Gerald Benischke
@beny23.github.io
2.9K followers 880 following 960 posts
Maker, breaker and fixer of software. Adventures in #appsec and #agile: beny23.github.io he/him
Posts Media Videos Starter Packs
beny23.github.io
What about blinkered excitement and breathless skepticism? ;-)
beny23.github.io
I can also say with the utmost integrity that I had a joke about the CIA triad available. But it’s confidential so I can’t tell you.
beny23.github.io
You’ve just got to COMMIT to the joke
beny23.github.io
Things must be going well when you have to resort to sex to sell your stochastic parrot.
beny23.github.io
Not shocked by this after @tautology.uk’s keynote at @bsidesncl.bsky.social this year…
agreenberg.bsky.social
Researchers pointed a satellite dish at the sky for 3 years and monitored what unencrypted data it picked up. The results were shocking: They obtained thousands of T-Mobile users' phone calls and texts, military and law enforcement secrets, much more: www.wired.com/story/satell... 🧵👇
Satellites Are Leaking the World’s Secrets: Calls, Texts, Military and Corporate Data
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypte...
www.wired.com
beny23.github.io
Weeeelll, enjoy your blog traffic stats while it lasts ;-) both times I managed it, it dropped back to normal internet anonymity fairly quickly…
beny23.github.io
Spotted you on the orange site front page. Nice one.
beny23.github.io
Committed.

100,101,345 rows deleted.
impavid.us
In honor of spooky month, share a 4 word horror story that only someone in your profession would understand

I'll go first: Six page commercial lease.
Reposted by Gerald Benischke
malwarejake.bsky.social
If productivity gains with AI use were truly so large, orgs wouldn't be regularly asking me how to audit which staff are using AI vs not.

The only tool you should need is managers telling you who is 10%+++ more effective since you deployed the new AI tooling. Unless of course those claims are... 🤔
beny23.github.io
Meh, viewpoints 20 years out of date will just prepare them for the realities in the commercial sector ;-)
beny23.github.io
Great open source supply chain retro. Fondly (erm, not really) remember many of those!
filippo.abyssdomain.expert
To implement robust mitigations across Geomys, I did a survey of open source project compromises in 2024/2025.

Three root causes dominate: phishing, control handoff, and unsafe GitHub Actions triggers. All three can be systematically avoided.

words.filippo.io/compromise-s...
A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises
Project compromises have common root causes we can mitigate: phishing, control handoff, and unsafe GitHub Actions triggers.
words.filippo.io
beny23.github.io
Just like all the crypto mining infrastructure was reused. Wait what? ;-)
Image of burnt out bitcoin mining farm
Reposted by Gerald Benischke
robbowley.net
Some people are saying the potential overbuild because of AI might not be a bad thing because, like the dotcom era, it could leave behind infrastructure we’ll benefit from for a long time.

1/6
Reposted by Gerald Benischke
junoryleejournalism.com
David Simon, creator of ‘The Wire’, being interviewed by Ari Shapiro (NPR)
SHAPIRO: OK, so you've spent your career creating television without Al, and I could imagine today you thinking, boy, I wish I had had that tool to solve those thorny problems...
SIMON: What?
SHAPIRO: ...Or saying...
SIMON: You imagine that?
SHAPIRO: ...Boy, if that had existed, it would have screwed me over.
SIMON: I don't think Al can remotely challenge what writers do at a fundamentally creative level.
SHAPIRO: But if you're trying to transition from scene five to scene six, and you're stuck with that transition, you could imagine plugging that portion of the script into an Al and say, give me 10 ideas for how to transition this.
SIMON: I'd rather put a gun in my mouth.
Reposted by Gerald Benischke
jjaron.bsky.social
Honestly, when the financial press starts printing diagrams like this, isn't it time for a regulator to step in?