soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
If quantum computers start breaking cryptography a few years from now, don't you dare come to me saying nobody warned you." - Aaronson, hours after NAS election.
He names no lab. He's reporting what the builders are telling him: ~2029 for CRQC is now plausible.
https://postquantum.com/security-pqc/aaronson-quantum-warning-nas/
AI agents are becoming more capable, but how do they securely access your accounts without exposing your passwords?
1Password has introduced 1Password for Claude, a new integration that allows Anthropic’s Claude to complete tasks requiring logins without ever seeing your credentials.
Key highlights:
* Passwords and one-time passcodes never enter the AI’s context or memory.
* Every credential request requires explicit user approval and biometric authentication.
* Access is limited to the specific task being performed.
* New Agentic Mode automatically protects the rest of your password vault while an AI agent is controlling your browser.
As AI agents evolve from assistants to autonomous operators, innovations like this could become the blueprint for balancing productivity with security. Giving AI permission to use credentials without revealing the secrets themselves, is an important step toward safer agentic AI.
#AI #ArtificialIntelligence #AgenticAI #ClaudeAI #Anthropic #1Password #CyberSecurity #IdentitySecurity #PasswordManagement #ZeroTrust #Infosec #Innovation
Think cybersecurity is only for fictional movies? These documentaries tell the real stories behind some of the biggest hacks, privacy battles, and cyber incidents 😎👇
Find high-res pdf ebooks with all my cybersecurity related infographics at https://study-notes.org
#cybersecurity #hacking #infosec #informationsecurity #privacy
I thought scaling Tor meant adding more relays.
What it actually meant was multiplying failure modes...
I now operate 24 Tor relays and bridges across 15 locations, 11 ASNs and 6 operating systems.
Every new relay brings another provider, firewall, IPv6 route, service manager, identity key, backup and recovery plan.
Some things I learned along the way:
🌍 More countries don’t automatically mean real diversity
🔑 The server is replaceable, the relay identity isn’t
🛠️ Linux, BSD and SunOS need the same outcomes, not the same commands
📊 What I configured isn’t always what the Tor network currently sees
A large fleet is easy to count. A resilient one is much harder to keep alive.
I wrote about what operating Tor across 15 locations actually taught me:
New analysis: How Much Can AI Actually Help With PQC Migration?
A hypothesis paper in MDPI Cryptography claims frontier AI (Mythos-class) compresses enterprise PQC migration from 12-15 years to 2-4 years. The paper models AI as both defender accelerator and adversary destabilizer through six feedback loops, and that dual-use framing is sound.
The timeline estimate is not.
I've led PQC migration programs generating 120,000+ discrete tasks. AI genuinely helps with the technical analysis fraction: crypto discovery triage (months to days), migration strategy automation across 100K+ instances, code diff generation (hours to minutes), test scenario creation.
That accounts for maybe 15-20% of total program effort.
The other 80%:
- Getting executive mandate and multi-year budget (3-12 months)
- Standing up program governance (3-6 months)
- Negotiating access to production segments across business units (this is the bottleneck in discovery, not analysis speed)
- Change advisory board approvals for every production change
- Vendor firmware/certification timelines entirely outside your control
- Interoperability testing with real counterparties on their schedules
- FIPS 140-3 module validation cycles
- CBOM and crypto-agility as organizational transformations, not technology deployments
Key analytical distinction: effort compression ≠ schedule compression. 20% of effort off the critical path saves zero calendar time. The institutional dependencies dominate the critical path in every large program I've observed.
The paper assigns 8 years to AI-compressible work and 2 years to the institutional floor. In my experience, those proportions are reversed.
EO 14412 (signed June 22, 2026) sets Dec 31, 2030 for PQC key establishment and Dec 31, 2031 for digital signatures in federal high-value systems. CNSA 2.0 requires new NSS acquisitions to be compliant from January 2027.
The correct response to AI-accelerated adversary capability is not "compress the timeline from 15 years to 4." It's: start the program now and use AI within it.
https://postquantum.com/post-quantum/ai-pqc-migration-how-much-help/
#infosec #cybersecurity #PQC #postquantum #cryptography #quantumcomputing #NIST #migration
ICE’s internal watchdog has opened more than 100 investigations into alleged doxing and threats targeting agency employees, according to court filings. 🛡️
The cases include efforts to identify online critics, raising transparency and free speech concerns over expanding government surveillance powers. ⚖️
🔗 https://www.wired.com/story/ices-internal-watchdog-is-now-investigating-online-critics/
#TechNews #ICE #USA #US #Privacy #Surveillance #FreeSpeech #Cybersecurity #DigitalRights #Government #Infosec #DataProtection #Security #CivilLiberties #Police #Trump
Florida police records allege an officer used DMV data and a license plate reader to track a woman he met before stopping her in traffic. 🚔
Investigators say he knew the database access was unauthorized, highlighting surveillance abuse risks and the need for stronger oversight. 🔒
#TechNews #Surveillance #Privacy #LicensePlateReaders #LawEnforcement #Law #Cybersecurity #DigitalRights #DataProtection #Infosec #Technology #CivilLiberties #Government #Florida #USA #US
Shufflecake talk at CAW 2026 last May - video now available online!
https://clip.place/w/d7Anz5jbsMCZo1HBg8JkES
https://www.youtube.com/watch?v=21LjKFBIwwY
#shufflecake #caw #eurocrypt #eurocrypt2026 #cryptography #crypto #truecrypt #veracrypt #security #Privacy #infosec #hacktivism #censorship
Apple’s App Store reportedly logs every tap and keystroke for personalized recommendations, with researchers claiming the data is tied to user accounts and sent unencrypted. 🔐
The reported collection cannot be disabled and raises transparency and user-control concerns for privacy, as Apple expands on-device activity tracking. ⚠️
#TechNews #Apple #AppStore #Privacy #iPhone #iOS #Advertising #Ad #Cybersecurity #DataProtection #DigitalRights #Infosec #Technology #Security
Apple’s Hide My Email reportedly exposed users’ real email addresses through an unfixed flaw disclosed over a year ago, weakening a core privacy feature. 🔒
Researchers say Apple was notified in 2025, yet the exploit remains, highlighting transparency and user-control concerns for privacy tools. ⚠️
🔗 https://mashable.com/tech/apple-hide-my-email-major-vulnerability-leaks-email-addresses
#TechNews #Apple #iPhone #iOS #Mac #HideMyEmail #Email #Mail #Privacy #Cybersecurity #iCloud #EmailSecurity #DataProtection #Infosec #DigitalRights #Technology #Security
"The oldest principles in security—auditing, logging, isolation, least privilege—matter more than ever now that actions happen at machine speed, not human speed."—Artem Dinaburg, our chief scientist, on Silver Bullet ep 158.
The full pod covers why prompt injection has no clean fix, how we rebuilt our audits around agents, and why decompilers should work more like language translators.
https://berryvilleiml.com/2026/07/01/silver-bullet-security-podcast-158-artem-dinaburg/
What we’ve learned about testing Rust for security, now available as a Testing Handbook chapter.
Inside, you'll find what Rust's guarantees don't cover, undefined behavior with Miri, property testing with proptest, Clippy lints, memory zeroization, and model checking with Kani.
We also released rust-review, a Claude Code plugin for automated Rust security reviews co-built with Aptos Labs.
https://blog.trailofbits.com/2026/07/13/rust-proof-your-code-with-our-new-testing-handbook-chapter/
U-Boot Bootloader Flaws Allow Stealthy Pre-Boot Code Execution
Binarly researchers discovered six vulnerabilities in the U-Boot bootloader's FIT signature verification process that allow for arbitrary code execution and denial of service. These flaws affect over 50 stable releases since 2013 and can be exploited to install persistent firmware malware.
**If you run devices that use the U-Boot bootloader (servers, network gear, industrial and IoT devices, BMCs), first make sure all these devices are isolated from the internet and their management interfaces are accessible from trusted networks only. Then ask your hardware vendors for firmware updates fixing the U-Boot FIT vulnerabilities and apply them as soon as they're released. Prioritize BMCs and core network equipment.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/u-boot-bootloader-flaws-allow-stealthy-pre-boot-code-execution-b-d-7-x-u/gD2P6Ple2L
Computers should serve people not limit or control them. They are tools that can be used for good or bad, like any other item that can be a weapon.
To make LLMs useful for information security research I find myself constantly lying to it to get around the seemingly arbitrary guardrails.
Its social engineering against the machine on a scale that i never though I would have to engage in to get basic work done.
Having studied LLMs and how to secure / hack them, they are not the world ending technology that talking heads fear. They are tools, very powerful tools, but tools nonetheless.
#ai #llm #infosec #informationsecurity #paranoia #thecomputerisyourfriend