Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

adamshostack@infosec.exchangeA

adamshostack@infosec.exchange

@adamshostack@infosec.exchange
About
Posts
32
Topics
7
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • oh, it's so hard to take the high ground and pass this one up...
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @paul_ipv6 If you say so!

    (Also I HATE Mastodon's fake access control here.)

    Uncategorized

  • @adamshostack how is your experience with using LLMs or agentic AI for threat modeling?
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @d3tm4r I've blogged on this extensively, for example https://shostack.org/blog/lessons-from-owasp/ (and dig through the AI category) I haven't dug at all into the local/frontier model tradeoffs.

    Uncategorized

  • Also, 14,600 people are caught speeding 16 times or more in a year?!?!?!
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    RE: https://mastodon.social/@TheWarOnCars/116535905280214951

    Also, 14,600 people are caught speeding 16 times or more in a year?!?!?!

    Uncategorized

  • Free as in Tribbles: https://nesbitt.io/2026/05/07/free-as-in-tribbles.html
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @joshbressers @andrewnez

    - YouTube

    Auf YouTube findest du die angesagtesten Videos und Tracks. Außerdem kannst du eigene Inhalte hochladen und mit Freunden oder gleich der ganzen Welt teilen.

    favicon

    (www.youtube.com)

    Uncategorized

  • Free as in Tribbles: https://nesbitt.io/2026/05/07/free-as-in-tribbles.html
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @joshbressers @andrewnez What was the combination on the safe? 🤣

    Uncategorized

  • Free as in Tribbles: https://nesbitt.io/2026/05/07/free-as-in-tribbles.html
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @joshbressers @andrewnez Josh.

    Uncategorized

  • I, too, am confused about who the author thought their parents were, and a moment of thought was insufficient to help.
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    I, too, am confused about who the author thought their parents were, and a moment of thought was insufficient to help.

    Link Preview Image
    Larry Garfield (@Crell@phpc.social)

    Attached: 1 image The Oxford Comma is correct English. If you disagree, you're wrong. #English #Writing

    favicon

    PHP Community on Mastodon (phpc.social)

    Uncategorized

  • This is certainly the high-water mark for application naming!
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    RE: https://zeppelin.flights/@glennf/116517975867201431

    This is certainly the high-water mark for application naming!

    Uncategorized

  • I got an email notification e from my bank that they can’t deliver email to me.
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @thedarktangent This also means "our entity resolution software doesn't understand that you have bank272@secretdomain... set as your email address.

    Uncategorized

  • New blogpost:
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @neil huh! I hadn't paid close attention. I think that's a default in something in the 11ty stack we're using, but Im not sure.

    Uncategorized blog posse rss

  • New blogpost:
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @neil I've had a full text feed for 20 years. 🙂 http://shostack.org/feed.xml

    Uncategorized blog posse rss

  • Ubuntu has long been my go-to Linux distro for spinning up a virtual server: “easy, vanilla install just works, whatever, I don’t have to agonize over anything.”
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @inthehands I mean, a lot's going to depend on your dev platform needs.

    I've been meaning to ask @lattera if there's a recommended linode-like PaaS for BSDs?

    (Linode-like: cheap, ~$10/small server/month, easy backup, 1-2 pages of config to spin up a new machine, reverse DNS support. Ideally, not hated by spamhaus 🤣 )

    Uncategorized

  • Ubuntu has long been my go-to Linux distro for spinning up a virtual server: “easy, vanilla install just works, whatever, I don’t have to agonize over anything.”
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @inthehands I mostly used linux because linode made it easy. When I next build something it might be freebsd on aws or some other hoster.

    Uncategorized

  • If you were to buy a brand new car, regardless of type, would you be more or less inclined to buy a car that has no telematics and infotainment, i.e., an "unconnected" car, specifically for data privacy reasons?
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @Nonya_Bidniss I think your lead-in question and poll questions are contradictory.

    Uncategorized

  • Incredible.
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @mhoye If only someone could invent some sort of, I dunno, approach or something that giving a single process all the power? authority? capabilities? privilege? was a bad thing, and we should go for less, not more.

    Uncategorized

  • Incredible.
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @mhoye I'm so glad that the "written confession" can't itself be hallucinated. That's a nice feature!

    Uncategorized

  • Comet C/2025 R3 (PanSTARRS) is now putting on a show, visible low in the predawn sky, with binoculars or telescope.
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @AkaSci I’ve been busy, hadn’t tracked it, but this looks like decent info on how to try to see it: https://starwalk.space/en/news/comet-c2025-r3-panstarrs

    Uncategorized

  • If I'm a non-security-focused developer who realizes that I have a security requirement for my code, what's the best way to find defenses I might leverage?
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @letoams But that's not what I'm asking. I'm asking what is someone practically supposed to do, and I would love answers that are not "ask an LLM a question where the person can't evaluate the answers."

    Uncategorized

  • If I'm a non-security-focused developer who realizes that I have a security requirement for my code, what's the best way to find defenses I might leverage?
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @letoams ok, so where does it lead? 😀

    Uncategorized

  • If I'm a non-security-focused developer who realizes that I have a security requirement for my code, what's the best way to find defenses I might leverage?
    adamshostack@infosec.exchangeA adamshostack@infosec.exchange

    @hacksilon I agree with you -- I've found 'I need to address threat X on stack A, B, C. Don't write code, but give me strategies and tools' works remarkably well -- and that seems like abdication. Maybe abdicating is ok here?

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups