Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
Dan GoodinD

dangoodin@infosec.exchange

@dangoodin@infosec.exchange
About
Posts
14
Topics
7
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Contrary to what password managers say, a server compromise can mean game over.
    Dan GoodinD Dan Goodin

    Contrary to what password managers say, a server compromise can mean game over.

    https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    @rootwyrm

    I'm not arguing with you. Sorry if it sounds like I am. I don't have the same technical background you do and am asking how the 7.8-severity vuln shouldn't be considered high severity because it involves fonts . . . bounds checking? I'm asking you to explain the reasoning behind your assessment as if I was a student in a security 101 class.

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    @rootwyrm

    CVSS is 7.8, which is high, no? That would seem to support the Anthropic's claim. What's the significance of the vulns being in fonts . . . bounds checking?

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    @rootwyrm

    Right, but the post doesn't say merely that the reports of the 500 vulns resulted in commits. It says all 500 were high-severity. If true, that would be significant, no?

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    Thanks for all the responses. So far, projects I understand to have received reports include: Ghostscript, OpenSC, lzw, and CGIF. Are others known? Links to commits that fix the vulns also appreciated.

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    @rootwyrm

    That's not what Antropic said. Antropic said the vulns were high-severity.

    Uncategorized

  • I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages.
    Dan GoodinD Dan Goodin

    I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages. Has anyone confirmed that these vulns were indeed high-severity and hadn't been discovered before? Is this development as big a deal as Anthropic says? Any other critiques?

    https://red.anthropic.com/2026/zero-days/

    Uncategorized

  • No big deal.
    Dan GoodinD Dan Goodin

    No big deal. Pro-authoritarian Marc only controls the platform that stores terabytes of our conversations in perpetuity.

    https://www.404media.co/marc-benioff-jokes-ice-is-watching-salesforce-employees-who-traveled-to-the-u-s/

    Uncategorized

  • Do any security pros have experience with products from vendor opswat?
    Dan GoodinD Dan Goodin

    @DaveMWilburn

    Super helpful! Thanks. Do customers use opswat at the edge of Networks much? How do they perform there?

    Uncategorized

  • Do any security pros have experience with products from vendor opswat?
    Dan GoodinD Dan Goodin

    Do any security pros have experience with products from vendor opswat? General impressions of the company also appreciated.

    Uncategorized

  • All these reports from security vendors finding that x attacks surged by >100% read just like "umbrella salesman predicts record monsoon season."
    Dan GoodinD Dan Goodin

    All these reports from security vendors finding that x attacks surged by >100% read just like "umbrella salesman predicts record monsoon season."

    Uncategorized

  • The New York Times has done as much as any Big Journalism organization to badmouth San Francisco in recent years.
    Dan GoodinD Dan Goodin

    @dangillmor

    talk about straw men.

    Uncategorized

  • The intruder said he worked for the cartel.
    Dan GoodinD Dan Goodin

    The intruder said he worked for the cartel. After gaining entry to the victim’s home by posing as a courier, he bound the victim’s wrists and ankles with duct tape, doused him with an unknown liquid and threatened to burn down the house.
    After more than an hour inside the Mission Dolores home, the intruder had robbed the victim of $13 million worth of cryptocurrency, pulling off a heist that recent police records suggest was far more violent and sophisticated than was previously known.

    https://www.sfchronicle.com/crime/article/sf-crypto-heist-clues-21333717.php

    Uncategorized

  • Am I the only journalist who would opt to go to jail rather than provide my biometrics to open a device when raided by law enforcement?
    Dan GoodinD Dan Goodin

    Am I the only journalist who would opt to go to jail rather than provide my biometrics to open a device when raided by law enforcement?

    Uncategorized
  • Login

  • Don't have an account? Register

  • Login or register to search.
Powered by NodeBB Contributors
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups