Posts by mttaggart@infosec.exchange
(DIR) Post #B5850LVp4sFp9wzBWy by mttaggart@infosec.exchange
0 likes, 1 repeats
Believe it or not, I am still working on #Ringspace. And here's a new release!This version of the protocol employs JWKS format for key exchange, and uses Base64URL formats for all encoded data. Plus.env support and resources for Docker deployment!https://codeberg.org/mttaggart/ringspace/releases/tag/v0.2.2What's Ringspace? It's a proposal for a human web protocol that combines mutual trust and reputation. https://ringspace.net
(DIR) Post #B59bDifffzEmRPyOUC by mttaggart@infosec.exchange
0 likes, 0 repeats
When AI pops, I'm looking forward to watching LinkedIn eat itself alive searching for a take.
(DIR) Post #B59bDj48D2nrfHPvc0 by mttaggart@infosec.exchange
0 likes, 0 repeats
@cR0w I can already see it happening, and it's already driving me crazy. For people so interested in math, counting (qubits) seems remarkably challenging for them!
(DIR) Post #B5FLB4iKpdHfcShCIC by mttaggart@infosec.exchange
1 likes, 0 repeats
It was my job for a decade to try to keep tweens and teens safe online. Let me tell you what you already know: no law or technology can do it. There are no lengths kids won't go to to talk to friends without prying eyes. The harder you try to lock it down, the dodgier their solutions will be.
(DIR) Post #B5FLB5R09Z0rqzarui by mttaggart@infosec.exchange
1 likes, 0 repeats
And yes of course, none of this legislation is about kids. We've already established these ghouls don't give a shit about kids. But these laws actually will hurt kids, which I guess is right on track.
(DIR) Post #B5UXK5vZnoNcoJM6Vc by mttaggart@infosec.exchange
0 likes, 1 repeats
I've been seeing this extension all over and wasn't sure exactly what folks were doing. Turns out, they weren't doing anything. Claude for Desktop is secretly installing this thing that activates when one of three other extensions are also present.https://www.thatprivacyguy.com/blog/anthropic-spyware/
(DIR) Post #B5UXK6PM16CQIfHsvI by mttaggart@infosec.exchange
0 likes, 0 repeats
Two of the listed IDs are private (or I couldn't find them in Chrome/Edge), and one is official Claude extension.
(DIR) Post #B5X1ExiiHAv8qfjAB6 by mttaggart@infosec.exchange
0 likes, 0 repeats
Yo did we forget about the Framework-funding-fash thing or
(DIR) Post #B5X1Ey4KymDZvjqQsq by mttaggart@infosec.exchange
0 likes, 0 repeats
Listen, I have a Framework. It's a great laptop—maybe the best I've ever had. But I can't support a company that funds, in any form, an actual real-life Nazi like DHH. I also need them to, y'know, take ownership of the massive misstep doing so is/was.
(DIR) Post #B5XKyYnNB07BzmMaMi by mttaggart@infosec.exchange
1 likes, 0 repeats
Lotta "Well he's not actually a Nazi" replies. Look:The term is loaded. It absolutely is. But if, in this age, someone has vociferously advocated for checks notesracial purity in their public writing, I think they surrender the benefit of the doubt. And I'm not waiting for them to line people up before I decide it's a problem.More simply: racist scum don't need your advocacy.
(DIR) Post #B5vhWalvC9M0kzM6Ii by mttaggart@infosec.exchange
1 likes, 0 repeats
We find that LLMs consistently prefer resumes generated by themselves over those written by humans or produced by alternative models, even when content quality is controlled.Horrifying. https://arxiv.org/abs/2509.00462
(DIR) Post #B5xwspEryWVhcmsKOG by mttaggart@infosec.exchange
0 likes, 1 repeats
Hey @cloudflare, how come you're protecting beamed[.]st, the DDoS service that's attacking Ubuntu? It's an obvious criminal enterprise that literally advertises botnet access.
(DIR) Post #B5xwspfoMM3qyLTqNs by mttaggart@infosec.exchange
0 likes, 0 repeats
@cloudflare 10/10 excellent brand synergy
(DIR) Post #B5xwsq019EDxz0vysa by mttaggart@infosec.exchange
0 likes, 0 repeats
@cloudflare I know I have tech journalists following me. I don't know why this isn't a bigger story. A part of the internet considered "Critical infrastructure" is being attacked with impunity, and those who could stop it are doing nothing.
(DIR) Post #B61s7JmBVpr7FZOBSy by mttaggart@infosec.exchange
1 likes, 0 repeats
@cwebber Willison's distinction (and previous iterations of it) strikes me as dangerously naive. Based on my own experience with both the tool and, y'know, human nature, nothing but the most draconian guardrails will prevent people from taking the easy way with these tools.We were never going to do this safely.
(DIR) Post #B669DEAxit5nTIDpM8 by mttaggart@infosec.exchange
0 likes, 1 repeats
Hey I'll sign your cert for you
(DIR) Post #B68BRbrj1wRdDr860u by mttaggart@infosec.exchange
0 likes, 0 repeats
@SwiftOnSecurity The "Threat Intel Paywall" is one of the primary reasons we founded @ifin. We're bringing back the old ways—including the in-depth research.
(DIR) Post #B6MmTDunSuHs2OdbxQ by mttaggart@infosec.exchange
1 likes, 2 repeats
This entire report from the Ontario government on genAI systems is worth a read, but the review of healthcare scribe accuracy is pretty devastating, imo. This has to work for the tech to be worth anything. If the notes in the chart are wrong, the whole thing falls apart.https://www.auditor.on.ca/en/content/specialreports/specialreports/en26/2026_AI_EN.pdf
(DIR) Post #B6aic6Rsulz1srX3FA by mttaggart@infosec.exchange
0 likes, 0 repeats
RE: https://infosec.exchange/@ifin/116622369159743355Gonna go back to sending software by mail until we can figure this out.RT: https://infosec.exchange/ap/users/115741367687413652/statuses/116622369159743355
(DIR) Post #B6aic6tXFy6LGcT8LI by mttaggart@infosec.exchange
1 likes, 0 repeats
@kims Is there anything more anti-LLM than typing source code from the pages of a magazine?