Adam Shostack

@adamshostack.bsky.social

Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE. Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack

Admittedly a US thing, but I think folks should reflect that Kimi, the open-weight AI model by $20b-valued Moonshot AI everyone is freaking out about, was developed by someone who went to CMU and then didn't stay in the US mostly because visas would prevent him setting up a US business

What I actually want: * I read and cite real sources * AI creates accurate bibtex from sketchy notes ("so-and-so's paper from SOUPS 2 years ago about topic") * AI cleans up the formatting so all references to one conference are formatted the same, titles with acronyms get capitailzed right ...

Dr. Casey Fiesler@cfiesler.bsky.social · 3w ago

So I just got probably my fifth email this year from another AI startup focused on citation verification (wanting me to do ads for them). This time as I was looking at their website (tagline: "Write your paper with 100% correct references") I thought... wait, why do we actually want this? 🧵

Despite being approved for Anthropic's "Cyber Verification Program" I still get *constant* refusals for spicy infosec work. Codex gpt-5.6-sol (without CVP) when asked to do the same tasks not only doesn't refuse, but does the job exponentially faster than Opus. What the hell happened to Claude?

Give me model liberty, or give me technical debt. Just in time to celebrate America’s 250th bday, let’s let model freedom ring. We should be pushing for broad defender access, not building guardrails that shoot down defenders and burn excessive compute. www.lutasecurity.com/post/fable-5...

Fable 5 Is Back, But We're Still Slowing Down Defenders

Chinese models have been accelerating, in part by distilling US frontier models. Cutting off Fable 5 and Mythos 5 inconvenienced them too, but it did not slow them down

lutasecurity.com

Was Hines v Stamos Cheryl Hines suing John Stamos over the long-awaited Full House/Curb Your Enthusiasm crossover? Nope, it was an attempt to suppress academic research into the organized manipulation of online platforms. After three years we finally won. But at great cost.

Kate Starbird@katestarbird.bsky.social · last mo.

Two years ago, my colleagues and I were sued by Stephen Miller's America First Legal. The Hines v Stamos case — built atop a number of false allegations — was a central element of the "censorship industrial complex" myth. Today, that case was dismissed (by a Trump judge in LA). We won.

UNITED STATES DISTRICT COURT
WESTERN DISTRICT OF LOUISIANA
MONROE DIVISION
JILL HINES ET AL — CASE NO. 3:23-CV-00571
VERSUS — JUDGE TERRY A. DOUGHTY
ALEX STAMOS ET AL — MAG. JUDGE KAYLA D. MCCLUSKY
MEMORANDUM RULING
Before the Court is a Renewed Joint Motion to Dismiss for Lack of Subject Matter and Personal Jurisdiction [Doc. No. 191] filed by Defendants, Alex Stamos, Renée DiResta, the Board of Trustees of the Leland Stanford Junior University, the Leland Stanford Junior University, Kate Starbird, Graphika, Camille François, the Atlantic Council, and Graham Brookie (collectively, "Defendants"). Plaintiffs, Jill Hines ("Hines") and Jim Hoft ("Hoft") (collectively, "Plaintiffs"), filed an Opposition [Doc. No. 207]. Defendants then filed a Reply [Doc. No. 209].
For the reasons set forth, Defendants' Motion is GRANTED.

Subject: Your password will be removed if it isn't used "Your HubSpot password hasn't been used in over 90 days and is scheduled for removal. We're removing unused passwords to follow security best practices." Thoughts?