bogo, to infosec
@bogo@hapyyr.com avatar

A few more days left to @devconf_cz. I am looking forward to talking about #threatmodeling and maybe meeting some nice people! #devsecops #infosec #foss

Who else is going to be there?

ianonymous3000, to Cybersecurity
@ianonymous3000@mastodon.social avatar

📚 Just completed the 'Basics of Personal Threat Modeling' course by @privacyguides 🛡️

Threat modeling is crucial because it helps identify and prioritize the most probable security and privacy risks. It enables focused resource allocation, tailored defenses, and heightened awareness.

Check it out: https://learn.privacyguides.org

#Cybersecurity #Privacy #ThreatModeling #cybersecurityawareness #opsec

image/png

privacyguides,
@privacyguides@neat.computer avatar

@ianonymous3000 glad you liked the course 🙌​

angdraug, to TikTok
@angdraug@mastodon.social avatar

I recently saw a conversation between two people I respect that ended poorly. This being a social platform, shortage of mutual understanding is not surprising. Most of the time, I just back away slowly, but this time, the topic is important enough, and I think I can see a framing that can help make conversations about it less antagonistic.

The topic is around .

If you don't know what threat modeling is, start here: https://circle.lt/post/20190405-social-networks-hygiene/#threat-model 1/

angdraug,
@angdraug@mastodon.social avatar

Global social networks with algorithmic feeds make #disinfo 10x worse.

A lot of people underestimate how bad it is, for the same reason people underestimated COVID: humans have no intuition for exponents, mechanical metaphors like weight and velocity really don't work for epidemiology.

In a race of exponents, a 0.1% advantage takes only 700 iterations to grow into a 2x advantage. On a platform with a billion users, a 0.1% difference can make one narrative overtake another in hours. 6/

angdraug,
@angdraug@mastodon.social avatar

The main threats to democracy are #war and #disinfo. Mitigating the risk of war has never been as straightforward as today: arm #Ukraine, arm #Taiwan, and let their resistance deter fascist empires from invading their neighbors.

Disinfo is a harder problem. Like cancer, it exploits freedom of speech and other essential aspects of democracy to turn a society against itself. Like with cancer, any treatment has to walk a careful balance to eradicate the disease without killing the host. 5/

rpetrich, to node

I spelunked into steganography to create a new feature in https://www.deciduous.app/ that lets you reimport PNGs and SVGs of your decision trees to derive the underlying YAML.

It involves some neat tricks inspired by Macromedia Fireworks (RIP), so I wrote a blog post about it: https://rpetrich.com/blog/posts/steganographic-trees-deciduous/

Deciduous now also sports a CLI (so you can #npm install it), and a bunch of lil things @shortridge and I added towards the goal of fast, easy, collaborative #threatmodeling of potential failures.

SheHacksPurple, to random

🎉 Level Up Your Threat Modeling Skills with me and @adamshostack! 🚀

Are you ready to master threat modeling? Join us for the "Maturing Your Threat Modeling Skills" @semgrep Community virtual event Jan 25, 9:00 am PT.

https://semgrep.dev/events/maturing-your-threat-modeling-skills/

cigitalgem, (edited ) to ML
@cigitalgem@sigmoid.social avatar

Today we worked on comments (some were toughies) from 8 readers/reviewers of our LLM architectural risk analysis (ARA) draft. BIML plans to release this work 1.24.24

#MLsec #ML #AI #threatmodeling #ARA

But not #AdversarialAI

cR0w, to random

I can't believe that this is still a thing, but if your risk model is noticeably impacted by the adversarial capability of writing an email in the English language then I'm pretty sure your threat model is already broken.

https://www.nbcnews.com/tech/security/nsa-hacker-ai-bot-chat-chatgpt-bard-english-google-openai-rcna133086

cR0w,

User discretion is not a security boundary.

cR0w,

To prove the point that users will continue to click links, regardless of how obvious it is that they shouldn't, I worked with the person in charge of the monthly phishing trainings at $dayjob last month. Historically, they have used the hated ruses like fake gift cards, and I wanted to try to get away from that, especially during the holidays. We ended up using something to the effect of the following:


Hello <first name>,

Happy Holidays. This is the monthly phishing test. Yes, really. It's not a trick. Use the <phishing reporting function> to report this as phishing. If you do not know how to use <phishing reporting function>, feel free to ask a colleague. If you still have questions, search for <phishing reporting function> on <internal docs site>.

Do not click the following link as it is there for metrics and will cause you to be assigned phishing awareness training: <phishing training 'malicious' link>

Sincerely,
IT Security Team

I don't know how well it was received by users, but I do know that we still had more clicks than two other months in 2023, despite being explicitly told not to click the link. Users will always click links with their link-clicking machines. Relying on their discretion is either ignorant, or I expect in some cases, malicious in that there will always be a scapegoat to blame for the inevitable breach.

#phishing #infosec

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The MATCH webinar was recorded and is now available via video
#swsec #appsec #threatmodeling
#MLsec #ML #AI

Proud to have participated with Irius Risk and Calypso AI

https://youtu.be/RI0pNGH9bgA?feature=shared

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The webinar will begin in 5 minutes:
Machine learning
Artificial intelligence
Threat modeling
Compliance
How the heck these link together

cigitalgem, (edited )
@cigitalgem@sigmoid.social avatar

We are underway. Stephen de Vries introducing everyone: Neil Serebryany (calypso), Siebe de Roovere (Toreon) and me.

#MATCH

noplasticshower, to ML
@noplasticshower@zirk.us avatar

I plan to "live toot" this morning's #MLsec #swsec #ML #AI #threatmodeling webinar beginning at 11am NY time (4pm London time) with my @cigitalgem identity. Feel free to follow along using the hashtag #MATCH.

cigitalgem, (edited ) to ai
@cigitalgem@sigmoid.social avatar

With the rise of AI, ML, and increasing compliance demands, the future holds exciting challenges. While we may not have a crystal ball, we've assembled a panel of experts to share their thoughts including Dr Gary McGraw, Stephen de Vries, Siebe De Roovere & Neil Serebryany
Join our webinar to learn just how the heck all of this fits together! https://lnkd.in/eq23dZ8M

Registration - https://www.iriusrisk.com/iriusrisk-match-webinar-2023

#threatmodeling #compliance #securedesign #ai #machinelearning #LLMs #swsec #MLsec

ulf, to random German

The #ThreatModeling Card from @adamshostack keeps the Lights on in my Hotel room while I let my Flipper play with the original key card 😈

cR0w, to ai

I just remembered that @thegrugq let me rant into a larger void about poor #AI #threatmodeling a while back and I should just tap the sign now and then instead of wasting cycles on repeating myself.

https://grugq.substack.com/p/i-refuse-to-bow-to-our-ai-overlords

adamshostack, to random

I had a great time with Chris Romeo on his podcast, “The Threat Modeling Podcast.” I’m honored to be featured on one of his first episodes and would highly recommend anyone with an inkling of an interest in threat modeling check out his work.

We dive deep into the Four Questions framework and explore the meaning and purpose, simplifying the threat modeling process.

Lean into these four questions, and you might just become a threat modeling Jedi! ⚔️

https://threatmodel.buzzsprout.com/2152378/12826352-the-four-question-framework-with-adam-shostack?utm_content=buffere71ad&utm_medium=social&utm_source=bufferapp.com&utm_campaign=buffer

#ThreatModeling

adamshostack,

@SteveBellovin It might be "Why is this knight different from all other knights" 🤣

adamshostack,

@SteveBellovin but really, because someone's lawyer got all munged up about fair use, there's https://github.com/adamshostack/4QuestionFrame :)

raptor, to random
  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • Leos
  • cisconetworking
  • provamag3
  • lostlight
  • All magazines