Adam Shostack :donor: :rebelverified:
adamshostack.infosec.exchange.ap.brid.gy
Adam Shostack :donor: :rebelverified:
@adamshostack.infosec.exchange.ap.brid.gy
Author, game designer, technologist, teacher.

Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board.

Books […]

[bridged from https://infosec.exchange/@adamshostack on the fediverse by https://fed.brid.gy/ ]
RE: https://hachyderm.io/@skinnylatte/115524200484374556

While this is fun, the temperature engineering subcommittee of the HOA has asked me to explain that a huuuuge amount of heat energy is visibly just bouncing off and people should not be trusted with a 3300 degree heat source.
November 10, 2025 at 5:36 PM
In these trying times, I'm glad to see this notebook still works for both men and women!

https://www.amazon.com/Journal-Hardcover-Notebook-Journals-Notebooks/dp/B0FDKZVFM8/
Amazon.com
www.amazon.com
November 10, 2025 at 4:22 PM
Doctor conferences get different door junk!
November 8, 2025 at 11:27 PM
RE: https://infosec.exchange/@SheHacksPurple/115516213748812207

I'm really glad this is no longer a conversation between me and Tanya!
infosec.exchange
November 8, 2025 at 10:57 PM
Publish your threat models? It's sparking debate. Join our discussion with OSTIF to talk about the benefits, dangers, and "why" of publication.

🗓️ Nov 12, 2pm CST 🔗 https://luma.com/zwsqlhs2
Threat Modeling w/ Adam Shostack · Zoom · Luma
Description Publish your threat models! This talk will cover the idea of publishing threat models, the dangers associated with the idea, and why open source…
luma.com
November 7, 2025 at 6:31 PM
@mattblaze if you haven't seen, some interesting numbers from a local paper

https://www.thestranger.com/news/2025/11/06/80313522/your-ballot-might-not-have-counted
Your Ballot Might Not Have Counted
As of blog time, King County Elections has challenged 4,119 ballots countywide because of signature-related issues including not signing the ballot at all or the signature not matching the one King County Elections has on file. In Seattle, 1,794 ballots aren’t being counted yet for similar issues. That’s only a little more than half a percent of the total ballots received—small, maybe, yet enough to make a difference in a tight race. by Nathalie Graham Last year, I was minding my own business, smug and confident because I’d bucked demographic trends and voted weeks before the election. Then, I got a text. King County Elections. An issue? With my ballot? It hadn’t been counted. I’d forgotten to sign the outside of my ballot. Fuck! The good news is I wasn’t the first illiterate dumbass to bypass simple instructions. And I am far from the last. This happens all the time (and have you _seen_ those reading scores?), including this cycle. As of blog time, King County Elections has challenged 4,119 ballots countywide because of signature-related issues including not signing the ballot at all or the signature not matching the one King County Elections has on file. In Seattle, 1,794 ballots aren’t being counted yet for similar issues. That’s only a little more than half a percent of the total ballots received—small, maybe, yet enough to make a difference in a tight race. Voters across all demographics are fucking up their signatures, but particularly the young people. Voters under the age of 35 account for 42 percent of the current challenged ballots. Surprisingly, the 25 to 34-year-olds are fucking this up more than the 18 to 24-year-olds with 428 challenged ballots. Though, not by much. The youths have 330 challenged ballots. Don’t get all high and mighty, elder millennials, the 34 to 44-year-olds also have 341 challenged ballots. You’re not “adulting.” You’re a mess. Just look at the state of you SCREENSHOT FROM KING COUNTY ELECTIONS All of your votes matter, of course, but they may really end up mattering in the race for Seattle mayor depending on how things shape up with ballot drops on today and tomorrow. Thankfully, this is an easy fix. First, figure out if your ballot was counted. If you wrote your phone number or email on the front of your ballot, King County Elections will drop you a line to let you know if there’s a ballot problem. You’ll also be notified of any problems if you signed up for ballot tracking. Fun fact: King County voters who tracked their ballots had a 63 percent voter turnout compared to 45 percent of county turnout in this election! But, if you haven’t signed up to track your ballot—which you can still do even after voting— _and_ you didn’t put any contact information on your ballot, King County Elections will mail you a notice letting you know there’s an issue. You can also check to make sure your ballot is counted by peeping at your voter portal. King County Elections will send a link to cure your ballot online. For me, that looked like signing my signature multiple times on an online form. If you do it by mail, you’ll do the same thing on a paper form and send it back to King County Elections to review. “We do see more voters use that online option,” Halei Watkins, communications director at King County Elections says. “It's very quick and easy. You get it done in like two minutes, and then you know it's taken care of, rather than filling out your form, waiting for us to receive it, and all of that.” Whatever method you choose to fix your ballot, you have until 4:30 p.m. on Nov. 24 to do so. And, for snail mail, that means your ballot-curing forms must be at King County Elections by then, not postmarked by then. According to Watkins, around 50 to 60 percent of challenged ballot voters respond and rectify their issues and their vote counts. The rest remain lonely, uncounted. Sad! Don’t be one of the uncounted few. Fix your shit.
www.thestranger.com
November 7, 2025 at 12:56 PM
twenty twenty twenty four hours to go....stop managing risk!

https://shostack.org/blog/stop-trying-to-manage-risk/
November 6, 2025 at 1:05 PM
Stop Trying To Manage Risk! That’s the title of my keynote for OWASP Global Appsec in Washington DC on Friday. And if you’re saying “WTF,” well, good. That’s the goal: to make you stop and think.

People hope risk management will solve all their cyber […]

[Original post on infosec.exchange]
November 6, 2025 at 2:58 AM
Reposted by Adam Shostack :donor: :rebelverified:
If you've been following the Castlevax mucosal #COVID #COVID19 vaccine development, you know that it has been looking like they lost US NextGen funding for their phase 2 trial in (one of the) the Trump cuts to biomedical research.

But today Castlevax announced that they are going ahead with a […]
Original post on infosec.exchange
infosec.exchange
November 5, 2025 at 2:12 AM
I have been reliably informed that as many in one in fifty or so of the ASPH attendees are masking. I regret the error https://infosec.exchange/@adamshostack/115483591518057581
Adam Shostack :donor: :rebelverified: (@[email protected])
The other conference at this hotel is .. checks notes.. the American Society of Public Health.. and I’m the only one in a mask.
infosec.exchange
November 4, 2025 at 12:56 AM
The other conference at this hotel is .. checks notes.. the American Society of Public Health.. and I’m the only one in a mask.
November 3, 2025 at 3:16 AM
Reposted by Adam Shostack :donor: :rebelverified:
And it here is! Thanks to a South Korean website, the worst kept secret can finally be seen.

The #lego Star Trek Enterprise NCC-1701-D, set 10356.

The model is 60cm long and consists of around 3600 bricks. If you buy it on release or a few days after, the […]

[Original post on mastodon.me.uk]
November 2, 2025 at 10:37 PM
Risk isn’t a hammer—and most problems aren’t nails.

I show why quantifying risk won’t fix cyber’s hardest decisions at USENIX '25.

🔨 https://tinyurl.com/4dj5mj3w
USENIX Security '25 (Enigma Track) - Risk Is Not a Hammer, and Most Hazards Aren't Nails
Risk Is Not a Hammer, and Most Hazards Aren't NailsAdam Shostack, Shostack + Associates"Risk management" has been given a privileged position in security, th...
www.youtube.com
October 31, 2025 at 5:04 PM
I don't know who needs to hear this, but if you do, "6/7" means "you're trying to hard."
October 31, 2025 at 12:44 AM
Having skimmed https://docs.fcc.gov/public/attachments/DOC-415190A1.pdf I now understand that a letter from a lawyer is a sufficient response to Salt Typhoon; that the FCC knows what constitutes "the agile and collaborative approach to cybersecurity that has proven successful"; why Chevron […]
Original post on infosec.exchange
infosec.exchange
October 30, 2025 at 11:46 PM
Reposted by Adam Shostack :donor: :rebelverified:
The FCC has published the text of the proposed order undoing its cyber requirements for telecoms, which will get a vote at next month's meeting: docs.fcc.gov/public/attac...

It says the requirements lacked legal standing and wouldn't be as effective as "an agile and collaborative approach."
October 30, 2025 at 10:59 PM
thanks! Sorry i missed that one.
October 30, 2025 at 11:35 PM
Reposted by Adam Shostack :donor: :rebelverified:
Austin Hackers Anonymous (AHA) is TONIGHT (2025-10-30) https://takeonme.org/ - Have some zero-day to share? AHA is an official CNA and will issue CVEs for vulnerabilities disclosed at the meeting. I'm planning to demo more SSHamble.com findings along with BloodHound OpenGraph stuff. See yall soon!
October 30, 2025 at 9:19 PM
If you're in Boston, Houston, Paris, or London, you should go see the Moonwalkers. Some notes start:

While in Boston, I had the chance to see “The Moonwalkers: A Journey with Tom Hanks,” and highly recommend it, not because I was wowed (I was) but because […]

[Original post on infosec.exchange]
October 30, 2025 at 8:53 PM
Jake Braun, who's my co-editor of the @defcon Franklin report has a new book, Fentanyl, Fighting the Mass Poisoning of America and the Cartel Behind It

Jake's had a long and illustrious career in government, including a stint as principal deputy at the Office of the National Cyber Director […]
Original post on infosec.exchange
infosec.exchange
October 30, 2025 at 6:57 PM
Reposted by Adam Shostack :donor: :rebelverified:
Like I said, I'm guessing that SpaceX just left the pieces in North Carolina, because there's no treaty that makes them deal with it in their own country.

A tale of 3 Crew Dragon Trunks. 3 totally different ways of SpaceX dealing with their (potentially lethal) garbage.

SpaceX and others are […]
Original post on mastodon.social
mastodon.social
October 30, 2025 at 4:18 PM
It’s a shame when American behavior drives apparently level headed commentators to write things like:

“That’s one thing we can do. Mr. Trump’s popularity is already dropping; anything we can do to help that along we should. The weaker he is domestically, the less latitude he has to do bad […]
Original post on infosec.exchange
infosec.exchange
October 29, 2025 at 3:54 PM
Get ready for your telco to demand more ID so they can leak it!

This will be accompanied by no reduction in spam calls from “your bank” https://mastodon.social/@therecord_media/115453323920478706
The Record (@[email protected])
Under the new FCC rule, telecom providers will be required to display a “verified caller name” as well as other data like a brand logo and reason for the call. https://therecord.media/fcc-adopts-new-rule-targeting-robocalls
mastodon.social
October 29, 2025 at 12:52 AM
Reposted by Adam Shostack :donor: :rebelverified:
Tickets for BSides Seattle 2026 are open

www.bsidesseattle.com
Bsides Seattle
Bsides Seattle Security Conference
www.bsidesseattle.com
October 28, 2025 at 6:17 PM
Trick or treat, D.C.! 🎃

Don’t get haunted by AI bugs—join our Threat Modeling Intensive at OWASP Global AppSec USA, Nov 3–5! 👻 https://tinyurl.com/4t4df2p7
Training Courses ⇽ OWASP 2025 Global AppSec USA (Washington, DC) | The OWASP Foundation Inc.
owasp.glueup.com
October 28, 2025 at 5:04 PM