
adam shostack
@adamshostack
Done with Twitter. Don't expect responses. Threat Modeling: Designing for Security. Working to reduce bad security outcomes.
Tal vez te guste
Threat Modeling is a Jolt Finalist, the first security-centered book on the list since Schneier’s Secrets & Lies newschoolsecurity.com/2014/09/jolt-a…
Leaving my account so it can't be squatted as easily, leaving my tweets because I hate linkrot.
New bloggage, shostack.org/blog/who-are-w… The paper is Who Are “We”? Power Centers in Threat Modeling, and the abstract reads: “I examine threat modeling techniques and questions of power dynamics...

I'm old enough to remember when Americans voted for the candidate they thought would do the best job.
When I saw those release notes I assumed Synology were trying to reduce codec license fees. Whatever the reason, as you say, security patches should not come at the cost of features.
Synology created a patch to address the zero-click vulnerability that researchers at @midnightbluelab found, but @adamshostack spotted this explanation about the patch:

Dutch researchers @midnightbluelab found critical zero-click vuln in photo app enabled by default on Synology storage devices, putting millions of systems at risk of being hacked. They found Synology systems owned by police/law firms/critical infrastructure contractors all vuln…
wow. the best thing I've seen this election.
"Bohemian Trumpsody" from @marshsongs may just be the best thing I've seen all day. Not only are the lyrics spot on, but man they can saaaaaaang!
New video: Scaling Threat Modeling youtu.be/ySGVUMYcoMw?fe… via @YouTube
youtube.com
YouTube
Scaling Threat Modeling
Back in the day, I did some cool #security #UX work with @adamshostack and @moduloprime at Microsoft. Now @beyondidentity is recruiting for a security-savvy UX designer. Any of my #infosec peeps interested? linkedin.com/posts/allan-zi…
Think Like a Hacker? Or not. youtu.be/2ITXN6Yqs-w?fe… via @YouTube
youtube.com
YouTube
Think Like a Hacker? Or not.
Shostack + Associates is launching a new course, Scaling Threat Modeling, and we'd like your input shostack.org/blog/scaling-t…

I remember Russian spies getting full time in-person jobs at Microsoft so my threat model has always been attuned to some form of this issue of spies infiltrating the software supply chain. theatlantic.com/international/…
theatlantic.com
Who Was the 12th Russian Spy at Microsoft?
Alexey Karetnikov tested software at the Redmond giant
Would you know if you hired a North Korean as a remote working employee? Didn’t have that on my cybersecurity bingo card for 2024!

United States Tendencias
- 1. Good Tuesday 21.7K posts
- 2. White House 105K posts
- 3. Texans 38.9K posts
- 4. #tuesdayvibe 1,317 posts
- 5. World Series 118K posts
- 6. Cobie 34.6K posts
- 7. Sanae Takaichi 60.6K posts
- 8. #Talus_Labs N/A
- 9. Seattle 51.8K posts
- 10. Blue Jays 101K posts
- 11. Mariners 95.1K posts
- 12. CJ Stroud 6,967 posts
- 13. Seahawks 37.9K posts
- 14. LA Knight 8,858 posts
- 15. Nick Caley 2,755 posts
- 16. East Wing 77.1K posts
- 17. Springer 70.5K posts
- 18. Joe Carter 3,287 posts
- 19. Dodgers in 5 2,306 posts
- 20. Coinbase 50.5K posts
Tal vez te guste
-
Dr. Anton Chuvakin
@anton_chuvakin -
edskoudis
@edskoudis -
Jeremiah Grossman
@jeremiahg -
Chris Wysopal
@WeldPond -
Dino A. Dai Zovi
@dinodaizovi -
Matt Johansen
@mattjay -
Ron Gula
@RonGula -
Ben Rothke
@benrothke -
Dan Guido
@dguido -
Space Rogue
@spacerog -
Chris Eng
@chriseng -
Erin Jacobs
@SecBarbie -
Andrew Hay
@andrewsmhay -
Dave
@daveshackleford -
Jennifer (JJ) Minella 🎙 #PacketProtector
@jjx
Something went wrong.
Something went wrong.