Dan Goodin's Avatar

Dan Goodin

@dangoodin.bsky.social

Cybersecurity Reporter, Ars Technica: https://arstechnica.com/author/dan-goodin/ Hungry for tips. Text me on Signal: DanArs.82. "The world isn’t run by weapons anymore, or energy, or money. It’s run by little 1s and 0s, little bits of data."

9,862 Followers  |  816 Following  |  107 Posts  |  Joined: 02.05.2023
Posts Following

Posts by Dan Goodin (@dangoodin.bsky.social)

Pitseleh
YouTube video by Elliott Smith - Topic Pitseleh

Pitseleh, or a ton of other stuff by Elliott Smith.

www.youtube.com/watch?v=Pg7y...

28.02.2026 03:09 — 👍 1    🔁 0    💬 0    📌 0
Preview
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises That guest network you set up for your neighbors may not be as secure as you think.

Excellent article on the work by @dangoodin.bsky.social: arstechnica.com/security/202...

I'd say we bypass Wi-Fi encryption, in the sense that we can bypass client isolation. We don't break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;)

26.02.2026 18:34 — 👍 8    🔁 7    💬 2    📌 0
Preview
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises That guest network you set up for your neighbors may not be as secure as you think.

That guest SSID you set up for your neighbors may not be as secure as you think

arstechnica.com/security/202...

26.02.2026 16:14 — 👍 8    🔁 5    💬 1    📌 1
Video thumbnail

This local Wolfdog joined an Olympic ski event and triggered the finish-line camera. This is Nazgul. He snuck into a cross-country skiing sprint this morning and raced the homestretch with some competitors before being escorted home. 14/10 someone get him a medal

18.02.2026 17:48 — 👍 23722    🔁 5067    💬 487    📌 641
Preview
Password managers' promise that they can't see your vaults isn't always true Contrary to what password managers say, a server compromise can mean game over.

The makers of password managers like Bitwarden, 1Password, Dashlane and LastPass promise they can't see your password vault. But that's not always true. A server compromise can mean game over for you, say researchers who examined some of the top password managers on the market

18.02.2026 18:24 — 👍 18    🔁 11    💬 2    📌 2
Preview
Password managers' promise that they can't see your vaults isn't always true Contrary to what password managers say, a server compromise can mean game over.

Contrary to what password managers say, a server compromise can mean game over.

arstechnica.com/security/202...

17.02.2026 21:46 — 👍 13    🔁 9    💬 0    📌 0
Preview
Password managers' promise that they can't see your vaults isn't always true Contrary to what password managers say, a server compromise can mean game over.

Contrary to what password managers say, a server compromise can mean game over.

arstechnica.com/security/202...

17.02.2026 21:46 — 👍 13    🔁 9    💬 0    📌 0
Preview
Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say Palo Alto Networks opted not to tie China to a global cyberespionage campaign the firm exposed last week over concerns that the cybersecurity company or its clients could face retaliation from Beijing...

Scoop: A report published last week outlined what Palo Alto researchers believed was a China-linked hacking campaign.

But after an intervention from execs, the report's language was changed to refer more vaguely to "a state-aligned group that operates out of Asia."
www.reuters.com/world/china/...

12.02.2026 18:25 — 👍 41    🔁 27    💬 4    📌 6
Preview
ICE Records Reveal How Agents Abuse Access to Secret Data Documents obtained by WIRED detail hundreds of investigations by the US agency into alleged database misuse that includes harassment, stalking, and more.

I filed this FOIA after publishing this investigation into ICE agents abusing law-enforcement databases. www.wired.com/story/ice-ag....

Those records are here:
airtable.com/appxK2tDF0YA...

09.02.2026 19:09 — 👍 23    🔁 14    💬 1    📌 0

If throngs of people handed over their IDs in exchange for a vanity blue check from a pro-authoritarian site, what reason is there to think Discord users won't do the same?

09.02.2026 19:28 — 👍 14    🔁 0    💬 0    📌 0
Preview
County pays $600,000 to pentesters it arrested for assessing courthouse security Settlement comes more than 6 years after Gary DeMercurio and Justin Wynn's ordeal began.

Two security professionals who were arrested in 2019 after performing an authorized security assessment of a county courthouse in Iowa will receive $600,000 to settle a lawsuit they brought alleging wrongful arrest and defamation.

arstechnica.com/security/202...

29.01.2026 19:57 — 👍 14    🔁 5    💬 1    📌 0

Trump’s federal thugs beat up on
His face and his chest
Then we heard the gunshots
And Alex Pretti lay in the snow, dead
Their claim was self defense, sir
Just don’t believe your eyes
It’s our blood and bones
And these whistles and phones
Against Miller and Noem’s dirty lies

(Full lyrics @ YT page)

28.01.2026 17:15 — 👍 12    🔁 4    💬 0    📌 0

Thanks for making sure we're aware of this. Our understanding is that Chrome on Android has started issuing these alerts. They're likely due to video players being embedded by ads that are trying to discover if Chromecast is available. This isn't just happening on Ars. We continue to investigate.

27.01.2026 19:16 — 👍 0    🔁 0    💬 0    📌 0

Thanks to @dangoodin.bsky.social for writing one of the few articles that actually questioned the @nytimes.com report.

19.01.2026 15:59 — 👍 1    🔁 1    💬 0    📌 0

No, I'm saying that before we can use the video as proof, the details I've mentioned though out this thread must be independently confirmed. Anyway, it doesn't sound like you and I agree on the burden of proof required to report a missile attack was responsible for the power outage. Peace & respect.

15.01.2026 19:13 — 👍 0    🔁 0    💬 1    📌 0

I assumed you had independently confirmed the gov's claims if you were pitching a whole story focusing on kinetic attacks. I've never liked the overly broad license news outlets give to unnamed sources, but if power was indeed restored hours later, I don't see how missiles could be responsible.

15.01.2026 18:58 — 👍 0    🔁 0    💬 2    📌 0

Yes, but when and where was the photo taken? Has anyone positively identified those crucial pieces of info? Assuming the video is authentic, did a cyberattack precede the missile attack? Statements from the Venezuela gov aren't confirmation. I can't find any independent confirmation.

15.01.2026 18:48 — 👍 0    🔁 0    💬 1    📌 0

I'm not saying missiles weren't used, but I'm looking for confirmation.

15.01.2026 18:27 — 👍 1    🔁 0    💬 1    📌 0

@metacurity.com Is there any independent confirmation of a kinetic attack? I don't see any mention of missiles or bombs in the first post Cynthia linked to, although the second does. The third appears to show damage to an electrical substation, but I can't tell where it is or when the video was shot

15.01.2026 18:26 — 👍 1    🔁 0    💬 1    📌 0
Conservatives Say Renée Good Was Brainwashed By Bible Into Loving Thy Neighbor

Conservatives Say Renée Good Was Brainwashed By Bible Into Loving Thy Neighbor

Conservatives Say Renée Good Was Brainwashed By Bible Into Loving Thy Neighbor https://theonion.com/conservatives-say-renee-good-was-brainwashed-by-bible-into-loving-thy-neighbor/

15.01.2026 16:30 — 👍 4729    🔁 972    💬 42    📌 31
Preview
Exclusive: US cargo tech company publicly exposed its shipping systems and customer data to the web Shipping tech company Bluspark left internal plaintext passwords, including those of executives, exposed to the internet, at a time when hacks in the shipping industry are on the rise.

New, by me: Security researcher Eaton Zveare spent weeks trying to alert a little-known but critical U.S. cargo tech giant that their shipping systems and customers' data were exposed to the web.

After weeks of trying, Zveare asked TechCrunch for help. We heard back! ...from the company's law firm.

14.01.2026 16:14 — 👍 59    🔁 25    💬 1    📌 2
Preview
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging Introducing Confer, an end-to-end AI assistant that just works.

The novel use of PassKeys to store the private key material is 👨🏻‍🍳💋

by @dangoodin.bsky.social

arstechnica.com/security/202...

13.01.2026 12:17 — 👍 5    🔁 1    💬 0    📌 0
Preview
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging Introducing Confer, an end-to-end AI assistant that just works.

Moxie Marlinspike—the engineer who set a new standard for private messaging with the creation of the Signal Messenger—is now aiming to revolutionize AI chatbots in a similar way.

arstechnica.com/security/202...

13.01.2026 16:42 — 👍 20    🔁 12    💬 2    📌 1
Preview
New York Attorney General Letitia James Threatens Legal Action Over Condé Nast's HR Firings | Video New York Attorney General Letitia James on Wednesday night threatened legal action against Condé Nast.

NY Attorney General Letitia James, speaking out against the illegal firings of 4 Conde Nast union members: “This is an injustice. Condé Nast, I’ll see you in court.”

www.thewrap.com/conde-nast-f...

13.11.2025 17:02 — 👍 5    🔁 0    💬 1    📌 0
"Flyer: Conde Nast union: Defend our rights Wednesday, Nov 12 6 PM Reinstate the Fired four." Four images of red fists raised in the air.

"Flyer: Conde Nast union: Defend our rights Wednesday, Nov 12 6 PM Reinstate the Fired four." Four images of red fists raised in the air.

In 15 minutes, NY AG Letitia James will participate in the Conde Nast union rally supporting the immediate reinstatement of 4 of our colleagues who were illegally fired in a union-busting move. If you're near WTC in Manhattan, please come and show your support.

12.11.2025 22:45 — 👍 12    🔁 2    💬 0    📌 0
Mastodon post (at: https://infosec.exchange/@dangoodin/115538605749075355)

Wow, the lack of ANY factual support for such a claim amounts to hyperbole. And from a CEO peddling a service to "guarantee content integrity." File this one under "Umbrella salesman predicts torrential rain."

https://www.wgcu.org/science-tech/2025-09-23/detection-expert-says-hackers-likely-used-ai-to-penetrate-airport-system

An airport employee points at a departure board after a cyber attack caused delays at Brussels International Airport in Zaventem, Belgium, Saturday, Sept. 20, 2025.
WGCU · Sep 23
Detection expert says hackers likely used AI to penetrate airport system
By Undetectable.ai/Special to WGCU
Nov 12, 2025, 12:26 PM
··
Web
18
boosts
·
0
quotes
·
37
favorites

Mastodon post (at: https://infosec.exchange/@dangoodin/115538605749075355) Wow, the lack of ANY factual support for such a claim amounts to hyperbole. And from a CEO peddling a service to "guarantee content integrity." File this one under "Umbrella salesman predicts torrential rain." https://www.wgcu.org/science-tech/2025-09-23/detection-expert-says-hackers-likely-used-ai-to-penetrate-airport-system An airport employee points at a departure board after a cyber attack caused delays at Brussels International Airport in Zaventem, Belgium, Saturday, Sept. 20, 2025. WGCU · Sep 23 Detection expert says hackers likely used AI to penetrate airport system By Undetectable.ai/Special to WGCU Nov 12, 2025, 12:26 PM ·· Web 18 boosts · 0 quotes · 37 favorites

Also, @undetectableai.bsky.social

12.11.2025 22:35 — 👍 2    🔁 0    💬 0    📌 0
Preview
Detection expert says hackers likely used AI to penetrate airport system As major airports across Europe have been targeted in a cyber-attack that began on Saturday, an expert is warning that artificial intelligence may have played a key role in the breach.The incident, wh...

As noted, @wgcunews.bsky.social has removed the post. Kudos for that, but journalism standards require an explanation. If any of you want to reach out directly, I'm happy to elaborate on the problems with these claims and why they can't be taken at face value:

web.archive.org/web/20250923...

12.11.2025 22:28 — 👍 7    🔁 0    💬 1    📌 0
Headline and byline:

Detection expert says hackers likely used AI to penetrate airport system

WGCU | By Undetectable.ai/Special to WGCU
Published September 23, 2025 at 9:23 AM EDT

Headline and byline: Detection expert says hackers likely used AI to penetrate airport system WGCU | By Undetectable.ai/Special to WGCU Published September 23, 2025 at 9:23 AM EDT

Dear @undetectableai.bsky.social: The comments attributed to your CEO, Christian Perry, in the WGCU post borders on quackery. There is 0 evidence AI is doing the things you say it is. Please stop spreading misinformation. Oddly, WGCU in Fort Meyers, Florida, has no removed the story. I wonder why

12.11.2025 22:21 — 👍 13    🔁 2    💬 1    📌 0

This fight is crucial to securing jobs. Please boost for reach.

12.11.2025 19:20 — 👍 6    🔁 0    💬 1    📌 0

ICYMI: 4 Conde Nast employees were illegally fired for exercising permitted speech in our workplace. Tonight, NY AG Letitia James will call out this union-busting move by our management. Please attend. Pls also sign our petition to reinstate our fired colleagues. actionnetwork.org/petitions/te...

12.11.2025 19:18 — 👍 19    🔁 6    💬 1    📌 0