Remote
Serge Droz
@sergedroz@infosec.exchange
323 Followers
391 Following
50 Posts
Joined October 29, 2022
Twitter:
WhatElse:
first.org
github:
Keybase:
Verification:
The whole AI mess in recent days made me think about @wendynather@infosec.exchange 's Security Poverty line. If it's true, that you now need an in-house LLM at your security teams command (->https://huggingface.co/blog/security-incident-july-2026) that line just went up dramatically.
I'm not anti AI, but I think we discuss the wrong questions.
Open post
Replying to
@ppossej@aus.social frankly, it wasn't AI that started this. It's HR departments acting on behalf of leadership who think older folks are unsuitable for numerous reasons, such as
Cost too much
Are not flexible
Don't know modern stuff
...
4
0
1
0
Open post
Replying to
@a@paperbay.org I'm glad your brought this up. Yes, there is a bit of an irrational anti AI sentiment in certain bubbles, confusing cause and effect. I guess you can use AI in stupid ways, but TBH I find it quite helpful.
I'm old enough to remember being told, that pocket calculators will cause the end mankind.
I can see a problem with ton's of vibe coded projects, that then are no longer maintained, but I don't think the solution is making vibe coding illegal.
3
0
1
0
Open post
@_dm@infosec.exchange @wendynather@infosec.exchange a recruiter having a multi year relationship to a person can actually deliver better services to companies hiring. These things exist. This doesn't imply the employee should pay for this, especially if you think about what that signals to the employee. I cannot see any good coming out of such an arrangement.
2
0
0
0
Open post
Replying to
@CuratedHackerNews maybe I'm overthinking this. But if the first tick box in a tech job is good pay, maybe the priorities are wrong all along.
I agree, pay needs to be good enough for a decent living. But for me tick box 1 is: is the job about something that I'm passionate about? If that disappears, I'm gone.
7
1
1
0
Open post
Open post
Replying to
@bert_hubert@eupolicy.social You seem rather cautious about using AI. I fully agree, that it's not clear what we will do with AI in a few years. That's a reason to try this out, and see where it's good and bad. That's, of course not the same as rolling it out organisation wide.
And I think people that talk about AI should actually have a bit of an idea what it does, something I don't see a lot.
And lastly, I think this field changes to rapidly for our current governance structures. So we should think hard about the goals of regulation and refrain from regulating specific tech.
And I have to disappoint you: I share the optimism and pessimism in your article.
1
0
0
0
Open post
Open post
RE: https://infosec.exchange/@LisaLobmeyer/116969361411938013
This sounds like a cool job, given the team lead.
Open quoted post
Quoting
My team @ @srlabs@infosec.exchange is growing. 🚀
We are looking for an experienced Forensic Analyst for our Blue Team. The ideal fit is a person that wants to dig deep into our clients' infrastructure to understand current attacker TTPs, somebody that wants to help build resilient IT environments by defending against current attack patterns and a true team player that helps clients prepare for or survive the worst case. And all of that can be done with amazing colleagues in an environment that fosters curiosity, growth while having fun together.
You know the game - if you know someone that knows someone - please send them this way.
https://security-research-labs.jobs.personio.com/job/2726007?language=en
Open quoted post 1
0
1
1
Open post
Replying to
@adulau Quantum Computing is the new block chain.
But let's face it: It's easier to babble about fuzzy threats than do something about existing ones, be this in IT-Security or Climate change. The former makes you important in a linkedin sense, the later is actually hard work.
5
0
1
0
Open post
Open post
Replying to on infosec.exchange
I'm involved in that. Make me sleep well again by submitting talks and registering. It's gonna be a cool event.
During Geneva Cyber Week, a FIRST Technical Colloquium titled Peak Incident Response will take place from 5–6 May 2026.
The event will focus on security and incident response for large-scale infrastructures and services, as well as the related policy implications.
We are currently seeking presentations on topics such as:
Operating large-scale services (e.g., DNS, BGP, NTP)
Defending against large-scale DDoS attacks
Coordinating incidents involving multiple stakeholders
Protecting shared and critical infrastructures
We warmly invite security professionals, incident responders, and policy makers with an interest in resilient digital infrastructure to join the discussions and share their perspectives.
More information about the event is available here: https://www.first.org/events/colloquia/geneva2026/
5
1
4
0
Open post
Replying to
@joebeone@techpolicy.social @sundogplanets@mastodon.social I guess it boils down to not junking up space.
3
0
0
0
Open post
Replying to
We have a preliminary program: https://www.first.org/events/colloquia/geneva2026/program
Join us for free in Geneva to talk about DNS, FOSS, large infrastructures and Incident response.
3
1
5
0
Open post
Replying to
@Di4na@hachyderm.io @bert_hubert@eupolicy.social it's not about hobby things. But running a document management system or an email/calenders system locally, be it for yourself or a large or does not need the cloud. It needs SRE to run it at scale. In many cases the cloud is about convince (and good sales) not feasibility.
I really suggest you read the quoted papers.
I think @bert_hubert@eupolicy.social is the last person to argue that "just install Linux" is the solution.
4
2
0
0
Open post
Open post
Replying to
@sophieschmieg This articlae say, you shouldn't take factoring as a good metric to measure progress, fair enough, but then you argue, in fact it's gonna be very soon we can factor. Isn't this a contradiction? THis is not a snarky remark. Personally I think QC is a risk, like there are many others. But I think there are biger, known risks.
And the store now decrypt later stuff I think is non-sense. Storing everything is not feasible, storing select stuff means you have a problem now, because some one ass already access to select important stuff. That boils down to a quote from Adi Shamir: NSA is not a crypto breaking agency, it's a crypto evading agency,
2
0
0
0
Open post
Replying to
3
0
2
0
Open post
Replying to
@adulau@infosec.exchange @jtk@infosec.exchange An important and for me, concerning topic. I do think though that we should refrain from confusing the current US administration with the us security community I admit some members from our community support the US administration, strange as it may seem.
To some extent more concerning to me is the feeling that our community has started to fragment way earlier. We stoped talking across borders (when was the last time you had a meaningful conversation with a Chinese team) and that's not only because of sanctions. National csirts seem to disengage, and the teams from big tech no longer participate. Of course this is not absolute, there are exceptions.
So our challenge seems twofold: Ensure the community is global and inclusive, and ensure we operate outside politics. And this implies working with folks you may not particularly like.
This is a difficult conversation, but one we need to have.
3
6
1
0
Open post
Replying to
@mho@social.heise.de @parismarx@mastodon.online thanks, it's good to visualize this. What do you think about adding cash unde payment options. I realize it's not tech, yet I increasingly go back to cash because I want to avoid us companies seeing how I spend money, and supporting them.
1
1
0
0
Open post
Replying to
@marasawr@mastodon.social so we need password managers that don't only suggest new passwords, but enter identities
10
1
3
0
Open post
Replying to
@adulau@infosec.exchange I guess because they are crawlers, and presumably No human ever looks at it. What I don't understand is why they download everything like 1000000 times.
If every foundational model would only download this once per month it would probably not be an issue.
1
0
0
0
Open post
Replying to
1
0
0
0
Open post
Replying to
@jrossstocholm @dansup I would agree with that, and it's a good article.
And let's face it:As of today individual fossile fuel Powers mobility et la are a far Bigger environmental threat. This AI is always bad retoric is as bad as the AI will bring heaven on earth one.
And I remember times where people said the exact same things about the internet.
1
0
0
0
Open post
Replying to
@CrimethInc@todon.eu Well, that's a bit romanticised, isn't it? This was probably true for wealthy white Europeans. Before 1914 war. It was only 1948 that slavery became illegal globally. And it was 1928 when the first attempt to make war illegal started (and failed -> WWII).
8
0
1
0
Open post
Replying to
@nohillside mir scheint, die FTP würde besser abschneiden, würde die NZZ aufhören sie zu unterstützen.
Das Blatt ist, mit wenigen Ausnahmen abgefahren.
1
0
0
0
Open post
Open post
Replying to
@rafi0t@social.yoyodyne-it.eu @adulau@infosec.exchange @jtk@infosec.exchange I think the challenge is where to draw the line. Only with ice directly? With it's host org (Goodbye CISA), with suppliers that make ICE possible (Goodbye most of us big tech), with operators that allow ice internet traffic (Goodbye Internet)?
This discussion keeps coming up. Should we only work with democracies? According to the economist there are only 25.
Number of people killed? Would that include all the drowned refuges?
It boils down to the fact, that the world is not two baskets of good and bad apples without interconnection.
What we can do is work for good. Again, these are difficult conversations, which won't have simple solutions.
1
2
0
0
Open post
Replying to
@adulau@infosec.exchange @jtk@infosec.exchange yep, and a reason might be that we lose our common vision. Making money is not a shared value, and neither is implementing a doctrine. Making the internet safe for all is a vision to be shared.
And fully agree: joint projects is the way to go.
1
4
0
0
Open post
Open post
Replying to
@CiaraNi@mastodon.green I'm in Switzerland. Don't get me wrong: I think there is little justification for personal cars in cities, and it's horrible what we sacrifice for cars in terms of space, pollution, noise etc. But I do have the feeling that a lot of cyclists have a similar mindset to car drivers that feel public space is their space. But public space is just that: Public, for every one.
I'm in Zurich, BTW
1
2
0
0
Open post
Open post
Replying to
@fedora@fosstodon.org I think people still underestimate RISC-V. We keep discussing high performance AI chips, but RISC-V is unencumbered by patents and works probably well for 95% of your daily compute needs: I am fairly sure it will be the defacto standard in a couple of years, so goodby to chip wars.
1
0
0
0
Open post
Open post
To buy the latest Swatch you have to fill out an ESTA: https://www.swatch.com/en-ch/mission-to-the-moon-1969-how-it-works.html ( Electronic Swatch Timepiece Application) :joy:
0
1
0
0
Open post
Replying to
@rafi0t@social.yoyodyne-it.eu @adulau@infosec.exchange @jtk@infosec.exchange I agree. I think the important thing you say is that the reason we collaborate needs to be clear, and that is what we should focus on: work with folks whose mission somehow aligns. I think ethicsfirst.org is a good start.
Would I answer a request from an ICE supplier about something I feel will be used to violate human rights: Nope! The same team asking info to take down a botnet. Yep.
Sometimes these are difficult discussions. At a former job. We had a group with reps from different business units that discussed cases. Interestingly we came to reasonable conclusions most of the time.
0
0
0
0
Open post
Replying to
@jullrich@infosec.exchange U agree with that. I disagree with the sentiment, that leaders will take twitter as an example.
0
0
0
0
Open post
Replying to
@lawrenceabrams@infosec.exchange Did you try this: https://www.first.org/members/teams/cert-mx
DM me if it doesn't work.
0
0
0
0
Open post
Replying to
@david_chisnall@infosec.exchange but you always had to show your passport, UK wasn't in Shenzhen, was it?
0
0
0
0
Open post
Replying to
We have the final program for the Peak Incident Response TC this comming May in Geneva: https://www.first.org/events/colloquia/geneva2026/program Join us for some great talks at this community organized conference. Top speakers, and a great opportunity to network.
0
0
0
0
Open post
Open post
Replying to
@CiaraNi@mastodon.green maybe we step back, because we know the bicycles won't stop i don't have a car and ride my bike every day, bit cyclists often are way ruder than cars
0
4
0
0
Open post
Open post
Replying to
@ross@fosstodon.org yes indeed, it describes everything that's wrong with the difference economy
0
0
0
0
Open post
Replying to
@nullagent@partyon.xyz @jack@mastodon.sdf.org To me it's not clear what this app does, in particular if it sends data back somewhere. That is the problem. That an OS regularly installs new components seems normal.
So once again, people complain about the wrong issues, and I feel this doesn't help, even if it is popular. It doesn't help, because Google can now say, all these complaints have nothing to do with reality, which is not wrong. But instead we should ask for more transparent and easily accessible info.
And I'm not saying this App is harmless. I just seem to have difficulties finding info about it.
0
0
0
0
Open post
Replying to
@hardingar@mindly.social @jullrich@infosec.exchange Yes, this is all true, and that's why you can quite a company. I just don't buy into the notion successful CEO == evil, selfish and dumb person. We only ever hear of the bad ones, and rarely of the good ones. Yet there are thousands of reasonably well governed companies.
I've worked in different places, and decided to leave because I didn't feel my employer's and my priorities align. For me the way you treat people or prioritize profit over well being matters. For others top salaries are more important than the type of work they do. That's fine, and it will determine how a companies does in the long run. Most of us in this industry are lucky enough to have the choice of seeking a different job easily.
TL;DR: Evil, profit driver CEOs ruin our lives and not understanding what it takes to run a company is just not a true statement in 99% of the cases.
I don't think many will follow Musk's example. But you have to give him, that he made Mastodon popular 🙂
0
0
0
0
Open post
It's an extra hot summer here. An operantly this happened a few weeks ago in Greenland: https://www.youtube.com/watch?v=UufMqwyO7pY It's quite mesmerising 😢
0
0
0
0
