adamshostack's profile picture. Done with Twitter.  Don't expect responses.
Threat Modeling: Designing for Security. Working to reduce bad security outcomes.

adam shostack

@adamshostack

Done with Twitter. Don't expect responses. Threat Modeling: Designing for Security. Working to reduce bad security outcomes.

Épinglé

Threat Modeling is a Jolt Finalist, the first security-centered book on the list since Schneier’s Secrets & Lies newschoolsecurity.com/2014/09/jolt-a…


Who are you going to believe, me or your own eyes?


Leaving my account so it can't be squatted as easily, leaving my tweets because I hate linkrot.


New bloggage, shostack.org/blog/who-are-w… The paper is Who Are “We”? Power Centers in Threat Modeling, and the abstract reads: “I examine threat modeling techniques and questions of power dynamics...

adamshostack's tweet image. New bloggage, shostack.org/blog/who-are-w… The paper is Who Are “We”? Power Centers in     Threat Modeling, and the abstract reads: “I examine     threat modeling techniques and questions of power dynamics...

I'm old enough to remember when Americans voted for the candidate they thought would do the best job.


adam shostack a reposté

When I saw those release notes I assumed Synology were trying to reduce codec license fees. Whatever the reason, as you say, security patches should not come at the cost of features.


adam shostack a reposté

Synology created a patch to address the zero-click vulnerability that researchers at @midnightbluelab found, but @adamshostack spotted this explanation about the patch:

KimZetter's tweet image. Synology created a patch to address the zero-click vulnerability that researchers at @midnightbluelab found, but @adamshostack spotted this explanation about the patch:

Dutch researchers @midnightbluelab found critical zero-click vuln in photo app enabled by default on Synology storage devices, putting millions of systems at risk of being hacked. They found Synology systems owned by police/law firms/critical infrastructure contractors all vuln…



adam shostack a reposté

wow. the best thing I've seen this election.

"Bohemian Trumpsody" from @marshsongs may just be the best thing I've seen all day. Not only are the lyrics spot on, but man they can saaaaaaang!



adam shostack a reposté

Back in the day, I did some cool #security #UX work with @adamshostack and @moduloprime at Microsoft. Now @beyondidentity is recruiting for a security-savvy UX designer. Any of my #infosec peeps interested? linkedin.com/posts/allan-zi…


Shostack + Associates is launching a new course, Scaling Threat Modeling, and we'd like your input shostack.org/blog/scaling-t…

adamshostack's tweet image. Shostack + Associates is launching a new course, Scaling Threat Modeling, and we'd like your input shostack.org/blog/scaling-t…

adam shostack a reposté

I remember Russian spies getting full time in-person jobs at Microsoft so my threat model has always been attuned to some form of this issue of spies infiltrating the software supply chain. theatlantic.com/international/…

theatlantic.com

Who Was the 12th Russian Spy at Microsoft?

Alexey Karetnikov tested software at the Redmond giant

Would you know if you hired a North Korean as a remote working employee? Didn’t have that on my cybersecurity bingo card for 2024!

RGB_Lights's tweet image. Would you know if you hired a North Korean as a remote working employee?  

Didn’t have that on my cybersecurity bingo card for 2024!


Loading...

Something went wrong.


Something went wrong.