Adam Shostack :donor: :rebelverified:'s Avatar

Adam Shostack :donor: :rebelverified:

@adamshostack.infosec.exchange.ap.brid.gy

Author, game designer, technologist, teacher. Helped to create the CVE and many other things. Fixed autorun for XP. On Blackhat Review board. Books […] [bridged from https://infosec.exchange/@adamshostack on the fediverse by https://fed.brid.gy/ ]

118 Followers  |  1 Following  |  952 Posts  |  Joined: 10.05.2024  |  2.0489

Latest posts by adamshostack.infosec.exchange.ap.brid.gy on Bluesky

a headline showing I wrote the introduction last year

a headline showing I wrote the introduction last year

One of the hats I wear is editor for the @defcon Franklin Hackers' Almanack. If you see talks that policymakers should know about, please let me know here, tag me, etc.

I'm already seeing great stuff on voting security, resisting back doors, irresponsible […]

[Original post on infosec.exchange]

09.08.2025 14:59 — 👍 1    🔁 2    💬 0    📌 0
Preview
Hackers Went Looking for a Backdoor in High-Security Safes—and Now Can Open Them in Seconds Security researchers found two techniques to crack at least eight brands of electronic safes—used to secure everything from guns to narcotics—that are sold with Securam Prologic locks.

Big maker of electronic locks that go in safes is amazingly bad at its job, and so are a lot of the safe-manufacturing companies that use the locks.

https://www.wired.com/story/securam-prologic-safe-lock-backdoor-exploits/

09.08.2025 09:38 — 👍 2    🔁 35    💬 3    📌 0
Post image

The frenzied activity here at @defcon is just a sight to behold!

08.08.2025 16:50 — 👍 0    🔁 1    💬 0    📌 0
Original post on infosec.exchange

The "groundbreaking" NIST report is on... a hackathon where the devs are available?

The dream of the 90s is alive in the media.

"“If the report was published, others could have learned more information about how the [NIST] risk framework can and cannot be applied to a red teaming context,” […]

07.08.2025 14:10 — 👍 0    🔁 0    💬 0    📌 0
Preview
Tabletop Security Games + Cards The exhaustive list of cybersecurity tabletop games.

If you're at Blackhat and see interesting, physical #cybersecurity games at the business hall, please let me know. I enjoy collecting these games, and they're often limited editions.

https://shostack.org/games

06.08.2025 19:10 — 👍 1    🔁 0    💬 1    📌 0
Post image

This 40th anniversary special release of #phrack is amazing. If you’re at #blackhat or #defcon you should aim to get one.

06.08.2025 06:22 — 👍 2    🔁 4    💬 0    📌 0
Post image

This 40th anniversary special release of #phrack is amazing. If you’re at #blackhat or #defcon you should aim to get one.

06.08.2025 06:22 — 👍 2    🔁 4    💬 0    📌 0

I mean, other than the preceding quoted list items, and probably much more.

05.08.2025 20:12 — 👍 0    🔁 0    💬 0    📌 0

Certainly nothing for any technology company to learn from in any of this.

05.08.2025 20:12 — 👍 1    🔁 0    💬 1    📌 0
Original post on infosec.exchange

6) OceanGate’s failure to conduct a detailed investigations after the TITAN experienced mishaps that negatively impacted its hull and components during dives conducted prior to the incident,

7) OceanGate’s toxic workplace environment which used firings of senior staff members and the
looming […]

05.08.2025 20:12 — 👍 0    🔁 0    💬 1    📌 0
Original post on infosec.exchange

3) OceanGate’s
excessive reliance on a real-time monitoring system to assess the condition of the TITAN's
carbon fiber hull and then their failure to conduct a meaningful analysis of the data provided by
the system,

4) OceanGate’s continued use of the TITAN after a series of incidents that […]

05.08.2025 20:10 — 👍 0    🔁 0    💬 1    📌 0

The Coast Guard has released its investigation report on the Titan submersible implosion.

05.08.2025 19:55 — 👍 0    🔁 4    💬 1    📌 0
Preview
Sam Bowne & Team - Beginner's Guide to Attacks and Defenses - DCTLV2025 **4-Day Training** **Please note: This is a four-day training that will be held Saturday-Tuesday (August 9-12). Participants will receive a DEF CON Human Badge with their registration** Name of Training: Beginner's Guide to Attacks and DefensesTrainer(s): Sam Bowne, Elizabeth Biddlecome, Kaitlyn Handelman, and Irvin LemusDates: August 9-

There' still room in our @defcon Training event!

https://training.defcon.org/collections/def-con-training-las-vegas-2025/products/sam-bowne-team-beginners-guide-to-attacks-and-defenses-dctlv2025-4-day-training

05.08.2025 01:15 — 👍 0    🔁 2    💬 0    📌 0
Preview
BGDon (@BrentD@techhub.social) Attached: 1 image Thanks for the waste Elon! Research quantified in the here and now found that in just six months of operation, DOGE wasted more than $21 billion. https://www.rawstory.com/doge-2673797223/ #Musk #DOGE #Waste #Fail #Efficiency #USGov

This sort of fact oriented analysis has no place on social media!! https://techhub.social/@BrentD/114977128381040020

05.08.2025 16:46 — 👍 0    🔁 1    💬 0    📌 0
Linux Is Best (@Linux@mstdn.ca) More than 3,000 Boeing defense workers went on strike Monday after rejecting a revised contract offer, demanding better pay and work conditions. The walkout affects key facilities in Missouri and Illinois as Boeing grapples with financial woes and safety concerns. Source: https://www.france24.com/en/americas/20250804-enough-is-enough-thousands-boeing-workers-strike-pay-work-conditions #Union #Strike #Boeing

It’s worth remembering that Boeing moved its HQ and manufacturing from Seattle in the hopes that they could avoid unions. https://mstdn.ca/@Linux/114972413247625181

04.08.2025 23:29 — 👍 2    🔁 2    💬 0    📌 0
Preview
ChatGPT agent triggers crawls from Bingbot and Yandex ChatGPT agent is the recently released (and confusingly named) ChatGPT feature that provides browser automation combined with terminal access as a feature of ChatGPT—replacing their previous Operator research preview which …

Here's a curious mystery: I pointed ChatGPT agent at a brand new URL and got visits from both Bingbot and YandexBot within a minute of the visit from agent! https://simonwillison.net/2025/Aug/4/chatgpt-agents-agent/

04.08.2025 22:57 — 👍 5    🔁 3    💬 1    📌 0

@mmasnick.bsky.social Tesla has also claimed (to the ny times) that Florida has essentially eliminated punitive damages. Is that claim as accurate as the ones covered in the electrek article?

04.08.2025 20:34 — 👍 0    🔁 0    💬 0    📌 0
Page logo: SONICWALL

Title: Recommended Mitigation Steps.

Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions:

**1. Disable SSLVPN Services Where Practical**

Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.

Page logo: SONICWALL Title: Recommended Mitigation Steps. Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions: **1. Disable SSLVPN Services Where Practical** Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.

So the official SonicWall mitigation leads with "turn it off" ? ooooof.

04.08.2025 18:40 — 👍 3    🔁 5    💬 2    📌 0
Preview
European Commission (@EUCommission@ec.social-network.europa.eu) Attached: 1 image Have you heard of the 3-30-300 🌳 rule? Everyone should be able to: 🌲 See at least 3 trees from their home 🌳 Have 30% tree canopy cover in their neighbourhood 🍃 Live within 300 meters of a high-quality green space Trees help us cool down our towns in the summer, improve air quality and regulate the water cycle. That’s why The EU Biodiversity Strategy commits to planting at least 3 billion additional trees in the EU by 2030. Learn more ➡️ https://europa.eu/!RGwp7f

Freakin’ Europe really does like rules!

Remember, if you’re a landlord, you need to rebuild your buildings to meet this or pay a fine of 1% of global revenue.

😇 https://ec.social-network.europa.eu/@EUCommission/114947180829111076

04.08.2025 14:41 — 👍 0    🔁 0    💬 0    📌 0
Matt Blaze (@mattblaze@federate.social) We can make our elections trustworthy in spite of the inevitable security weaknesses in equipment! How? By using an architecture that *tolerates* security flaws instead of requiring you to eliminate them. This is called "Software Independence", formalized by Ron Rivest (the R in RSA) about 15 years ago. Ron is giving a talk at the Voting Village this year. Software Independence is achieved with something called "Risk Limiting Audits", invented by Philip Stark. Philip is also giving a talk.

This is a really interesting point: We can achieve security despite insecure components, if we know the outcomes we want to achieve.

Voting, which is usually a knot of requirements in tension, is a surprising place for this to emerge.

https://federate.social/@mattblaze/114961899333870131

03.08.2025 14:24 — 👍 0    🔁 3    💬 0    📌 0
Original post on federate.social

We can make our elections trustworthy in spite of the inevitable security weaknesses in equipment!

How? By using an architecture that *tolerates* security flaws instead of requiring you to eliminate them. This is called "Software Independence", formalized by Ron Rivest (the R in RSA) about 15 […]

03.08.2025 00:02 — 👍 7    🔁 1    💬 0    📌 0

@jik Sendgrid should absolutely do better at managing account close state. And I wonder if they have to keep the card on file for some period because of pci rules?

02.08.2025 15:34 — 👍 0    🔁 0    💬 1    📌 0
Post image

When I worked as a SGE for the White House ONCD we had to attend mandatory Hatch Act training. I just found my “Social Media Quick Guide” for what is permissible. Nowdays I bet it is quite different.

02.08.2025 02:59 — 👍 3    🔁 1    💬 0    📌 0
Post image

“I find your lack of font consistency disturbing!”

02.08.2025 01:01 — 👍 0    🔁 2    💬 0    📌 0

@JessTheUnstill See, and everyone's complaining about AI! 😂

01.08.2025 23:33 — 👍 0    🔁 0    💬 0    📌 0

You wanna know why the US economy hasn't already tipped into a huge depression?

AI.

Literally.

Megatech is throwing so much capital at AI it's legit keeping the economy afloat.

01.08.2025 20:34 — 👍 3    🔁 9    💬 4    📌 1
Original post on infosec.exchange

For the #wastewater fans, here is an informative primer on how the nationwide*] #covid #COVID19 wastewater data is collected, and the differences between the CDC's NWSS and WatewaterScan's data systems: [https://pandemics.sph.brown.edu/news/2025-01-23/wastewater-brief. Via Katelyn Jetelina.

[*] […]

01.08.2025 16:16 — 👍 0    🔁 2    💬 0    📌 0
Post image

“Where we’re going, we don’t need roads!”
#aviation #737 #manufacturing

01.08.2025 15:33 — 👍 0    🔁 2    💬 0    📌 0

The last Blue Angels pass was low enough to trigger the rain sensor on my skylight.

31.07.2025 19:15 — 👍 0    🔁 0    💬 0    📌 0
Original post on infosec.exchange

Are there sshd state machines? I'm looking for one that covers "root," "running as user" and "spawning shell"*?

I've found https://www.researchgate.net/figure/Abstract-description-of-SSH2-with-Diffie-Hellman-key-exchange_fig2_241880255 and Figure 5 of […]

30.07.2025 23:04 — 👍 0    🔁 0    💬 1    📌 0

@adamshostack.infosec.exchange.ap.brid.gy is following 1 prominent accounts