Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Allan Friedman

@allanfriedman@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, and occasionally getting paid for it. Poster of food pics.

0 Followers
0 Following
30 Posts
Joined November 10, 2022
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 4mo ago

Friends: in light of recent news, may I encourage you to get the Shingles Vaccine if you are eligible (over 50 or have immune system issues) and encourage others in your life to get it.

Shingles took me out for two whole months last year and was incredibly painful. I still have intermittent nerve pain in my face that wakes me up in the middle of the night.

160
36
147
7
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 5mo ago

I'm embarrassed that we still need to say this, but:
Trans rights are human rights.

I have trans friends, and they are every bit as annoying and wonderful as all my other friends. Many of them are way better hackers.

And we should all be annoyed that, in the US, even just flying through a major transit airport could be a real threat to their lives and wellbeing.

33
0
8
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

Amazing opening keynote at @bsidessf@infosec.exchange by my old con buddy @bubblewire@infosec.exchange making the case for *optimism* in a very tumultuous time for the security community.

Why to be optimistic?
1. “The Room where it happens” Security is now increasingly part of strategic institutional decision making. Beyond just tech to real influence. 10 years ago, who wanted hackers in the room?

2. We have learned to design for humans, not against them.

3. Started to focus on what actually moves risk. Real skepticism of rote vendor solutions. Better at calling bullshit and focusing on what solves real problem

4. Barrier of entry are lower. Abstractions allow more people to engage in security. Everyone can be a builder. We depend on creativity and experimentation. Security practitioners are becoming builders.

5. Legacy risk might finally be tractable! AI tools can read, understand, and transform the legacy cold bases. We can imagine burning down technical debt.

6. We can pave things from the start - new providers are thinking about security “with a heightened awareness” New AI leaders have invested in security. Not a first priority, but maybe second or third, rather than bolt-on.

We have managed massive transitions in the security space before (cloud native!).

She also reminds us that the entire security community is built on just that: community. We share, we build collaboratively, we rely on alliances and nonprofits and standards orgs.

9
0
9
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 7mo ago

Table next to me at the coffee shop are senior firefighter policy folks talking about CERTs (community emergency response teams) and the language is similar enough to infosec that my ears won't stop firing cyber interrupts into my conscious brain.

8
0
2
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

A nice moment in the McRary Institute Cyber Summit. Army Cyber Advisor Brett Pugh acknowledges that CISA and its hardworking expert staff are carrying on with their critical mission without getting paid.

My former teammates are doing damn good work in a very rough time.

6
0
5
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 5mo ago

A very happy birthday to everyone who spent time to pick something other than Jan 1 for their fake birthday!

Many happy returns, and I hope you get a free ice cream cone somewhere. (Do they still do that?)

5
0
1
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

Impressed by the new ZeroDayClock effort/collective/call highlighting that the window between vuln and exploit now must be assumed as t=0.

The call to action is solid, though sadly nothing terribly new. Secure by design, adapt policies and practices. Liability, eridacate classes of vulns.

https://zerodayclock.com

6
0
7
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 5mo ago

Hi Friends! You have one week to submit to The Diana Initiative, an amazing infosec conference aimed at fostering more inclusive information security industry. I understand that they are particularly interested in Red Team talks, so please circulate to those who would be interested.

https://sessionize.com/tdi-online-2026/

@DianaInitiative@defcon.social

4
0
9
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

Tired: the meeting could have been an email.

Wired: This email could have been both written and read by an LLM.

5
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 5mo ago

Anyone know of research on how people “discover” new open source that they want to use? Does one search GitHub for strings relevant to what they are looking for? See code used in other projects? Are there other registries?

4
0
4
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

“Shadow AI is like regular AI, but with cooler hair and music.”

3
0
1
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

@k8em0@infosec.exchange blows away @bsidessf@infosec.exchange by singing a very sarcastic “You’ll Adapt” to the tune of Hamilton’s “You’ll be back.”

Her talk did not shy away from the potential human impact of a massive shift to automation, and the need to think about politics in this context.

3
2
2
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 6mo ago

Heading off to @bsidessf@infosec.exchange ! (And the other conf) Hope to see you there.

3
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 4mo ago
Replying to @wendynather@infosec.exchange
@wendynather I love that this is the equivalent of the national cybersecurity agency under CRA.
2
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 4mo ago
Replying to @wendynather@infosec.exchange
@wendynather SBOM?
1
2
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 7mo ago

A gorgeous 2 mile walk across DC and the National Mall to make it to Day 2 of @DistrictCon@infosec.exchange and the entertaining keynote by Daniel Ridge.

Feels pretty special… “hackers now a-bed Shall think themselves accursed they were not here,”

2
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 7mo ago

If anyone is making the hard choice not to attend #DistrictCon because of the weather, I will happily buy your badge.

2
0
4
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 46mo ago
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange thanks, well said. I like to think the engagement we (or at least I) have had on social media has been beneficial to my mission (#SBOM !) and led to greater inclusion and more shared perspectives.
3
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 46mo ago
Replying to @longobord@infosec.exchange
@longobord@infosec.exchange @jerry@infosec.exchange LOL. Definitely being generated, with varying levels of completeness and quality, and tech / niche specialization. Starting to see tools and services to turn data into intelligence and thence to action.
2
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 5mo ago

Last day of RSAC conference. Once more into the breach [response and recovery AI tooling sales talks]!

0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 7mo ago

@risottobias@toot.risottobias.org ha! Glad I wasn’t the only one.

0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 4mo ago
Replying to @jscholes@dragonscave.space
@jscholes https://www.reuters.com/legal/litigation/us-fda-blocked-research-publication-that-covid-shingles-vaccines-are-safe-nyt-2026-05-05/
0
1
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 2mo ago
Does it even count as properly doing Maryland crabs by the Bay if you don’t feel like you need a shower after?
0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 2mo ago
An “omniBOM”? I had a blast recently chatting with my old friend @joshbressers@infosec.exchange about the proliferation of BOMs over the past few years, and how we need to think about them. I believe that they will eventually merge into one holistic “omniBOM.” However, we need to learn the lessons from the SBOM movement. Before we get to a completist solution, we’ll need to consider each independently to understand the technical- and business-specific use cases to build core data models that reflect utility, availability, and consistency. This, in turn, will catalyze ecosystems of tooling, automation, meaningful data use, and—yes—requirements and regs. Available wherever you lovingly hand-pick your artisinal audio content. https://opensourcesecurity.io/2026/2026-06-allan-omnibom/
0
1
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 1mo ago
A fun familiar name in today’s Catfishing game. What’s that? You don’t play Catfishing, the daily trivia game where you try to guess the Wikipedia article based on a curated list of the categories? If you are a trivia person, you should probably add this to your daily fun. https://catfishing.net Name blurred to avoid spoilers, although if you follow me you probably know it.
0
1
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 1mo ago
The SBOM minimum just got bigger. CISA and its international partners have released a substantially expanded Minimum Elements. It adds and clarifies most of the new fields from the 2025 CISA draft, and sets a far stronger expectation for how much of the software an hashtag#SBOM should actually cover. https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle
0
1
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 1d ago
Gonna be a good night…
0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 2mo ago
Replying to @christopherkunz@chaos.social
@christopherkunz@chaos.social @joshbressers@infosec.exchange haha, definitely. That’s a big part of why I think it’s useful to have a shared vision of the basics of each of these types of BOMs. Otherwise, we’ll end up with a bunch of implementations, many of which won’t be feasible with today’s tooling. See, e.g. tinyurl.com/aibompaper on exactly why and how to avoid this problem.
0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 1mo ago
Replying to @fedward@distraction.party
@fedward@distraction.party does not surprise me that you enjoy and are good at Catfishing.
0
0
0
0
Open post
Allan Friedman @allanfriedman@infosec.exchange
· 2mo ago
Replying to @mariuxdeangelo@infosec.exchange
@mariuxdeangelo@infosec.exchange @joshbressers@infosec.exchange it’s Denise has been overstated! We’re trying to coordinate something in the OpenSSF. Happy to chat more.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:52:47 UTC