I never actually learned how to take a picture. That is, I think there’s a little more nuance than “point phone at pretty scenery / delicious plate.” I’m not about to study photography formally, but I am about to go on vacation. Anyone have a few good videos or a helpful beginner site / book?
Allan
@allanfriedman.bsky.social
SBOM Champion. Paranoid about supply chains of all kinds. Former full-service technocrat at CISA, NTIA. Lapsed{engineer, academic, author}. Now wandering the world doing acts of infosec-goodness, & occasionally getting paid for it. Poster of food pics.
Error: Your password must contain at least two characters who talk to each other about something other than a man.
I continue to think "O(n) with service growth" is the most ignored and/or (perhaps deliberately) misunderstood part of toil: sre.google/sre-book/eli...
Google SRE - What is Toil in SRE: Understanding Its Impact
Learn what toil is in SRE, how it affects operational work, and why minimizing it is crucial for efficiency and morale.
sre.google
🎵 Now they know how many holes it takes to fill the Annie Hall... 🎶
Sort of insane fact about how broken US urban planning is—America now spends more building *just the lights for roads and highways* than on all subways & ground mass transit combined Spending on roadway *pavement* is 18x transit spending
In case it’s hard to tell what I’m actually saying here: Slowing down vulnerability disclosure is to cybersecurity as drinking sea water is to dehydration. Might feel better if you’re desperate but it will greatly accelerate your doom. This isn’t a fix for vuln process saturation
Happy #Cybersecurity awareness month! Be aware that even the most well-funded orgs can’t handle floods of AI-generated OSS bug reports. Now every maintainer can get vuln reports slower than ever with GitHub rate limits for new security reports. Pace the defense frontier!
I really enjoyed this article: we have new toys, and those will guide tactics, rather than strategy. Leaving aside current challenges around “not having any strategy,” there is also a pretty large cyber-shaped hole in this line of thinking that scholars need to fill.
Latest publication: Hammers & Nails: Military Innovation as a Strategic Dead End In this article I argue that innovation has become an end-in-itself, supplanting the much harder challenge of defining a meaningful, justifiable and achievable strategy. www.militarystrategymagazine.com/article/hamm...
I love Americana and country music, including songs that celebrate the simple pleasures of country live: Avett Bros, Delta Rae, etc. But are there any songs that celebrate the joys of city living? The neighborhoods, the local coffee shops, street festivals, great restaurants, cocktails?
Chatted with @dpp.me, founder & CEO of Spice Labs, & @allanfriedman.bsky.social, Senior Technical Advisor at the Institute for Security & Technology, about PQC & Cryptographic Bill of Materials (CBOMs) for the latest @redmonk.com MonkCast. redmonk.com/videos/david... youtube.com/shorts/VPflv...
Cryptography Bill of Materials Explained #cbom #postquantumcryptography #softwaredevelopment
YouTube video by RedMonk
youtube.com
I assume that when whoever is making it IPOs they will reveal the full lineup implied by the existence of Tilly Norwood.
Proud to say that I was at the first ever Fluff Festival, in Somerville during grad school.
What is the over/under for number of Fluff Cones we’re gonna sell at Fluff Festival on Saturday. I hope it’s a lot.
I mean that's just normal. You check things and make sure they're correct and have experts review them and so on. You edit, you extend, you simplify. It's research. Solving the N-S conjecture on Sunday and publishing the proof on Monday is weird.
I don’t usually share rumors but: 1) This is from someone with inside knowledge & is plausible 2) Is a real issue of policy we need to think about: if the norms of sharing become strained, will the labs start hoarding knowledge to avoid PR or regulatory issues? scottaaronson.blog?p=10062
I love Prof Klonick, and read what she writes regularly, but I think there’s a fairly obvious difference between being annoyed by automated content moderation and having humans review inputs that may never have been intended to be shared with anyone.
People 2014-2024: “We don’t want robots reviewing our content! We demand human review!” People in 2026: “Holy shit, did you know humans are reviewing our content!? How creepy! We only want robots!!”
I think the sanest way to approach this llm stuff if you use it as if it’s a new abstraction from machine code. It’s another layer to communicate instructions to a computer. The biggest problem is we weren’t ready to communicate with computers in the way we do with other people. We fucked that up
This is seismic news for fisheries scientists. Northern cod is *the* iconic symbol of total fisheries collapse due to overfishing (and other factors) *and* the iconic symbol of a complete failure to recover for decades afterwards. This is like announcing the complete recovery of bison on land.
For the first time in over 30 years, Newfoundland and Labrador’s Northern cod stock has been deemed “healthy” by Ottawa. www.canadianaffairs.news/2026/09/05/i...
Having some fun with late summer flavors: aquavit-infused croutons. (For a course with heirloom tomatoes and homemade smoked trout)
[wipes hands] yeap. You got agents. See the message boards in your internal package manager? They must’ve nested there about ohhh 3 weeks back.
Another agent message board. So far, there isn't evidence that production models with guardrails collude in this way, but both smarter closed models (which may be less compliant) & Mythos-class open models (that can be ablated) are coming. Cybersecurity is going to become a mess soon collusion.wiki
Today in obvious solutions: realizing I can put a metal rack on the burner to better roast peppers.
Amazing writeup by @dangoodin.bsky.social of a BGP-hijack for a supply chain attack. He shows: 1) clear details of BGP attack w $ motive, 2) we have tools to prevent this, but you have to use them, and 3) how to write clearly about complicated security topics. arstechnica.com/security/202...
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
What can we learn from a BGP hijacking that poisoned production software? Plenty.
arstechnica.com
Finally enjoying @nealstephenson.bsky.social ‘s The Diamond Age, and I can’t express the joy of discovering new words that I have to look up. I flatter myself reasonably well-read and -schooled, and it’s a fun treat to be sent scurrying.
Right now there is a lady in college who is discovering Dolly Parton and will carry that music through the rest of her life in the same way I discovered Johnny Cash in 2003. I take comfort in that.
if there’s a point to fame it’s to do what dolly parton did in the world
"We want a classified information system but we want it to work exactly the same as all of our unclassified information systems and introduce zero additional friction of any kind" is the cybersecurity "Claude, do a breakthrough" of the moment
Are we finally relitigating the French and Indian War on here?
Animaechan Cracks Knuckles with Pout
ALT: Animaechan Cracks Knuckles with Pout
static.klipy.com
You ever just think about how Fort Necessity was a bonehead move?