<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-16T15:28:04Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Rob O :verified:</title>
  <author>
    <name>Rob O :verified:</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1hq3hx0nkk5l2gtp3ec00q9sf64pyxzvma9tkxg5350qt2qljfgqssgpxge.rss" />
  <link href="https://yabu.me/npub1hq3hx0nkk5l2gtp3ec00q9sf64pyxzvma9tkxg5350qt2qljfgqssgpxge" />
  <id>https://yabu.me/npub1hq3hx0nkk5l2gtp3ec00q9sf64pyxzvma9tkxg5350qt2qljfgqssgpxge</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/246/145/114/116/303/original/2bb49d72eac9372c.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/246/145/114/116/303/original/2bb49d72eac9372c.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqs0wtj3z9vgjxk8ln7z2j8420urdur3z8eymzz6f9x0xhededvlpvszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzgt92dt</id>
    
      <title type="html">So, the argument seems to be that acceleration of attacks (and, I ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0wtj3z9vgjxk8ln7z2j8420urdur3z8eymzz6f9x0xhededvlpvszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzgt92dt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswamwlw7frmjha4n6zfx2gjxfsew8emegcwljfdnyye5rflf8ppscx23ps0&#39;&gt;nevent1q…3ps0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;So, the argument seems to be that acceleration of attacks (and, I assume, increased success rate) necessitate higher levels of automation. The HTB success rates, in particular, are what seem to be raising alarm bells from those on the practicioner side.&lt;br/&gt;&lt;br/&gt;The argument is, roughly, that IF we&amp;#39;re about to be inundated by an influx of highly skilled red-team agents,  THEN we need blue team agents in the loop that are capable of responding with similar speed. &lt;br/&gt;&lt;br/&gt;That strikes me as reasonable logic. I&amp;#39;m not sure I&amp;#39;m willing to grant the antecedent at this point, but the structure of the IF-THEN strikes me as rational.&lt;br/&gt;&lt;br/&gt;Or maybe we could just turn all the computers off and throw them out of whatever window is nearest.
    </content>
    <updated>2026-04-21T21:05:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv4zshnewgsqe4vvkn23f84s280xanmzh3f96gdhkcnkty0r4e9dszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzsjcx5d</id>
    
      <title type="html">Which, just to put a bow on the conversation, seems to be the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv4zshnewgsqe4vvkn23f84s280xanmzh3f96gdhkcnkty0r4e9dszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzsjcx5d" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr5qnh8n93337awgnakdx3uqs3st02lhw5ecz3zzwythehxukdrfcky92es&#39;&gt;nevent1q…92es&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Which, just to put a bow on the conversation, seems to be the point of both pieces. &lt;br/&gt;&lt;br/&gt;If you accept their premise about attack speed accelerating (not sure I do,.but it *is* a reasonable hypothesis), then it&amp;#39;s probably time to actually get those things done... And to do that at a fast enough pace, one probably needs agents (and the restrictions outlined).
    </content>
    <updated>2026-04-21T19:20:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstqg8t3evcvuk4ys7mvza5cdyh4cgsg3wx7k2msxj09dl3gq2w3wgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzauxaq9</id>
    
      <title type="html">One of my hotter professional takes is that cybersecurity is no ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstqg8t3evcvuk4ys7mvza5cdyh4cgsg3wx7k2msxj09dl3gq2w3wgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzauxaq9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq0k6z2gkc5wvyqjluueyzpakw8nq4ldfq40xvq60kxumyl6tp7rcu984ez&#39;&gt;nevent1q…84ez&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One of my hotter professional takes is that cybersecurity is no longer a fast-moving industry and that we&amp;#39;ve had a pretty solid notion of how to do security right for at least a decade. &lt;br/&gt;&lt;br/&gt;Our problems these days are more about making sure those things get done than in figuring out what the right thing to do is.
    </content>
    <updated>2026-04-21T17:04:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspageatwwu7dwtuuczw2g4xsxa78hq97uqrzkcfdq8csm4ppx225szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzuj0jju</id>
    
      <title type="html">I agree, but what are the chances at getting a substantive ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspageatwwu7dwtuuczw2g4xsxa78hq97uqrzkcfdq8csm4ppx225szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzuj0jju" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrldj8tdwt0pr6zmnq09qvy9llda7xje7mefpgx00zs5kkmv5dqeqdefrf8&#39;&gt;nevent1q…frf8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I agree, but what are the chances at getting a substantive regulatory framework or product liability regulations in this space?&lt;br/&gt;&lt;br/&gt;I&amp;#39;m using &amp;#34;engineering&amp;#34; as shorthand for design/implementation since, as we all know, most of what tech does really shouldn&amp;#39;t be called engineering.&lt;br/&gt;&lt;br/&gt;There&amp;#39;s a few interesting nuggets in there, though. In addition to &amp;#34;The boring basics like asset management, least privilege, and network segmentation really do matter&amp;#34;, the relative importance of penetration testing (declining), detection engineering (increasing), and the shift towards &amp;#34;assume you&amp;#39;re compromised&amp;#34; all strike me as reasonable points.
    </content>
    <updated>2026-04-21T16:44:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgmg9xu2ts7eyfwetul0p6ewz7ccm3fklyqdzv8cte8nkhgdsax0qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qztk8hs8</id>
    
      <title type="html">The argument that both pieces seem to be putting forward is that ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgmg9xu2ts7eyfwetul0p6ewz7ccm3fklyqdzv8cte8nkhgdsax0qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qztk8hs8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv29jnyv55cp8m9n8ckngpevu2lxch5rj4leyuxxnwy3ghpwtjrdcp8jn9e&#39;&gt;nevent1q…jn9e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The argument that both pieces seem to be putting forward is that they expect attackers, in the future, to be leveraging AI/LLMs to increase the pace of attacks to a point where will no longer be feasible for humans to play the same role in the incident response loop that they currently play.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m not sure I accept that, but it&amp;#39;s a clear hypothesis that be tested for correctness with data. It&amp;#39;s also not rooted, as you say, in happier vibes.&lt;br/&gt;&lt;br/&gt;The set of controls proposed by both appear to differ (I only skimmed the one you posted). Mubix&amp;#39;s piece focuses on two attributes, one of actions and one of agents.&lt;br/&gt;&lt;br/&gt;Agents need to have minimally constrained scope (so, least privilege applied to agents). The set of actions they are permitted to take should also only be actions that are reversible. The rest of the document outlines engineering best practices that absolutely need to be in place (and, as we know, often aren&amp;#39;t) in order to facilitate those.
    </content>
    <updated>2026-04-21T16:33:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrjutgjusft9sz34lmutysqkqlsg4jj74rvgny8ywjfsd8u6jls0czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzmydm78</id>
    
      <title type="html">That said, a non-trivial amount of the recommendations of both ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrjutgjusft9sz34lmutysqkqlsg4jj74rvgny8ywjfsd8u6jls0czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzmydm78" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg5gvjsree5twhmx9557lz7nnxlyumlacx9673plfcg3v7wnlns2qv6cvfn&#39;&gt;nevent1q…cvfn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;That said, a non-trivial amount of the recommendations of both are, in z nutshell, &amp;#34;Get your act together and finally do the basics right.&amp;#34;
    </content>
    <updated>2026-04-21T16:17:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg5gvjsree5twhmx9557lz7nnxlyumlacx9673plfcg3v7wnlns2qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qznjgn4v</id>
    
      <title type="html">Ehhh, the CISO to current practitioner ratio is low, but ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg5gvjsree5twhmx9557lz7nnxlyumlacx9673plfcg3v7wnlns2qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qznjgn4v" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr3wglf92ecesn43krptey95l6n03h4yfp4f04vruxw49qkd806sqk6kwdt&#39;&gt;nevent1q…kwdt&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Ehhh, the CISO to current practitioner ratio is low, but there&amp;#39;s definitely folks on there from a practitioner background. It also echoes many of the same points as the ones Mubix made here:&lt;br/&gt; &lt;a href=&#34;https://infosec.exchange/@mubix/116415117902139733&#34;&gt;https://infosec.exchange/@mubix/116415117902139733&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I haven&amp;#39;t drunk the proverbial KoolAid, but I find interesting that both position papers are a) providing reasonably precise (and testable) hypotheses about how they are anticipating the threat landscape will change over the medium term and b) describing reasonably precise control sets needed to mitigate that risk (as well as the risk caused by the technical debt accrued by the lack of oversight of past AI investments).&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/note1kzd4aewuhpvpyulexdpsygmxgd2hwkw63lnp6t5a2pa5tg83rp6qx7w4l8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;note1kzd…w4l8&lt;/a&gt;&lt;/span&gt;&lt;br/&gt; &lt;/div&gt; Made a thing about Mythos and what companies need to do about it (like everyone else on the planet). I think where mine sticks out is giving some practical, “you can start this tomorrow” advice:&lt;br/&gt;&lt;br/&gt;“The Day-Zero Normal”&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.linkedin.com/posts/mubix_the-day-zero-normal-by-rob-fuller-activity-7450542077001662464-6o6X&#34;&gt;https://www.linkedin.com/posts/mubix_the-day-zero-normal-by-rob-fuller-activity-7450542077001662464-6o6X&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-04-21T16:14:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsggnur8tfawdnkq069ys7fvgphvuf39x3jeutcdm6crkjw8qvzwgczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzsp57j3</id>
    
      <title type="html">It&amp;#39;s almost like having an &amp;#34;engineering&amp;#34; discipline ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsggnur8tfawdnkq069ys7fvgphvuf39x3jeutcdm6crkjw8qvzwgczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzsp57j3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvemrh4r430j42aqkkfhzhyqyjyhyh3ly4ql2ygjhhjxn4320dewcs008w7&#39;&gt;nevent1q…08w7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;It&amp;#39;s almost like having an &amp;#34;engineering&amp;#34; discipline with little in the way of professional liability is a bad thing.
    </content>
    <updated>2026-04-14T15:35:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8sdtmajz3k9pphg4zkemxv0mh2mhxe82w3a9sc0jvxc5ca8tle7szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qztv9jre</id>
    
      <title type="html">*sigh* Mythos messaging is starting to hit regular people. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8sdtmajz3k9pphg4zkemxv0mh2mhxe82w3a9sc0jvxc5ca8tle7szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qztv9jre" />
    <content type="html">
      *sigh* Mythos messaging is starting to hit regular people. I&amp;#39;ve already had to explain twice, now, how Mythos isn&amp;#39;t going to decrypt all network traffic.&lt;br/&gt;&lt;br/&gt;This is exhausting.
    </content>
    <updated>2026-04-13T18:21:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0tr6fzqgh6xf8ckaugedvthvfjclza9elmmxnpf2gj4y9zpmx5kszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzr2q4vc</id>
    
      <title type="html">I get the sense that the economy has a lot of folks feeling very ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0tr6fzqgh6xf8ckaugedvthvfjclza9elmmxnpf2gj4y9zpmx5kszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzr2q4vc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspl46ahtxp6rjljw6hcxzgn7jn70wn3uc6h4mapfpw05swu0u4ffcxng7pc&#39;&gt;nevent1q…g7pc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I get the sense that the economy has a lot of folks feeling very french. Late 1700s french.
    </content>
    <updated>2026-04-10T19:42:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgx23m4yfur7r24u3rynh5l3ek9288ja2zmd0llep3sgz3h4enh5gzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz9z9ppk</id>
    
      <title type="html">Oh god, think about all the InfoSec techbros that are about to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgx23m4yfur7r24u3rynh5l3ek9288ja2zmd0llep3sgz3h4enh5gzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz9z9ppk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszkjelxyujt56g274lgrzad9xun95wvwxxhcppargnfdy6mkusx3sgtlv2n&#39;&gt;nevent1q…lv2n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Oh god, think about all the InfoSec techbros that are about to become experts in astrophysics.
    </content>
    <updated>2026-04-10T15:57:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv3nhc3trndxtu5xp7eyx8fhvvtyxejzd60ugutrrrsn4jzlhhwzczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz7sklqg</id>
    
      <title type="html">I&amp;#39;ve also wondered, to some extent, how much of this is the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv3nhc3trndxtu5xp7eyx8fhvvtyxejzd60ugutrrrsn4jzlhhwzczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz7sklqg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgwafmvffdynyr5cf3rxdnq2auvgkg04zmz66ek8wfy9q793md6jgzgqq0h&#39;&gt;nevent1q…qq0h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve also wondered, to some extent, how much of this is the result of &amp;#34;main character syndrome&amp;#34;, for lack of a better phrase.&lt;br/&gt;&lt;br/&gt;People want to believe they&amp;#39;re doing something wild, exciting, and innovative. So much of cybersecurity, however, is glorified accountancy, tradesman (plumbing/electrical/etc), and janitorial work.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s hard for folks to wrap their head around the fact that their jobs are much more like that of the folks in Office Space than V from Cyberpunk.
    </content>
    <updated>2026-04-10T14:22:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszttgdsk3ymz26q98w3u5uzm6v30pdezq2tvf4yxdx4tltcn78lkczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzl40n0u</id>
    
      <title type="html">Incidentally, I really wish there were better tools for teaching ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszttgdsk3ymz26q98w3u5uzm6v30pdezq2tvf4yxdx4tltcn78lkczyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzl40n0u" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp6q79gdfh4739da6qwr96mrykw4n85ry3znt73znm9d0a9fyhhrs5cj3zf&#39;&gt;nevent1q…j3zf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Incidentally, I really wish there were better tools for teaching about this kind of thing.
    </content>
    <updated>2026-04-09T15:36:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8g6pqnalgsy7t45aqq2vhs8qz2gus2y4acph57dt4mlpucwuyy0czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz4yz2yz</id>
    
      <title type="html">I suppose we&amp;#39;ll see. Given the unreliability of US foreign ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8g6pqnalgsy7t45aqq2vhs8qz2gus2y4acph57dt4mlpucwuyy0czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz4yz2yz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgd26wvkgjn8nl7e27r99rxnp09j2wcaf9luur8n2pmgae7w3wg2ssdqtjf&#39;&gt;nevent1q…qtjf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I suppose we&amp;#39;ll see. Given the unreliability of US foreign and security policy, we&amp;#39;ve seen other sectors shift away from American produced goods. Notably, the auto industry. &lt;br/&gt;&lt;br/&gt;I would think that some countries (Denmark, for example) might be wondering if it&amp;#39;s time to shift technical infrastructure away from US goods too. Hasn&amp;#39;t there been some of this happening in the cloud space already?&lt;br/&gt;&lt;br/&gt;I imagine the primary problem here is the lack of alternatives in the router space.
    </content>
    <updated>2026-03-24T15:34:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0njk5zk5v4360afc9ul897mffzqzsk9wemz8x9x283cn6lv2j33szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz60jld3</id>
    
      <title type="html">RE: https://mastodon.neat.computer/@jonah/116284778632962494 I ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0njk5zk5v4360afc9ul897mffzqzsk9wemz8x9x283cn6lv2j33szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz60jld3" />
    <content type="html">
      RE: &lt;a href=&#34;https://mastodon.neat.computer/@jonah/116284778632962494&#34;&gt;https://mastodon.neat.computer/@jonah/116284778632962494&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I wonder how freaked out Cisco and Palo Alto are right now about the possibility of retaliatory actions.&lt;br/&gt;nostr:note1euvpufmyle0e6el77937y5t862hg7wkja4nn9jdyher770udhneq9sjhya&lt;br/&gt;
    </content>
    <updated>2026-03-24T15:18:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxk4uhut99m45gqv5292ysa07w3ayxepwyqq08wapmgfvqtr48e8qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzwls78n</id>
    
      <title type="html">&amp;#34;Malicious pickle de-serialization&amp;#34; sounds like something ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxk4uhut99m45gqv5292ysa07w3ayxepwyqq08wapmgfvqtr48e8qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzwls78n" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstvp37dq69ljhny7yg9ycxupusymnhamel6nf4dy5085y6uy942ygjux5qz&#39;&gt;nevent1q…x5qz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;&amp;#34;Malicious pickle de-serialization&amp;#34; sounds like something from Law and Order SVU.
    </content>
    <updated>2025-10-06T16:23:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx4vqkfpsuq9pc3lnrul8gt4f8425dmh0y398nsupf8c8rxc087rgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzykeqy8</id>
    
      <title type="html">One of the most accessible Def Con talks I attended was this one: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx4vqkfpsuq9pc3lnrul8gt4f8425dmh0y398nsupf8c8rxc087rgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzykeqy8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxa9s9xnkytsgw7ya05r2dd9kzlgpvdwtjjn88nd6furpnxsplhssgvy7zf&#39;&gt;nevent1q…y7zf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One of the most accessible Def Con talks I attended was this one:  &lt;a href=&#34;https://www.youtube.com/watch?v=F1VttfQFTWE&#34;&gt;https://www.youtube.com/watch?v=F1VttfQFTWE&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Sounds like things haven&amp;#39;t changed all that much.
    </content>
    <updated>2025-09-23T15:57:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfrkltky3cch0rfu84ysz58tfxrkpry0nyvl9gn25fac7r5xx3u5czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz4dtsuw</id>
    
      <title type="html">So, this was blocks away from where I lived for like 6 years. ICE ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfrkltky3cch0rfu84ysz58tfxrkpry0nyvl9gn25fac7r5xx3u5czyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz4dtsuw" />
    <content type="html">
      So, this was blocks away from where I lived for like 6 years. ICE was (mostly) chased away and someone apparently slashed their tires, in one of the most affluent neighborhoods in the city.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.wxxinews.org/local-news/2025-09-09/ice-agents-in-the-park-ave-neighborhood-spark-large-scale-protest&#34;&gt;https://www.wxxinews.org/local-news/2025-09-09/ice-agents-in-the-park-ave-neighborhood-spark-large-scale-protest&lt;/a&gt;
    </content>
    <updated>2025-09-09T22:47:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw3va2drklvedqglx7v9k7mxe5walm26jk2txpy2r7ahhusls408qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz8fz4qx</id>
    
      <title type="html">All I see here is &amp;#34;Ran a human subjects experiment without an ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw3va2drklvedqglx7v9k7mxe5walm26jk2txpy2r7ahhusls408qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz8fz4qx" />
    <content type="html">
      All I see here is &amp;#34;Ran a human subjects experiment without an IRB.&amp;#34; Why are these &amp;#34;researchers&amp;#34; still employed?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.404media.co/researchers-secretly-ran-a-massive-unauthorized-ai-persuasion-experiment-on-reddit-users/&#34;&gt;https://www.404media.co/researchers-secretly-ran-a-massive-unauthorized-ai-persuasion-experiment-on-reddit-users/&lt;/a&gt;
    </content>
    <updated>2025-04-29T22:16:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspdmphsav6ecway8ra4zmgcvzhdgakncq9869zrmfjqtxg28yw2fszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzgcce89</id>
    
      <title type="html">I see applications in RPGs. Imagine Skyrim or Baldurs Gate ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspdmphsav6ecway8ra4zmgcvzhdgakncq9869zrmfjqtxg28yw2fszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzgcce89" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw6ue009a2fasrzqvmuyy6kqmqrndt6z88wzsgthnsp9r385zz9psq0m5kl&#39;&gt;nevent1q…m5kl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I see applications in RPGs. Imagine Skyrim or Baldurs Gate without canned dialogue. That said, the replay value of those games would skyrocket, probably hurting sales of other games. On the ethical side, compensation for voice actors would be a problem.
    </content>
    <updated>2025-04-07T13:31:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy2umyawp80fj40xkm42jjxy8jukj3nhrxqfntyghjn6ql6384mzszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzs4nml8</id>
    
      <title type="html">I used to teach quite a lot of courses that covered ethics as it ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy2umyawp80fj40xkm42jjxy8jukj3nhrxqfntyghjn6ql6384mzszyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzs4nml8" />
    <content type="html">
      I used to teach quite a lot of courses that covered ethics as it applies to technology. This was, to honest, my gateway into security. &lt;br/&gt;&lt;br/&gt;One of my favorite discussions was &amp;#34;What software would you refuse to write?&amp;#34;&lt;br/&gt;&lt;br/&gt;I think about that *a lot*.
    </content>
    <updated>2025-02-18T20:16:31Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd97s8hs3s84rdgjdxf3ravyvgjcjg4jtzy8c79heh688jm76877szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzphh9k4</id>
    
      <title type="html">Friend, I think you have far too high of an opinion about ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd97s8hs3s84rdgjdxf3ravyvgjcjg4jtzy8c79heh688jm76877szyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzphh9k4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8gw474xzc0jw844400dml6uuksmgutnuttsaan8ykcj5sucn8y2gxmcza0&#39;&gt;nevent1q…cza0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Friend, I think you have far too high of an opinion about university administrators. A few things:&lt;br/&gt;&lt;br/&gt;1) Most universities are schools attached to hedge funds by way of the endowment. In most schools, the person with the most practical power on campus isn&amp;#39;t the president or the board, it&amp;#39;s the CFO/VP for Finance/&amp;lt;insert similar title here&amp;gt;.&lt;br/&gt;&lt;br/&gt;2) US universities can be held hostage with the threat of withholding financial aid money. Suppose there&amp;#39;s a threat: &amp;#34;Remove diversity or you can&amp;#39;t receive student loans/pell grants&amp;#34;. Without that income, most universities wouldn&amp;#39;t be able to make payroll. There might be a delay by a semester or two while operating budgets are shuffled around and there are massive layoffs, but that&amp;#39;s the ballgame. They&amp;#39;d be relying on research funds and money from their foundation.. but that really doesn&amp;#39;t go very far.&lt;br/&gt;&lt;br/&gt;This really sucks, but I strongly suspect no universities are coming to save anyone.
    </content>
    <updated>2025-02-11T14:18:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszdz6q0huh9tnttce0cf3ud2ytvnn2f6swcld5ydtprfht34w2d2qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz3g42qu</id>
    
      <title type="html">Yeah. This *is* a C programming class too, for what it&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszdz6q0huh9tnttce0cf3ud2ytvnn2f6swcld5ydtprfht34w2d2qzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qz3g42qu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2hx8u5k9kv3r4s6jmzgg0ey8wq62e7hr5q8a2txts69y2d7txa0qnh7rrw&#39;&gt;nevent1q…7rrw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah. This *is* a C programming class too, for what it&amp;#39;s worth. It&amp;#39;s the third class in our programming sequence (Python, then OOP w/ Java). &lt;br/&gt;&lt;br/&gt;I very intentionally frame the class as &amp;#34;Our goal here is to learn to think like the compiler, and we&amp;#39;re going to take away all the cool programming tools you had in your first two classes.&amp;#34;
    </content>
    <updated>2024-11-08T18:44:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8wxk8lvj25t8gdm5egvyphphh9t8amv0pkz3y0m6j4573wvqtnwgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzrqggwz</id>
    
      <title type="html">Yeah. This is a problem I&amp;#39;m really noticing in my year 2 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8wxk8lvj25t8gdm5egvyphphh9t8amv0pkz3y0m6j4573wvqtnwgzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzrqggwz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx3kf9qmp0fmp80l0p00uhla6wper2pp77ug0rzl3wqq4x7zugjcqfhspx7&#39;&gt;nevent1q…spx7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah. This is a problem I&amp;#39;m really noticing in my year 2 course right now. Students are relying on the AI to do any kind of critical thinking, even things like basic debugging. &lt;br/&gt;&lt;br/&gt;It&amp;#39;s not uniform across all students, but it&amp;#39;s a real problem when they&amp;#39;re asked to do something the AI isn&amp;#39;t good at. For example, my course spends a lot of time covering topics like memory management, process management, etc... along with the syscalls used for it.&lt;br/&gt;&lt;br/&gt;But, the course is intended to prep students for understanding exploit development/reverse engineering, so we use Windows, not Linux (like all the other OS courses out there). ChatGPT ain&amp;#39;t great at writing code for Windows. &lt;br/&gt;&lt;br/&gt;Interestingly, it usually fails on the same stuff I do in my first pass, like all the wonky string typecasting needed. It&amp;#39;s all stuff there&amp;#39;s not a ton of resources for. There&amp;#39;s maybe 1 or 2 useful books and the rest of the content lives in TechNet articles. There&amp;#39;s not even a ton on Stack Overflow. Not enough for ChatGPT to really work with.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m encountering students that really struggle with the debugging process. Instead of &amp;#34;Compile, get an error, research that error, figure out the problem, fix the problem, add the next bit of functionality&amp;#34;, I&amp;#39;m seeing students just throw the whole thing into ChatGPT (maybe) with the error message and expect ChatGPT to fix it.
    </content>
    <updated>2024-11-08T18:29:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0ahaegnllpn60stzg4g2r8ys6u7zl4nayqqpu05xzjzpwuxw7gugzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzw9fd87</id>
    
      <title type="html">My best story on that - I was red teaming a student competition ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0ahaegnllpn60stzg4g2r8ys6u7zl4nayqqpu05xzjzpwuxw7gugzyzuzxue7w66nafpvx88pauqkp825yscfn054wcezjx3updgr7f9qzw9fd87" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrw5vanhan5w9gf0r7hnf47jpv9947m5sqlap7amnn0uqjntr3hncdu0j2n&#39;&gt;nevent1q…0j2n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;My  best story on that - I was red teaming a student competition during which the student teams could attack each other too.&lt;br/&gt;&lt;br/&gt;One team of students blew out Ansible that replaced every binary in System32 with a simple executable that just printed &amp;#39;No&amp;#39;.&lt;br/&gt;&lt;br/&gt;The pro red team spent, like, half the day tracking down why Cobalt Strike was telling us &amp;#39;No&amp;#39; thinking it was a permissions problem.
    </content>
    <updated>2024-11-07T20:28:19Z</updated>
  </entry>

</feed>