Remote
Chief Executive Dysfunction Officer
If found, please return to nearest dumpster fire.
🏴 
227
Followers
292
Following
12
Posts
Joined November 06, 2022
/var/www:
Posts
Open post
Replying to
@Athena@chaosfem.tw
@Athena@chaosfem.tw @clarfonthey@toot.cat 'hol up, sorry for intruding here, but I kinda want to check something:
The anti-LLM folk working on this can't afford to take an anti-LLM stance in that thread, or it risks their jobs.
But now that the thread has been locked, the anti-LLM folk can't post in the thread anymore.
Is that not somewhat analogous to the status quo? If folk couldn't post their honest positions freely in the thread without risking their position, the thread being locked changes nothing.
Posting "diplomatically coached" responses to avoid outing yourself is not going to measurably affect the outcome of a policy discussion that is there for appearances only.
If Athena's extremely-mild post was enough to get it locked... then they were just looking for an excuse, and they were absolutely not interested in having a discussion. In case that wasn't already startlingly obvious from the preconditions.
You don't beat fascism by playing according to fascism's rules.
4
0
2
0
Open post
Replying to
@i0null@infosec.exchange
@i0null@infosec.exchange The internet is, after all, just a really big shared wobbly base.
Very wobbly.
1
0
0
0
Open post
Replying to
@Caution@tech.lgbt
@Caution@tech.lgbt Have at it mate. :)
No credit needed; I can't really claim it entirely anyway. It's a riff on the Long Term Nuclear Waste Warning Message: https://en.wikipedia.org/wiki/Long-term_nuclear_waste_warning_messages
0
1
0
0
Open post
Replying to
@Em0nM4stodon@infosec.exchange
@Em0nM4stodon@infosec.exchange "Legitimate interest" has become one of the most insidious and widely-misused phrases in the English language.
There is no legitimacy here. This database is not a place of honour. No highly-esteemed deeds will be accomplished with this data. What they do is dangerous and repulsive to us. This database is best shunned and left uninhabited.
10
2
6
0
Open post
Replying to
@JenMsft@mastodon.social
@JenMsft@mastodon.social Honestly, yesterday-me is a complete dickhead.
1
0
0
0
Open post
Replying to
@davidgerard@circumstances.run
@davidgerard
We present a proof-of-concept framework, Just Furnish Context (JFC)
Their acronym at least matches my response to this.
1
0
0
0
Open post
Replying to
@zackwhittaker@mastodon.social
@zackwhittaker I would deeply like for my bank to internalise this, but they're big enough to not care. My options for a ""mild"" security/privacy design issue with their app (the app's home screen – which lists account, personal, and financial details – is still shown unredacted in the OS recent-apps screen, even after exiting the app) is "private-only disclosure through Bugcrowd, which deems physical-access vectors as out-of-scope" or "talk to the LLM – which can only signpost you to Bugcrowd". That's it. There aren't even any branches left in my area (who, as you note, probably wouldn't know what to do with the information anyway. security.txt actually 403s (lol, lmao).
It's not a salacious breach, and companies this big have long been trying to make it as difficult as possible to speak to a relevant human (even before the genAI bubble). And so it will languish, unfixed and unnoticed by those outside of the industry.
With perhaps the exception of a few keen-eyed domestic abusers.
Thank you for coming to my xTEDx Rant.
1
2
0
0
Open post
Replying to
@slothrop@chaos.social
18
3
3
0
Open post
Replying to
@flyingpenguin@infosec.exchange
@flyingpenguin Outstanding. Thank you for doing the work to broadcast the signal on this. It does rather seem that it'll be one of those "just a small administrative change, nothing to see here" things that, in context, shows up as having a much longer, and thornier, tail than advertised.
1
0
0
0
Open post
Replying to
@flyingpenguin@infosec.exchange
@flyingpenguin
'scuse the readers-digest editing of your work, but I think that this is perhaps worth calling out as "the other shoe" – especially in light of NIST's recent & (with hindsight) interestingly-timed announcement that they will no longer enrich CVEs outside of the KEV/crit-list.
Anthropic ignores twenty years of security domain expertise and treats “finding vulnerabilities faster” as self-evidently dangerous. We all know the discovery rate has not been the constraint on vulnerability management for a decade. The constraint is triage, prioritization, patching velocity, and coordinated disclosure. A tool that accelerates discovery without accelerating remediation grows the backlog; it does not shift the threat model. Anthropic’s own stated justification for the entire Glasswing program is defensive uplift at partner organizations. The system card presents zero evidence of defensive uplift.
By withholding Mythos from general release and granting access only through the Glasswing consortium, Anthropic inserts itself as a de facto clearance-granting body for an “uplift” of vulnerability knowledge. The companies on the Glasswing list have every reason to love being inside the velvet rope. They get early access to a capability the rest of the industry does not. They get to shape disclosure timelines on their own products. They get to be the first to patch, and the first to know which competitors are exposed. They get a seat at the table of a body that now decides, on a rolling basis, which vulnerabilities are too dangerous for the public to know about.
1
3
0
0
Open post
Replying to
@davidgerard@circumstances.run
@davidgerard@circumstances.run Ooft, lads, that "we don't believe in opt-in because we don't know what it means" thing is a death-knell. Proper jumping in with the techbro PUA creep crowd there.
I'd say that's a pretty solid litmus test for when an OSS project has passed the point of no-return under its current governance. The project may technically remain "open-source", but the point of it being open-source in the first place has been entirely defeated.
Don't need to bother inspecting the source for malware when they're proudly blogposting their way through admitting that they've given the entire company over to the purveyors of malware-in-a-guy-fawkes-mask.
When the entire notion of consent gets reframed so much that they've torn the picture, done a serial-killer magazine montage with the text from it and, oooh, whadya know, it comes out saying "i tHe UnDeRsInEd Do HeArBy gIvE cOnCeNt FoR [eVrYtHiNg]", the source licensing becomes irrelevant. It's radioactive either way. It's just a matter of time before you start losing fingers and toes to it.
8
1
6
0
Remote instance
infosec.exchange
Open on original server