# Shostack & Friends Blog

Security, privacy, economics and unrelated topics since 2005

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Application and AI roundup - October

DevFeed: [Application and AI roundup - October](<https://devfeed.tech/articles/application-and-ai-roundup-october-36684.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-oct-2023/>)

Author: Adam

Published: 2023-11-09T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Adversarial attacks](<https://devfeed.tech/topics/adversarial-attacks.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [browser](<https://devfeed.tech/topics/browser.md>), [okta](<https://devfeed.tech/topics/okta.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [browser](<https://devfeed.tech/tags/browser.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [okta](<https://devfeed.tech/tags/okta.md>), [security](<https://devfeed.tech/tags/security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An October roundup covering the SEC's case against SolarWinds and its CISO, research on vulnerabilities in large language models and adversarial attacks, AI policy and model behavior, and threat-modeling issues involving browser privacy, Okta's support system, and bug hunting.

### Source excerpt

Exciting news from the SEC, lots of AI, and lots of threat modeling.

## Security Principles in 2023

DevFeed: [Security Principles in 2023](<https://devfeed.tech/articles/security-principles-in-2023-36970.md>)

Original publisher: [Read original article](<https://shostack.org/blog/security-principles-in-2023/>)

Author: Adam

Published: 2023-10-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [design](<https://devfeed.tech/tags/design.md>), [developer](<https://devfeed.tech/tags/developer.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>)

### AI overview

The author reflects on how their view of security design principles has changed. Although many principles remain valid, they are harder to learn, apply, teach, and assess consistently than threat modeling techniques because they require abstraction, careful analysis, and comparison of possible designs.

### Source excerpt

Principles are lovely, but do they lead us to actionable results?

## Adversarial Thinking and Wargames

DevFeed: [Adversarial Thinking and Wargames](<https://devfeed.tech/articles/adversarial-thinking-and-wargames-36660.md>)

Original publisher: [Read original article](<https://shostack.org/blog/adversarial-thinking-wargames/>)

Author: Adam

Published: 2023-10-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Learning](<https://devfeed.tech/topics/learning.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

The article examines how military wargames teach strategy and adversarial thinking, then compares that approach with commercial cybersecurity. It argues that cybersecurity teams primarily enable business goals rather than defeat an enemy.

### Source excerpt

Thinking about adversarial thinking

## Threat Modeling on Sale

DevFeed: [Threat Modeling on Sale](<https://devfeed.tech/articles/threat-modeling-on-sale-37044.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-on-sale/>)

Author: Adam

Published: 2023-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A one-day Amazon sale offers Threat Modeling: Designing for Security for $4.99, which the author describes as the lowest price they remember. The author also asks readers who enjoyed the book to leave a rating or review.

### Source excerpt

Best price ever for Threat Modeling

## Application and AI roundup - September

DevFeed: [Application and AI roundup - September](<https://devfeed.tech/articles/application-and-ai-roundup-september-36687.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-september/>)

Author: Adam

Published: 2023-10-04T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [c/c++](<https://devfeed.tech/topics/c-c-plus-plus.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Zig](<https://devfeed.tech/topics/zig.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [development](<https://devfeed.tech/tags/development.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>)

### AI overview

A September roundup covering application security developments involving memory safety, C and C++, Zig, hardware memory tagging, secure-by-design AI guidance, cybersecurity policy for medical devices, and open-source software security.

### Source excerpt

September was a big month in appsec for both memory safety and policy

## FDA Releases Final Cybersecurity Guidance for Medical Devices

DevFeed: [FDA Releases Final Cybersecurity Guidance for Medical Devices](<https://devfeed.tech/articles/fda-final-cyber-guidance-is-out-36789.md>)

Original publisher: [Read original article](<https://shostack.org/blog/fda-final-cyber-guidance/>)

Author: Adam

Published: 2023-09-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [medical-devices](<https://devfeed.tech/tags/medical-devices.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [sdl](<https://devfeed.tech/tags/sdl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The FDA released final cybersecurity guidance for medical devices, replacing guidance that was nearly nine years old. The article says it is detailed and product-focused, and discusses its expected effects on medical device submissions, other regulatory guidance, and product liability litigation.

### Source excerpt

The FDA has released their new guidance, which will be broadly impactful.

## Comparing Retrospectives

DevFeed: [Comparing Retrospectives](<https://devfeed.tech/articles/comparing-retrospectives-36733.md>)

Original publisher: [Read original article](<https://shostack.org/blog/comparing-retrospectives/>)

Author: Adam

Published: 2023-09-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [retrospectives](<https://devfeed.tech/topics/retrospectives.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [design](<https://devfeed.tech/tags/design.md>), [forensic](<https://devfeed.tech/tags/forensic.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [report](<https://devfeed.tech/tags/report.md>), [retention](<https://devfeed.tech/tags/retention.md>), [retrospectives](<https://devfeed.tech/tags/retrospectives.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article compares Microsoft's retrospective on the Storm-0558 key acquisition with Thornton Tomasetti's forensic investigation of the Arecibo Telescope collapse. It argues that retrospectives preserve authoritative accounts, support organizational learning, and reassure stakeholders, while contrasting the reports' length, authorship, and treatment of evidence. It also examines log retention as a security design choice.

### Source excerpt

We can learn a lot from comparing retrospectives

## Open training: Threat Modeling for Champs (October)

DevFeed: [Open training: Threat Modeling for Champs (October)](<https://devfeed.tech/articles/open-training-threat-modeling-for-champs-october-37036.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-for-security-champs/>)

Author: Adam

Published: 2023-09-14T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [course](<https://devfeed.tech/tags/course.md>), [security](<https://devfeed.tech/tags/security.md>), [skills](<https://devfeed.tech/tags/skills.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

An October Threat Modeling for Security Champs course offers five instructor-led discussions over one week alongside self-paced work. The training is intended for technology professionals with prior threat-modeling experience and includes a skills assessment to gauge readiness.

### Source excerpt

Seats are available in our October training

## Application and AI roundup - August

DevFeed: [Application and AI roundup - August](<https://devfeed.tech/articles/application-and-ai-roundup-august-36676.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-aug/>)

Author: Adam

Published: 2023-08-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [LLMs](<https://devfeed.tech/topics/llms.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [llms](<https://devfeed.tech/tags/llms.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An August roundup of articles and developments covering large language models, AI product development, AI threats, application security, threat modeling, OpenSSH sandboxing, regulatory requirements, and Amazon's Threat Composer tool.

### Source excerpt

Lots of interesting work in LLMs (again)

## ML Sec Ops: Feature with Diana Kelley

DevFeed: [ML Sec Ops: Feature with Diana Kelley](<https://devfeed.tech/articles/ml-sec-ops-feature-with-diana-kelley-36892.md>)

Original publisher: [Read original article](<https://shostack.org/blog/ml-sec-ops/>)

Author: Kris

Published: 2023-08-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai-ml](<https://devfeed.tech/tags/ai-ml.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [podcast](<https://devfeed.tech/tags/podcast.md>)

### AI overview

Adam appeared on the ML Sec Ops podcast with Diana Kelley, CISO at Protect AI, to discuss the state of AI and ML security, major threats, and current priorities for the machine learning security field.

### Source excerpt

Adam featured on ML Sec Ops podcast

## Use the Defcon Wifi

DevFeed: [Use the Defcon Wifi](<https://devfeed.tech/articles/use-the-defcon-wifi-37100.md>)

Original publisher: [Read original article](<https://shostack.org/blog/use-the-defcon-wifi/>)

Author: Adam

Published: 2023-08-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Bluetooth](<https://devfeed.tech/topics/bluetooth.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [defcon](<https://devfeed.tech/tags/defcon.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [networks](<https://devfeed.tech/tags/networks.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>), [wifi](<https://devfeed.tech/tags/wifi.md>)

### AI overview

The article argues that using the official Defcon Wi-Fi can be reasonable when devices are fully patched, users join the official networks, and applications use TLS. It contrasts this with the risks of cellular infrastructure and notes that airplane mode does not disable Bluetooth or Wi-Fi; a Faraday cage provides stronger isolation.

### Source excerpt

Why it's ok to use the Defcon wifi

## SEC Cybersecurity Rules

DevFeed: [SEC Cybersecurity Rules](<https://devfeed.tech/articles/sec-cybersecurity-rules-36966.md>)

Original publisher: [Read original article](<https://shostack.org/blog/sec-cybersecurity-rules/>)

Author: Adam

Published: 2023-08-01T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This commentary reviews the SEC's new cybersecurity rules, including a requirement to disclose material cybersecurity breaches within four days. It discusses the rule's focus on incident impacts, prompt investor reporting, aggregation of incidents, and the author's concerns about limiting technical details and failing to learn from past events.

### Source excerpt

The SEC has important new cybersecurity rules

## Chuck, Acme, and Remediation Avoidance

DevFeed: [Chuck, Acme, and Remediation Avoidance](<https://devfeed.tech/articles/chuck-acme-and-remediation-avoidance-36727.md>)

Original publisher: [Read original article](<https://shostack.org/blog/chuck-acme-remediation-avoidance/>)

Author: Adam

Published: 2023-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [cost-savings](<https://devfeed.tech/tags/cost-savings.md>), [integration](<https://devfeed.tech/tags/integration.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article discusses how automated threat modeling may reduce remediation costs and improve efficiency, using findings from a Forrester report and a hypothetical company, Acme, to illustrate the challenges of discovering security issues late through penetration testing.

### Source excerpt

Threat modeling really CAN save you money, just ask Chuck!

## Threat Modeling and Secure by Design

DevFeed: [Threat Modeling and Secure by Design](<https://devfeed.tech/articles/threat-modeling-and-secure-by-design-36728.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cisa-secure-by-design-feedback/>)

Author: Adam

Published: 2023-07-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [complex](<https://devfeed.tech/tags/complex.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>)

### AI overview

The Threat Modeling Manifesto team published feedback to CISA responding to its Secure by Design Guidance. The feedback takes the form of a detailed letter, which was also covered by Infosecurity Magazine.

### Source excerpt

Our feedback to CISA is now public

## A proposal to rate-limit Windows' CreateFile API to slow ransomware

DevFeed: [A proposal to rate-limit Windows' CreateFile API to slow ransomware](<https://devfeed.tech/articles/microsoft-can-fix-ransomware-tomorrow-36888.md>)

Original publisher: [Read original article](<https://shostack.org/blog/microsoft-can-fix-ransomware-tomorrow/>)

Author: Adam

Published: 2023-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article argues that Microsoft could reduce ransomware's impact by rate-limiting Windows' CreateFile API, which ransomware uses to open files before encrypting them. The proposed limit could slow attacks and give defensive tools more time to detect them.

### Source excerpt

My latest at Dark Reading draws attention to how Microsoft can fix ransomware tomorrow.

## Worthwhile Books Q2 2023

DevFeed: [Worthwhile Books Q2 2023](<https://devfeed.tech/articles/worthwhile-books-q2-2023-37131.md>)

Original publisher: [Read original article](<https://shostack.org/blog/worthwhile-books-q2-2023/>)

Author: Adam

Published: 2023-06-28T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [books](<https://devfeed.tech/tags/books.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [password](<https://devfeed.tech/tags/password.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

A quarterly reading list covering books about cybersecurity, passwords, machine-learning security attacks, zero trust, technology history, and technical writing, along with memoirs and other nonfiction.

### Source excerpt

Books that I read in the second quater that are worth your time include two memoirs, a great book on the security of ML, and more!

## AI-assisted programming can speed development while increasing abstraction and technical debt

DevFeed: [AI-assisted programming can speed development while increasing abstraction and technical debt](<https://devfeed.tech/articles/ai-will-be-the-high-interest-credit-card-of-2023-36663.md>)

Original publisher: [Read original article](<https://shostack.org/blog/ai-high-interest-credit-card/>)

Author: Adam

Published: 2023-06-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [jupyter notebooks](<https://devfeed.tech/topics/jupyter-notebooks.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Python](<https://devfeed.tech/topics/python.md>), [pair\_programming](<https://devfeed.tech/topics/pair-programming.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [appsec](<https://devfeed.tech/tags/appsec.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [jupyter-notebooks](<https://devfeed.tech/tags/jupyter-notebooks.md>), [pair-programming](<https://devfeed.tech/tags/pair-programming.md>), [programming](<https://devfeed.tech/tags/programming.md>), [python](<https://devfeed.tech/tags/python.md>)

### AI overview

The author reflects on using ChatGPT, GitHub Copilot, pair programming, and Jupyter Notebooks while learning Python and producing graphs. The experience accelerated development and debugging, but raised concerns about code quality, application security, abstraction, and the faster accumulation of technical debt.

### Source excerpt

AI will be the high interest credit card of 2023 I haven't done a lot of work in Python, and I've never used it to produce graphs. But after an hour of pair programming and then using Chatgpt and Github Copilot got me quite far in writing a set of Jupyter Notebooks, and dramatically shrunk the effort to use and debug a new tool. I wanted to record some thoughts on the experience, and what it means for programming and for application security.

## AppSecPNW 2023

DevFeed: [AppSecPNW 2023](<https://devfeed.tech/articles/appsecpnw-2023-36688.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsecpnw2023/>)

Author: Adam

Published: 2023-06-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [event](<https://devfeed.tech/tags/event.md>), [keynote](<https://devfeed.tech/tags/keynote.md>)

### AI overview

The author reports delivering the opening keynote at OWASP's AppSec PNW 2023 in Portland and provides the presentation slides.

### Source excerpt

Adam's AppSecPNW 2023 keynote

## Phishing Defenses

DevFeed: [Phishing Defenses](<https://devfeed.tech/articles/phishing-defenses-36934.md>)

Original publisher: [Read original article](<https://shostack.org/blog/phishing-defense/>)

Author: Adam

Published: 2023-06-07T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Users](<https://devfeed.tech/topics/users.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [cost](<https://devfeed.tech/tags/cost.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [email](<https://devfeed.tech/tags/email.md>), [people](<https://devfeed.tech/tags/people.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

This commentary examines phishing defenses and argues that telling users to avoid bad links and relying on defense in depth may impose costs without necessarily being effective. It considers user behavior, suspicious-email reporting, and the value of security training.

### Source excerpt

Phishing behaviors, as observed in the wild.

## Application Security and AI Roundup - May

DevFeed: [Application Security and AI Roundup - May](<https://devfeed.tech/articles/application-and-ai-roundup-may-36682.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-may-2023/>)

Author: Adam

Published: 2023-05-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [openai](<https://devfeed.tech/tags/openai.md>), [passwords](<https://devfeed.tech/tags/passwords.md>)

### AI overview

A May roundup covering AI safety and security developments, application security concerns, vulnerabilities in DNA sequencing devices, and Google Authenticator's planned end-to-end encryption. It also discusses risks in LLMs, ChatGPT Enterprise, GPT-4, and AI-assisted code analysis.

### Source excerpt

This month runs quite heavy on AI, but the CISA Safe by Design and Default document is going to be important for the next several years.

## The Cyber Safety Review Board Should Investigate Major Historical Incidents

DevFeed: [The Cyber Safety Review Board Should Investigate Major Historical Incidents](<https://devfeed.tech/articles/the-cyber-safety-review-board-should-investigate-major-historical-incidents-36749.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cyber-safety-review-board-historical-incidents/>)

Author: Adam

Published: 2023-05-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [solarwinds](<https://devfeed.tech/topics/solarwinds.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [incident](<https://devfeed.tech/tags/incident.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>)

### AI overview

The article argues that the U.S. Cyber Safety Review Board should investigate major historical cyber incidents, beginning with SolarWinds, to build a respected shared history of cyber incidents. It notes that the board has not investigated SolarWinds and highlights its report on the open source Log4Shell vulnerabilities as clear and helpful.

### Source excerpt

Tarah Wheeler and Adam write in CFR

## Star Wars Day Security Content and Discounts

DevFeed: [Star Wars Day Security Content and Discounts](<https://devfeed.tech/articles/may-the-fourth-secure-you-36878.md>)

Original publisher: [Read original article](<https://shostack.org/blog/may-the-fourth-secure-you/>)

Author: Adam

Published: 2023-05-04T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [digital](<https://devfeed.tech/topics/digital.md>), [email](<https://devfeed.tech/topics/email.md>)

Tags: [digital](<https://devfeed.tech/tags/digital.md>), [email](<https://devfeed.tech/tags/email.md>), [security](<https://devfeed.tech/tags/security.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A Star Wars Day announcement highlighting security-related video and podcast content, including material about email and threat modeling, along with discounts.

### Source excerpt

Celebrating Star Wars Day in style!

## Layoffs in Responsible AI Teams

DevFeed: [Layoffs in Responsible AI Teams](<https://devfeed.tech/articles/layoffs-in-responsible-ai-teams-36956.md>)

Original publisher: [Read original article](<https://shostack.org/blog/responsible-ai-layoffs/>)

Author: Adam

Published: 2023-04-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [responsible-ai](<https://devfeed.tech/topics/responsible-ai.md>), [ai-ethics](<https://devfeed.tech/topics/ai-ethics.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Twitch](<https://devfeed.tech/topics/twitch.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-ethics](<https://devfeed.tech/tags/ai-ethics.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [twitch](<https://devfeed.tech/tags/twitch.md>)

### AI overview

This opinion examines layoffs in responsible AI teams at companies including Microsoft and Twitch. It argues that ethical AI work may need to become more actionable for software development, while also noting the need for transparency, accountability, and regulation of AI systems.

### Source excerpt

Some inferences from layoffs in responsible AI teams

## Five Threat Model Diagrams for Machine Learning

DevFeed: [Five Threat Model Diagrams for Machine Learning](<https://devfeed.tech/articles/five-threat-model-diagrams-for-machine-learning-36796.md>)

Original publisher: [Read original article](<https://shostack.org/blog/five-threat-model-diagrams-for-ml/>)

Author: Adam

Published: 2023-04-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Training AI Models](<https://devfeed.tech/topics/training-ai-models.md>), [Data Quality](<https://devfeed.tech/topics/data-quality.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai-and-cybersecurity](<https://devfeed.tech/tags/ai-and-cybersecurity.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-quality](<https://devfeed.tech/tags/data-quality.md>), [diagram](<https://devfeed.tech/tags/diagram.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [training-data](<https://devfeed.tech/tags/training-data.md>)

### AI overview

This article presents five threat-model diagrams for machine learning systems. The diagrams distinguish threats to and from ML systems, illustrate data flows and responses, and examine how training-data sources and system-design decisions can create risks. The author emphasizes that the diagrams are illustrative rather than complete and notes uncertainty about the model of how Twitter content reached Microsoft's Tay.

### Source excerpt

Some diagrams to help clarify machine learning threats

[Next page](<https://devfeed.tech/sources/shostack-friends-blog.md?cursor=WyIyMDIzLTA0LTEzVDAwOjAwOjAwKzAwOjAwIiwgIjVmY2ZmOWQ5LTg2NzktNGYxMC05YTQxLWIyOTI5Y2YyOGZlOCJd>)