"I mean they say you die twice. One time when you stop breathing and a second time, a bit later on, when somebody says your name for the last time." - Banksy
We've lost too many.
#NaClCon#rip
Some of the people who helped build the modern internet and shape today’s cybersecurity industry gathered in Carolina Beach this week for the inaugural NaClCON conference. https://t.co/RcXCIShxyV
"If LLMs can be entrusted with software development, then they ought to be writing patches that work.
They’re not.
The contrast between the breathless blog posts from commercial entities and ... 97 findings patched in the open source world is really shocking." https://t.co/wVJXikdWHV
I just learned the sad news that Peter Neumann has passed away.
Peter Neumann shaped how a generation of security people learned to think about risk. As editor of RISKS Digest, he gave many of us coming up in the 1990s and early 2000s a steady education in the real-world consequences of computer failures. His work made the field more serious, more thoughtful, and more honest. He will be missed.
I first met Peter when we both testified at the 1998 Senate Governmental Affairs Committee meeting on Government Security where the L0pht testified. The combination of Peter and the L0pht made the hearing more powerful even if us hackers stole the spotlight.
Neumann and the L0pht made the same argument from two different directions. Neumann gave the institutional, systems-engineering view: the country was becoming dependent on brittle, interconnected systems that were never designed for security, reliability, or survivability. The L0pht gave the field evidence: here are the actual flaws, here is how attackers think, here is how cheaply and quickly these systems can fail in practice.
Neumann supplied the credibility of a long-time researcher warning that this was not just “hackers breaking into things,” but a structural failure of technology markets, procurement, engineering discipline, and risk management. The L0pht supplied the proof that the warnings were not theoretical. Together, we made the hearing unusually powerful: the academic risk community and the hacker community were telling the Senate the same thing, in different languages, before the rest of the world had fully caught up.
Couldn’t agree more with @WeldPond about @window for @DarkReading being “one of the most important security leaders of the past two decades," for her ability to achieve systemic change. Great #Darkreading20 special coverage.
I’ve been promoting the value of AI to fix for over 2 years to our customers. If you have a dual use technology ethics says build more fire stations before you unleash the flamethrowers. I started releasing dual use tools over 25 years ago and I adamantly believe in them. You need to promote the defense side to all who will listen as the offense side needs no promotion.
He began by replicating Mythos findings with his specialized harness.
Then went on to find more critical novel zero days in open source code that he can't share yet because they're not fixed.
TL;DR - harnesses are where the magic is. https://t.co/e8jhbktBKQ
Should Tesla have a mode where it learns the driving habits of the driver in the region and behave accordingly? For instance, I’m in Boston so it would cut people off, merge at the last second and treat blinkers as signals you might not want to give off in all lane changes.