Allan

@allanfriedman.bsky.social

SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, & occasionally getting paid for it. Poster of food pics.

I never actually learned how to take a picture. That is, I think there’s a little more nuance than “point phone at pretty scenery / delicious plate.” I’m not about to study photography formally, but I am about to go on vacation. Anyone have a few good videos or a helpful beginner site / book?

In case it’s hard to tell what I’m actually saying here: Slowing down vulnerability disclosure is to cybersecurity as drinking sea water is to dehydration. Might feel better if you’re desperate but it will greatly accelerate your doom. This isn’t a fix for vuln process saturation

Katie Moussouris (she/her/she-hulk/she-ra)🌻@k8em0.bsky.social · last wk.

Happy #Cybersecurity awareness month! Be aware that even the most well-funded orgs can’t handle floods of AI-generated OSS bug reports. Now every maintainer can get vuln reports slower than ever with GitHub rate limits for new security reports. Pace the defense frontier!

Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.

With this update:

Private vulnerability reporting now applies daily per-user rate limits to new reports.
Reporters who reach a limit see a message asking them to try again later.
Limits apply only to new reports. Comments on existing advisories aren’t affected.
Repository administrators can set a custom daily overall reporting limit for their repository.
Repository administrators can add trusted reporters to an allow list so they’re never rate limited.
To configure these settings, go to your repository’s settings, select Advanced Security, and click Settings next to “Private vulnerability reporting.”

I really enjoyed this article: we have new toys, and those will guide tactics, rather than strategy. Leaving aside current challenges around “not having any strategy,” there is also a pretty large cyber-shaped hole in this line of thinking that scholars need to fill.

Matthew Ford@warmatters.bsky.social · 2w ago

Latest publication: Hammers & Nails: Military Innovation as a Strategic Dead End In this article I argue that innovation has become an end-in-itself, supplanting the much harder challenge of defining a meaningful, justifiable and achievable strategy. www.militarystrategymagazine.com/article/hamm...

I love Americana and country music, including songs that celebrate the simple pleasures of country live: Avett Bros, Delta Rae, etc. But are there any songs that celebrate the joys of city living? The neighborhoods, the local coffee shops, street festivals, great restaurants, cocktails?

I mean that's just normal. You check things and make sure they're correct and have experts review them and so on. You edit, you extend, you simplify. It's research. Solving the N-S conjecture on Sunday and publishing the proof on Monday is weird.

Ethan Mollick@emollick.bsky.social · 4w ago

I don’t usually share rumors but: 1) This is from someone with inside knowledge & is plausible 2) Is a real issue of policy we need to think about: if the norms of sharing become strained, will the labs start hoarding knowledge to avoid PR or regulatory issues? scottaaronson.blog?p=10062

I love Prof Klonick, and read what she writes regularly, but I think there’s a fairly obvious difference between being annoyed by automated content moderation and having humans review inputs that may never have been intended to be shared with anyone.

Kate Klonick@klonick.bsky.social · 4w ago

People 2014-2024: “We don’t want robots reviewing our content! We demand human review!” People in 2026: “Holy shit, did you know humans are reviewing our content!? How creepy! We only want robots!!”

I think the sanest way to approach this llm stuff if you use it as if it’s a new abstraction from machine code. It’s another layer to communicate instructions to a computer. The biggest problem is we weren’t ready to communicate with computers in the way we do with other people. We fucked that up

This is seismic news for fisheries scientists. Northern cod is *the* iconic symbol of total fisheries collapse due to overfishing (and other factors) *and* the iconic symbol of a complete failure to recover for decades afterwards. This is like announcing the complete recovery of bison on land.

Bild
UBC Oceans@ubcoceans.bsky.social · last mo.

For the first time in over 30 years, Newfoundland and Labrador’s Northern cod stock has been deemed “healthy” by Ottawa. www.canadianaffairs.news/2026/09/05/i...

Amazing writeup by @dangoodin.bsky.social of a BGP-hijack for a supply chain attack. He shows: 1) clear details of BGP attack w $ motive, 2) we have tools to prevent this, but you have to use them, and 3) how to write clearly about complicated security topics. arstechnica.com/security/202...

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

What can we learn from a BGP hijacking that poisoned production software? Plenty.

arstechnica.com

"We want a classified information system but we want it to work exactly the same as all of our unclassified information systems and introduce zero additional friction of any kind" is the cybersecurity "Claude, do a breakthrough" of the moment