Allan Friedman
allanfriedman@infosec.exchange
<p><a href="https://infosec.exchange/tags/SBOM" class="mention hashtag" rel="tag">#<span>SBOM</span></a> Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, and occasionally getting paid for it. Poster of food pics.</p>
Posts
-
Post #4205741
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for how much of the software an hashtag#SBOM should actually cover. https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle
-
Post #4023159
A fun familiar name in today’s Catfishing game. What’s that? You don’t play Catfishing, the daily trivia game where you try to guess the Wikipedia article based on a curated list of the categories? If you are a trivia person, you should probably add this to your daily fun. https://catfishing.net Name blurred to avoid spoilers, although if you follow me you probably know it.
-
Post #3653218
An “omniBOM”? I had a blast recently chatting with my old friend @joshbressers@infosec.exchange about the proliferation of BOMs over the past few years, and how we need to think about them. I believe that they will eventually merge into one holistic “omniBOM.” However, we need to learn the lessons from the SBOM movement. Before we get to a completist solution, we’ll need to consider each independently to understand the technical- and business-specific use cases to build core data models that r...
-
Post #3570408
Does it even count as properly doing Maryland crabs by the Bay if you don’t feel like you need a shower after?
-
Post #2137701
Friends: in light of recent news, may I encourage you to get the Shingles Vaccine if you are eligible (over 50 or have immune system issues) and encourage others in your life to get it. Shingles took me out for two whole months last year and was incredibly painful. I still have intermittent nerve pain in my face that wakes me up in the middle of the night.
-
Post #1049199
I&#39;m embarrassed that we still need to say this, but: Trans rights are human rights. I have trans friends, and they are every bit as annoying and wonderful as all my other friends. Many of them are way better hackers. And we should all be annoyed that, in the US, even just flying through a major transit airport could be a real threat to their lives and wellbeing.
-
Post #1049198
A very happy birthday to everyone who spent time to pick something other than Jan 1 for their fake birthday! Many happy returns, and I hope you get a free ice cream cone somewhere. (Do they still do that?)
-
Post #1022343
Hi Friends! You have one week to submit to The Diana Initiative, an amazing infosec conference aimed at fostering more inclusive information security industry. I understand that they are particularly interested in Red Team talks, so please circulate to those who would be interested. https://sessionize.com/tdi-online-2026/ @DianaInitiative
-
Post #843408
If anyone is making the hard choice not to attend #DistrictCon because of the weather, I will happily buy your badge.
-
Post #843407
@risottobias ha! Glad I wasn’t the only one.
-
Post #843406
A gorgeous 2 mile walk across DC and the National Mall to make it to Day 2 of @DistrictCon and the entertaining keynote by Daniel Ridge. Feels pretty special… “hackers now a-bed Shall think themselves accursed they were not here,”
-
Post #843405
Table next to me at the coffee shop are senior firefighter policy folks talking about CERTs (community emergency response teams) and the language is similar enough to infosec that my ears won&#39;t stop firing cyber interrupts into my conscious brain.
-
Post #843404
Impressed by the new ZeroDayClock effort/collective/call highlighting that the window between vuln and exploit now must be assumed as t=0. The call to action is solid, though sadly nothing terribly new. Secure by design, adapt policies and practices. Liability, eridacate classes of vulns. https://zerodayclock.com
-
Post #843403
Tired: the meeting could have been an email. Wired: This email could have been both written and read by an LLM.
-
Post #843402
A nice moment in the McRary Institute Cyber Summit. Army Cyber Advisor Brett Pugh acknowledges that CISA and its hardworking expert staff are carrying on with their critical mission without getting paid. My former teammates are doing damn good work in a very rough time.
-
Post #843401
Heading off to @bsidessf ! (And the other conf) Hope to see you there.
-
Post #843400
“Shadow AI is like regular AI, but with cooler hair and music.”
-
Post #843399
Anyone know of research on how people “discover” new open source that they want to use? Does one search GitHub for strings relevant to what they are looking for? See code used in other projects? Are there other registries?
-
Post #843398
Last day of RSAC conference. Once more into the breach [response and recovery AI tooling sales talks]!
-
Post #743787
@k8em0 blows away @bsidessf by singing a very sarcastic “You’ll Adapt” to the tune of Hamilton’s “You’ll be back.” Her talk did not shy away from the potential human impact of a massive shift to automation, and the need to think about politics in this context.
-
Post #725720
Amazing opening keynote at @bsidessf by my old con buddy @bubblewire making the case for *optimism* in a very tumultuous time for the security community. Why to be optimistic? 1. “The Room where it happens” Security is now increasingly part of strategic institutional decision making. Beyond just tech to real influence. 10 years ago, who wanted hackers in the room? 2. We have learned to design for humans, not against them. 3. Started to focus on what actually moves risk. Real skepticism of r...