Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Steve Bellovin

@SteveBellovin@infosec.exchange
  • Open on infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

4523 Followers
284 Following
50 Posts
Joined November 16, 2024
Home Page:
https://www.cs.columbia.edu/~smb/
Pronouns:
He/Him
Photography-only account:
@urbandinosaurs@urbanists.social
License:
All of my photos available via a Creative Commons BY-NC license: http://creativecommons.org/licenses/by-nc/4.0/

Posts

Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · 3d ago
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @dan@mastodon.durrans.com
@dan@mastodon.durrans.com @cigitalgem@sigmoid.social I figure they got suspicious of people coming from LAS wearing hoodies…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · 5d ago
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to on mastodon.laurenweinstein.org
@lauren@mastodon.laurenweinstein.org Hence the patent…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 07, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @thefunnypages@mastodon.social
@thefunnypages@mastodon.social @jack_daniel@mastodon.social I feel seen.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 07, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @olaf@social.secret-wg.org
@olaf@social.secret-wg.org @aka_pugs@mastodon.social And a rotary dial phone at that…
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 05, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to on elefanti.co
@adam@elefanti.co @20002ist@thepit.social I'm reminded of the refugee ship St. Louis (https://encyclopedia.ushmm.org/content/en/article/voyage-of-the-st-louis)
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 04, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Trains, of course, have restrooms. (I believe that this work train is on a track for the Purple Line, a light rail line under construction in the Maryland suburbs of DC.)
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 03, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @karlauerbach@sfba.social
@karlauerbach@sfba.social Well, a tale told on behalf of an idiot…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 03, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @karlauerbach@sfba.social
@karlauerbach@sfba.social The new document is immunity for past transgressions for only Trump and a few others. But critics say that it isn't legally binding: https://www.nytimes.com/2026/08/03/us/politics/todd-blanche-trump-irs-fund-loopholes.html?smid=url-share&smid=nytcore-ios-share&rsrc=cl-share
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 02, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social @joebeone@techpolicy.social Or look on https://bidenwhitehouse.archives.gov
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Aug 02, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social @joebeone@techpolicy.social There was a very energetic effort sponsored by the Biden White House on software liability, examining all sorts of issue surrounding it. For "some reason", that effort vanished about 1.5 years ago…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 31, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @wendynather@infosec.exchange
@wendynather@infosec.exchange I've never tried quite that. I have worked on securing what AT&T called "operational support systems" (OSS), the many computers that tend and feed the phone switches, plus the so-called "adjunct processors" that help the actual switches. Let me put it like this: it's a nightmare. None of these systems were built for today's environment, and they can't easily be upgraded. And if you tried to reimplement them, you'd definitely introduce far more bugs, including security bugs, than you removed. OSSes do things like associating a physical wire or fiber with a "trunk" to another switch. How many OSSes do you think AT&T has? Your guess is almost certainly too low. And adjunct processors? Suppose you dial an 800 (internationally a "free phone") number. That has to get translated to an actual phone number, and appropriate billing stuff handled. That is *not* done by the switch; rather, the switch does (in effect) an RPC call to the adjunct processor, which does the hard stuff (including the database lookup) and returns the answer to the switch. One last thought: back in the 1990s, I used to say that the Internet was becoming the data equivalent of the phone network. I no longer say "is becoming"—it is. Build your phone network lately, including what is known as "outside plant", i.e., the wires on poles or in conduits? Build your own high-capacity, production-ready switch? No, phone switching is not done today the way it was done when I joined AT&T in 1982, but apart from the fact that a lot of the complexity is inherent to the problem, you still have to interoperate with legacy gear, unless you're also building your own handsets, etc. (During a meeting in, I think, 1996, on how to do a completely "greenfield" design for a new phone switch, I completely blew a Bellhead's mind by suggesting that 800 numbers be implemented as a distributed database and cryptographically signed reverse-charge tokens…)
22
1
6
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 31, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
RE: https://flipboard.com/@newyorktimes/world-5f2k3dqjz/-/a-pCnP_INfSNOk69c9sBFwbw%3Aa%3A3195393-%2F0 Look, @sundogplanets@mastodon.social
Quoting
The New York Times @newyorktimes@flipboard.com
A Ton of Space Junk Tumbles Unpredictably to Earth Every Week https://www.nytimes.com/2026/07/31/world/asia/space-debris-earth.html?utm_source=flipboard&utm_medium=activitypub Posted into World @world-newyorktimes
Open quoted post
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 31, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
RE: https://infosec.exchange/@agreenberg/117011022100893459 I've been expecting this. The US attacks Iranian water systems; Iran attacks US systems.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 31, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @paris@hachyderm.io
@paris@hachyderm.io @thedarktangent@defcon.social @eff@mastodon.social This is not new—I first heard of it ~25 years ago. Drivers' license scanners were originally created to help catch fake IDs; the benefits to bars, given liability issues, ar obvious. But some brands *marketed* themselves with their ability to capture other data, to help create a customer database for targeted ads, etc. See, e.g., p 59 of https://www.nationalacademies.org/publications/10656 (Disclaimer: I was on the committee that produced the report.)
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 30, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @fgbjr@indieweb.social
@fgbjr@indieweb.social Plus farting in their general direction, of course.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 30, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @cryptomancer@fediverse.cryptomancer.de
@cryptomancer @CryptoOrrDun@ioc.exchange Yes, 7 rounds, and no, it doesn't scale even to 10 rounds, let alone 14. Attacking weakened versions of ciphers is a standard analytic technique—and sometimes a variant of the attack on a weakened version will scale up and sometimes it won't. (A fair number of years ago, there was a decent attack on a weakened version of Skipjack, an NSA-designed cipher. I showed that to someone I knew who had NSA contacts. His reply: "You call it worrisome; I call it good engineering." To my knowledge, no one has ever been able to scale it up to the full cipher.)
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @sundogplanets@mastodon.social
@sundogplanets@mastodon.social If you want, you're more than welcome to use this very amateur photo as an example. I took it in Death Valley (a dark sky area) in mid-January of this year, and it shows *6* satellite tracks. (50mm, f/1.8, ISO 2800, 3 seconds, slightly enhanced to show all 6 tracks). I hate to think what a longer exposure would show!
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mattblaze@federate.social
@mattblaze@federate.social @karlauerbach@sfba.social Only my own, as best I recall.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @karlauerbach@sfba.social
@karlauerbach@sfba.social @mattblaze@federate.social I've only testified once, and my mother got very upset when she heard I was going to—her model for people testifying before a Congressional committee was HUAC or McCarthy's committee, where people were compelled to testify and either abase themselves, incriminate themselves, or take the Fifth. I had to reassure her that this was not that sort of committee, and that testifying was an honor.
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @bontchev@infosec.exchange
@bontchev@infosec.exchange Yup, I boosted it this morning.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @agreeable_landfall@mastodon.social
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange Ross and others.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @agreeable_landfall@mastodon.social
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange In a production system, probably—but in a research setting where you're challenging an LLM to break the cryptosystem? I doubt it. Besides, HSMs are often not as secure as they should be, per research done at Cambridge University.
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 29, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @agreeable_landfall@mastodon.social
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange What concerns me is a Kobayashi Maru sort of scenario, where instead of finding a crack in an algorithm the LLM hacks the researchers' accounts and steals the file with the secret key or the plaintext, all unknown to the researchers.
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social Think of it as an improvement to the NY Times.
2
3
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange I'm old enough to remember when the Right was claiming that FEMA was planning on rounding people up. It's always projection…
32
0
4
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @cryptomancer@fediverse.cryptomancer.de
@cryptomancer I follow @CryptoOrrDun@ioc.exchange here… That LLMs should find bugs in crypto libraries is utterly unsurprising at this point. But these results are about the algorithms, which is much more interesting.
3
1
1
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
RE: https://flipboard.com/@newyorktimes/home-page-91uottdbz/-/a--1AFgpJbRrygQyybRU2ysA%3Aa%3A3195393-%2F0 Are any *technical* details on this available?
13
7
14
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @darkuncle@infosec.exchange
@darkuncle@infosec.exchange @mattblaze@federate.social And we lost Peter Neumann just a few weeks ago…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 28, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to on federate.social
@mattblaze@federate.social A classic case. See https://www.newscientist.com/article/1818118-technology-sorry-no-numbers-the-day-the-uss-telephone-network-crashed/ and https://catless.ncl.ac.uk/Risks/9.63.html#subj3.1 — and https://catless.ncl.ac.uk/Risks/9.69#subj5 for the precise bug: misuse of a a 'break' statement. The salient points: it was a flaw in error recovery code, which was triggered if and only if while a phone switch was rebooting, it received two incoming call requests within 1/100 second. In the aftermath, AT&T started classes in the proper use of 'break' statements…
Technology: Sorry, no numbers - The day the US's telephone network crashed | New Scientist
New Scientist

Technology: Sorry, no numbers - The day the US's telephone network crashed | New Scientist

IT WAS fortunate for AT&T, operator of the world's most sophisticated communications network, that 15 January is a holiday in the US - in remembrance of

0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to on threads.net
@jswatz_tx Also grifting.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @adamshostack@infosec.exchange
@adamshostack@infosec.exchange @briankrebs@infosec.exchange @hal_pomeranz@infosec.exchange Interesting. I don't think the swelling was any worse than the other times I've been stung, but it doesn't take a lot of tongue swelling to threaten one's airway.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @Teri_Kanefield@mastodon.social
@Teri_Kanefield@mastodon.social Interesting thread, since I'm currently mulling if I should find an agent for a book I'm working on…
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mikeloukides@hachyderm.io
@mikeloukides@hachyderm.io @briankrebs@infosec.exchange Yup. After calling my doctor—my tongue was starting to swell up—it was off to the local urgent care center for injections of a steroid, to reduce the inflammation, and an antihistamine, to deal with the allergic reaction. The latter put me right to sleep…
4
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @briankrebs@infosec.exchange
@briankrebs@infosec.exchange Sounds bad, though perhaps not as bad as the time one flew into my mouth while I was bicycling and stung my tongue…
9
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 27, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @jtk@infosec.exchange
@jtk@infosec.exchange Alas, no. I looked for it a fair number of years ago but it was long gone. I remember how it worked and could probably reconstruct it, but it was a) too slow to be usable for production, and b) not secure, even by the standards of 1979, since it couldn't be setuid. It was a prototype to let us rapidly experiment with the protocol design, since back then on my department's PDP 11/45, compiling even a small program too a long time. I rewrote it in C (also long gone), once the protocol was set, but it was missing a few essential features, too. The first release version was a completely new version by Steve Daniel. The basic idea was that the set of newsgroups you subscribed to was a shell environment variable which could include shell meta characters, most notably * if you wanted to read everything. 'Find -newer' found articles newer than a 0-length dot file; 'ls -i | sort | uniq' was used to show cross-posted articles only once. But yes, I wish I still had it!
3
0
1
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 26, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @nixCraft@mastodon.social
@nixCraft@mastodon.social @cstross@wandering.shop The first version of Netnews (https://www.cs.columbia.edu/~smb/papers/netnews-hist.pdf) was a 150 line Bourne shell script, but had multiple newsgroups and cross-posting…
9
1
4
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 25, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
RE: https://flipboard.com/@newyorktimes/new-york-bat3un55z/-/a-TfouDAImTVaqT-uRVBqrow%3Aa%3A3195393-%2F0 Cue the uncanny valley
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 25, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mattblaze@federate.social
@mattblaze@federate.social @20002ist@thepit.social "Do you advocate overthrowing the government of California by force or violence?" "Is that a multiple choice question?"
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 25, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mattblaze@federate.social
@mattblaze@federate.social @20002ist@thepit.social You get to read that one… (I did notice that I had quoted the 1950 version.)
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 25, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social @mattblaze@federate.social Being an inveterate nerd, I decided to actually read the Geneva Convention (https://www.ohchr.org/en/instruments-mechanisms/instruments/geneva-convention-relative-treatment-prisoners-war) The answer is rather unclear… Article 13 says "prisoners of war must at all times be protected". Article 14 says "Prisoners of war are entitled in all circumstances to respect for their persons and their honour" and "Prisoners of war shall retain the full civil capacity which they enjoyed at the time of their capture. The Detaining Power may not restrict the exercise, either within or without its own territory, of the rights such capacity confers except in so far as the captivity requires." And then it gets interesting… Article 82: "A prisoner of war shall be subject to the laws, regulations and orders in force in the armed forces of the Detaining Power"—what are the rules regarding bugging of members of the US armed forces? I have no idea what those laws are. And then there's Article 92: "Article 88, fourth paragraph, notwithstanding, prisoners of war punished as a result of an unsuccessful escape may be subjected to special surveillance. Such surveillance must not affect the state of their health, must be undergone in a prisoner of war camp, and must not entail the suppression of any of the safeguards granted them by the present Convention." What is "special surveillance"? How does it differ from ordinary surveillance? Does the latter include bugged premises?
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 24, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mattblaze@federate.social
@mattblaze@federate.social For the former, I suspect one has to look at the Geneva Conventions; for the latter, I'd guess yes, unless barred by the former
0
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 24, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
RE: https://flipboard.com/@newyorktimes/home-page-91uottdbz/-/a-VdgkV6NZSMSSlraEqwBP2g%3Aa%3A3195393-%2F0 This is really scary and worth reading.
Quoting
The New York Times @newyorktimes@flipboard.com
This Is What’s Keeping Me Up at Night https://www.nytimes.com/2026/07/23/opinion/trump-midterms-fraud-corruption.html?utm_source=flipboard&utm_medium=activitypub Posted into Home Page @home-page-newyorktimes
Open quoted post
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 23, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @grumpybozo@toad.social
Possible minor spoiler on the new Odyssey movie Hover or focus to reveal Sensitive
@grumpybozo@toad.social Ya think so?
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 23, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @DaveMWilburn@infosec.exchange
re: Possible minor spoiler on the new Odyssey movie Hover or focus to reveal Sensitive
@DaveMWilburn@infosec.exchange Mmm… To my (rather limited) knowledge, there's no definitive consensus on who they were, though Greek tribes are one candidate. (The Wikipedia article says that all of the known references were Egyptian, not Greek, and that one story indicates that at least some of them were probably not Greek.)
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 23, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @grumpybozo@toad.social
Possible minor spoiler on the new Odyssey movie Hover or focus to reveal Sensitive
@grumpybozo@toad.social Interesting; I hadn't known of Hesiod's list; thanks! Hesiod's timing is roughly equivalent to that of Homer, so it would not have been an improbable mention in the Odyssey, but the Trojan War was several hundred years earlier, which makes the phrase anachronistic coming from Odysseus.
1
1
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 23, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @mattblaze@federate.social
Possible minor spoiler on the new Odyssey movie Hover or focus to reveal Sensitive
@mattblaze@federate.social Downtown Silver Spring, about .4 miles from the Metro station.
0
0
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 23, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Possible minor spoiler on the new Odyssey movie Hover or focus to reveal Sensitive
I went to see the Odyssey movie (in IMAX) last night. It's an impressive film, though far too loud. It stayed reasonably close to the epic poem, though with a few (largely unimportant) changes, like the role and timing of the lotus flower incident. There were a few glaring anachronisms, notably the repeated references to the Sea Peoples and (far worse) Odysseus' reference to the "Age of Bronze". What was most interesting to me was the philosophical focus of the movie around Zeus' Law (roughly: be kind and hospitable to strangers; if you're such a guest, respect your host) and how that permeated the whole movie. I won't say more, for fear of thematic spoilers, but I found it quite noticeable, and not just in the obvious place, and quite interesting. The cinematography was superb; so were the special effects. Anyway: highly recommended, and though you don't need to be familiar with the source material it helps. (I don't see many movies in theaters; oddly enough, as best I recall the last one I saw before this one was Nolan's "Oppenheimer".)
0
3
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 21, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @paul_ipv6@infosec.exchange
@paul_ipv6@infosec.exchange @20002ist@thepit.social @wendynather@infosec.exchange @mattblaze@federate.social @fuzzface@epsilon-ix.masto.host @SecureOwl@infosec.exchange It was in NJ—Bell Labs Murray Hill. I never learned the origin of the two levels. My guess is that the deeper section was built first, and when the machine room was expanded it was perceived that there was no need for such depth, perhaps because they no longer had those giant IBM bus and tag cables.
0
2
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 21, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social @wendynather@infosec.exchange @mattblaze@federate.social @fuzzface@epsilon-ix.masto.host @SecureOwl@infosec.exchange A friend in another building spotted mice in his office (but of usual size), so he used a live trap and put a couple in a cage in his office. The Facilities people were upset, so he pointed out that he didn’t bring the mice there, and if they didn’t want mice in his office they should do something. They were not amused, so he offered to just open the cage door and let them go back where he had caught them. They were even less amused by that…
0
2
0
0
Open post
SteveBellovin
Steve Bellovin @SteveBellovin@infosec.exchange · Jul 21, 2026
Steve Bellovin
@SteveBellovin@infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

infosec.exchange
Replying to @20002ist@thepit.social
@20002ist@thepit.social @wendynather@infosec.exchange @mattblaze@federate.social @fuzzface@epsilon-ix.masto.host @SecureOwl@infosec.exchange In one place I worked in Bell Labs, the under-floor space had two levels. I pulled a tile over the deeper section—and found that it was filled with water… Fortunately, there were no cable joins or thick yellow Ethernet cable vampire taps in that area, so no harm was done.
0
3
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:28:10 UTC