His Due?
Compared to Dylan and Springsteen, the country-music legend can seem deeply uncool. It took time for me to appreciate his profound, plainspoken strength.
on.wsj.com
Reposted by Adam Shostack
ostifofficial.bsky.social
Join us October 29th at 14:00 CST for a meetup with @adamshostack.bsky.social!

RSVP here: luma.com/6fvp6orm

First Adam will present on threat models (he literally wrote *the* book on the subject) and a Q&A portion will follow. We look forward to him and our community connecting!
Threat Modeling w/ Adam Shostack · Zoom · Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open source…
luma.com
adamshostack.bsky.social
“Insurance will take care of it.”

Not with AI.

Today’s policies weren’t built for model failures, prompt injections, or regulators asking how your LLM works.

You might be covered.
You might not.
But either way?

Insurance doesn’t help you design safer AI.

That’s on you.

Full post: is.gd/nap9QY
Shostack + Friends Blog > AI Insurance Won't Save You
LLM Insurance is, and will remain, a great source of insurer profits.
is.gd
Reposted by Adam Shostack
sanders.senate.gov
If you are a federal worker, there are several credit unions and other financial institutions that are offering zero interest loans during the government shutdown.

Please go to my website for more information: www.sanders.senate.gov/resources-fo...
Reposted by Adam Shostack
worfemail.bsky.social
All crew,

Do not click on links in emails. They pose a major security risk. For more information: http://bit.ly/1MUISmu

Worf
Reposted by Adam Shostack
wbm312.bsky.social
You know what I want companies to care about? Good UX/UI design for security and privacy.

Some of it is just so so bad.
Reposted by Adam Shostack
daveaitel.bsky.social
Who else is going to #offensiveAICon tomorrow ?
adamshostack.bsky.social
I'm old enough to remember when Republicans said government talking with a technology company about removing content was censorship.
adamshostack.bsky.social
I'm old enough to remember when Republicans said government talking with a technology company about removing content was censorship.
adamshostack.bsky.social
"All records relating to violations of 18 U.S.C. §§ 1001 (False Statements), 666
(Theft or Bribery Concerning Programs Receiving Federal Funds), and 1343 (Wire Fraud)
(collectively, the “Subject Offenses”) involving Xiaofeng WANG including, but not limited to..."
adamshostack.bsky.social
Congratulations and thank you!

Are the warrants actually unsealed?
Reposted by Adam Shostack
riana.bsky.social
This is a really, REALLY good order. It unseals everything but the search warrant affidavits - the part I knew would be hardest and wasn't expecting to get. And even for those, the court says they shouldn't be sealed forever and tells DOJ to file a status report within 90 days. That's incredible.
Reposted by Adam Shostack
riana.bsky.social
If you've been following my six-month quest to unseal the search warrants for XiaoFeng Wang's homes, huge news:

I won.

storage.courtlistener.com/recap/gov.us...
storage.courtlistener.com
adamshostack.bsky.social
The Wikipedia entry about the ship of Theseus has been edited 2,052 since it was published in 2003.

Number of sentences from the original post that remain today: 0

Number of original graphics in this post: 0
mmasnick.bsky.social
Reposted with alt text. Also, from a cursory look, this appears to basically be true, which is pretty funny. Philosophers... debate.
Number of times the Wikipedia entry about the ship of Theseus has been edited since it was published in 2003: 2,052
Number of sentences from the original entry that remain today: 0