Dan Goodin
dangoodin@infosec.exchange
<p>Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.</p>
Posts
-
Post #4247871
"A human who conducted such a hack would be facing years in prison. For a machine, criminal liability is harder to determine." https://www.newyorker.com/news/the-lede/inside-openai-hack-of-hugging-face
-
Post #4247826
TV sticks that offer free streaming services are turning people's tnternet connections into vehicles for fraud. https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
-
Post #4216802
A quantum-resistant cryptography algorithm that was under consideration to become an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken. https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/
-
Post #3152552
If it wasn't already, 2FA spraying is now a thing https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/
-
Post #3152551
You too can turn a Bluetooth device into a PC-pwning proxy https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/
-
Post #3088047
There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults. https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343 What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacke...
-
Post #3088046
Can’t make sense of Dashlane’s vault theft notification? You’re not alone. https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/
-
Post #2589000
Anybody know of any Linux distributions that have released fixes for Dirty Frag?
-
Post #2588999
Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past? https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/
-
Post #2588998
Can anyone help me find my AirTag attached keys? The FindMy app shows me their general location, which is a large public building where I last had them. When I go on site, my app is mostly unable to see them at all. Occasionally my app seems to be able to see a very weak signal but I can't seem to zero in on it. This is driving me nuts. I've looking now for two weeks. Anybody got tips?
-
Post #2588997
Are MP3 players even a thing these days? What are some good brands/models?
-
Post #2405711
In 2012, an industry-wide coalition of hardware and software makers adopted Secure Boot to protect against a long-looming security threat. The threat was the specter of malware that could infect the BIOS, the firmware that loaded the operating system each time a computer booted up. From there, it could remain immune to detection and removal and could load even before the OS and security apps did. To this day, key players in security—among them Microsoft and the US National Security Agency—regar...
-
Post #2246712
If you could ask any question to Mozilla concerning last month's The Zero-days are Numbered post, what would it be? https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
-
Post #2246711
There's a ton of skepticism over the true value of AI-assisted vulnerability discovery, and with good reason. Maybe the new details Mozilla has revealed don't tip the scales in favor of it being beneficial, but people should at least sift through them in good faith and with an open mind before declaring all of them bullshit. https://arstechnica.com/information-technology/2026/05/mozilla-says-271-vulnerabilities-found-by-mythos-have-almost-no-false-positives/
-
Post #2205567
Mastadonians wanting more security- and privacy-related content here: there are a bunch of journalists, researchers and engineers who are woefully underfollowed relative to the impact and importance of the work they do. Please follow and engage with them so they have a strong incentive to use this platform more. There are way too many to name all of them. In no particular order here are some (but sorry, not all; please look at the people I follow for more): @lhn @josephcox @jasonkoebler @ma...
-
Post #2173374
Mozilla has provided behind-the-scenes details on the 271 vulnerabilities it discovered with the help of Mythos. Those details include full Bugzilla reports on 12 of the vulnerabilities. I'd be curious for people to look at the reports and hear what they think. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
-
Post #1823770
Have any distributors/vendors released versions that fix CopyFail? If so, can someone help me compile with distributors and versions?
-
Post #1623137
Can someone explain @filippo's post to me like I'm a 5-year-old? https://words.filippo.io/128-bits/
-
Post #1544692
It's hard to overstate the importance of SSH in securing home networks, massive cloud centers and everything in between. Now, researchers have devised a novel cryptographic attack that breaks integrity of this widely used protocol. Dubbed Terrapin, it's the first-ever practical attack of its kind, and one of the very few attacks against SSH at all. Terrapin exploits weaknesses in the specification of SSH when paired with widespread algorithms (ChaCha20-Poly1305 and CBC-EtM) to remove an...
-
Post #1505762
With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo wants to make one thing perfectly clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-world/
-
Post #1432767
Signal Messenger is warning that Recall, the AI tool rolling out in Windows 11 that will screenshot, index, and store everything a user does every three seconds, poses a risk to its users. Effective immediately, the Windows Desktop version will by default block the ability of Windows to screenshot the app. Of course, Microsoft provides no API to disable Recall from screenshotting specific apps, so Signal is getting creative. They are invoking a digital rights management API that blocks the scree...
-
Post #1350145
Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.” https://arstechnica.com/security/2026/04/while-some-big-tech-players-accelerate-pqc-readiness-others-stay-the-course/
-
Post #938041
I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.
-
Post #932120
I'm trying to understand a bit more about CVE-2026-33579, the critical vulnerability in OpenClaw. To exploit, an attacker needs low-level paring privilege permissions. How does one acquire such privileges? Can anyone do it? I'm asking because I want to understand what's required for an attacker to exploit. Feel free to ping me at DanArs.82, or drop an answer here.
-
Post #782775
Google is dramatically shortening its deadline readiness for the arrival of Q Day, the point at which existing quantum computers can break public-key cryptography algorithms that secure decades’ worth of secrets belonging to militaries, banks, governments, and nearly every individual on earth. https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/
-
Post #768807
Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so. Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately. https://news.ycombinator.com/item?id=47501729
-
Post #760722
For more than four days, a server at the very core of the Internet’s domain name system was out of sync with its 12 root server peers due to an unexplained glitch that could have caused stability and security problems worldwide. This server, maintained by Internet carrier Cogent Communications, is one of the 13 root servers that provision the Internet’s root zone, which sits at the top of the hierarchical distributed database known as the domain name system, or DNS. Given the crucial role a roo...
-
Post #725106
I've been thinking a lot about the wide-spread anthropomorphism of LLMs in research, news articles and everyday conversations. I understand why it's problematic, but I wonder: why hasn't there been similar pushback on the decades-long practice of anthropomorphizing computers and software in general? It's common these days, for instance for people to say malware "tricks" an OS into doing stuff. Plenty of other examples as well. Why is one bad and the other OK?
-
Post #725105
If I hear one more person say that Beyonce isn't a real country singer/song writer and should stay in her own RnB/hip-hop lane I'm going to lose it.
-
Post #725104
Dear readers. If you're not willing to support the families of those you want to read then we regretfully will be preventing you from obtaining our work for free. https://infosec.exchange/@StefanThinks@beige.party/116199534759633586 https://infosec.exchange/@StefanThinks@beige.party