@SteveBellovin@infosec.exchange cover
@SteveBellovin@infosec.exchange avatar

SteveBellovin

@[email protected]

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

This profile is from a federated server and may be incomplete. View on remote instance

@kevinrothrock@infosec.exchange avatar kevinrothrock , to random

The U.S. State Dept is reportedly developing an online portal that will enable people in Europe and elsewhere to see content banned by their govts, "including alleged hate speech and terrorist propaganda," as a way to counter censorship. The site will be hosted at "freedom.gov." https://www.reuters.com/world/us-plans-online-portal-bypass-content-bans-europe-elsewhere-2026-02-18/

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@kevinrothrock Does that include Colbert's interview with Talarico?

@SteveBellovin@infosec.exchange avatar SteveBellovin , to random

I said it during his first term, and I'll repeat it now: what Trump really wants is to be able to prosecute people for lèse-majesté: https://bsky.app/profile/did:plc:fa3rwygrp2ebgwdiq6sjn2te/post/3mf5xgsebzk24

@SteveBellovin@infosec.exchange avatar SteveBellovin , to random

Two stories, side by side, in the NY Times Technology section.

ALT
@w7voa@journa.host avatar w7voa , to random

Airbus, announcing a major recall, says a recent incident involving an A320-family aircraft revealed that solar flares may corrupt data critical to the functioning of flight controls. https://www.reuters.com/business/aerospace-defense/airbus-issues-major-a320-recall-after-flight-control-incident-2025-11-28/

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa Yikes! But I'm quite unclear how a software fix (and in particular reverting to an older version, as opposed to installing new code that keeps multiple widely-spaced copies of the data) can deal with data corruption due to solar flares.

@w7voa@journa.host avatar w7voa , to random

CBS News’ Nancy Cordes: Your DoJ OIG “reported this year that there was thorough vetting by DHS and the FBI of these Afghans who were brought into the US so why do you blame the Biden administration?"

President Trump: “Because they let them in. Are you stupid? Are you a stupid person?”

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa Naturally, the reporter to whom he said that was a woman.

@georgetakei@universeodon.com avatar georgetakei , to random

Powerful.

ALT
SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@georgetakei Reminds me of sidewalk plaques I've seen in Europe. Here are examples from Amsterdam and Rome.

Qui Abitava ROSSANA CALO NATA 1941 ARRESTATA 18.10.1943 Deporta Auschwitz Assassinata 23.10.1943

@evacide@hachyderm.io avatar evacide , to random

I'm re-reading The Big Con, by David Maurer, because I love the argot of early 20th century confidence men, but also because a book about how grifting works holds great explanatory power generations after it was written.

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@evacide A wonderful book.

@w7voa@journa.host avatar w7voa , to random

The White House pardons of last year’s turkeys, Peach and Blossom, declared "null and void” because then-President Biden used an autopen, says President Trump (adding the two birds were then sent on their way to “processing” but he’s now issued a valid pardon for them).

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa His pettiness knows no bounds.

@SteveBellovin@infosec.exchange avatar SteveBellovin , to random

The Trump regime wants to start making a list of Jews (https://www.nytimes.com/2025/11/21/us/eeoc-university-pennsylvania-antisemitism-jewish.html). Now where have I heard that one before?

@evacide@hachyderm.io avatar evacide , to random

I don't usually indulge in "The cost of living has gone up" discourse, but I just paid $120 to repair the soles on a pair of boots and I am ready to storm the Bastille.

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@evacide Watch out for all of the gold leaf trim it's been decorated with of late.

@w7voa@journa.host avatar w7voa , to random

The steep tariffs President Trump issued in August led to a significant contraction in imports and the trade deficit, newly released data shows. https://www.nytimes.com/2025/11/19/us/politics/trumps-tariffs-trade-data.html?smid=nytcore-ios-share

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa Shocked, etc.

@jerry@infosec.exchange avatar jerry , to random

I do feel like MS/Azure, AWS, and Cloudflare need to do a better job of coordinating their outages so some of yall can get some much needed time away from IT

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@jerry Back at Bell Labs, when "the" primary timesharing machine was down (hey, I'm talking early 1980s), it was labeled "theory day".

@kevinrothrock@infosec.exchange avatar kevinrothrock , to random

yep

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@kevinrothrock Well, we knew Trump wanted to build an arch in Washington…

@w7voa@journa.host avatar w7voa , to random

Paul Ingrassia, the president’s embattled nominee to lead the Office of Special Counsel, told a group of fellow Republicans in a text chain the MLK Jr. holiday should be “tossed into the seventh circle of hell” and said he has “a Nazi streak,” according to a text chat viewed by Politico. https://www.politico.com/news/2025/10/20/paul-ingrassia-racist-text-messages-nazi-00613608

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa Only the finest people.

@mattblaze@federate.social avatar mattblaze , to random

Waldorf-Astoria Hotel (and Neighbors), NYC, 2017.

All the pixels, with room services, at https://www.flickr.com/photos/mattblaze/32609074081

ALT
SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@mattblaze According to Mike Wallace's wonderful book "Greater Gotham", the hotel was a merger/peace treaty between two feuding cousins, William Waldorf Astor and John Jacob Astor IV. "A clause in the contract stipulated that the two properties could be sealed off in the event of a falling out."

@w7voa@journa.host avatar w7voa , to random

The president, on his Truth Social account, posts an AI video portraying him as 'King Trump' piloting a fighter jet which drops shit on 'No Kings' demonstrators. https://truthsocial.com/@realDonaldTrump/115398251623299921

image/png

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@w7voa No wonder there were signs today about the Turd Reich.

@SteveBellovin@infosec.exchange avatar SteveBellovin , to random

Best sign I’ve seen thus far: “United we ribbet. Divided we croak.”

@kevinrothrock@infosec.exchange avatar kevinrothrock , to random

I wonder if this still happens if the ICE officer who did this had been wearing a mask, as usual? Remarkable how accountability materializes when there's a face to the violence.

SteveBellovin ,
@SteveBellovin@infosec.exchange avatar

@kevinrothrock @cstross nailed it in “The Annihilation Score”, in 2015.

ALT
  • Reply
  • Loading...
  • @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    lol

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @kevinrothrock From Trump, that was a compliment.

    @briankrebs@infosec.exchange avatar briankrebs , to random

    Whatever this is, it's probably not great. WaPo writes: Pete Hegseth orders rare urgent meeting of hundreds of generals, admirals

    "Defense Secretary Pete Hegseth has ordered hundreds of the U.S. military’s generals and admirals to gather on short notice — and without a stated reason — at a Marine Corps base in Virginia next week, sowing confusion and alarm after the Trump administration’s firing of numerous senior leaders this year."

    "The highly unusual directive was sent to virtually all of the military’s top commanders worldwide, according to more than a dozen people familiar with the matter. The directive was issued earlier this week, as a government shutdown looms, and months after Hegseth’s team at the Pentagon announced plans to undertake a sweeping consolidation of top military commands."

    "In a statement Thursday, Pentagon spokesman Sean Parnell affirmed that Hegseth “will be addressing his senior military leaders early next week,” but he offered no additional details. Parnell, a senior adviser to the defense secretary, voiced no concerns about The Washington Post reporting on the meeting, scheduled for Tuesday in Quantico, Virginia."

    https://www.washingtonpost.com/national-security/2025/09/25/hegseth-generals-quantico-meeting/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @briankrebs I never saw the movie but long ago, I read the book.

    @w7voa@journa.host avatar w7voa , to random

    MSNBC - Former FBI Director James Comey is expected to be indicted in the Eastern District of Virginia in the coming days.

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa The real charge will be lèse-majesté.

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random

    Wow—a treatment for Huntington's: https://www.bbc.com/news/articles/cevz13xkxpro

    @evacide@hachyderm.io avatar evacide , to random

    So how is OpenAI going to know that a user is under 18?

    "We’re building an age-prediction system to estimate age based on how people use ChatGPT."

    https://openai.com/index/teen-safety-freedom-and-privacy/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @evacide I have a two word answer to anyone promising to do that: "error bars". While I'm sure that they can build a system that can reliably distinguish an infant from a senior citizen, I doubt very much that they can reliably distinguish a 17-year-old from a 19-year-old.

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random
    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    hello, fellow countrymen. do any of you have plans to catch the next indians or redskins game? perhaps you will vacation in the gulf of america or scale the mighty mount mckinley? oh, how i love the smell of the department of war in the morning

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @kevinrothrock If he can’t get the Nobel Peace Prize, he’s going to try for the Nobel War Prize.

    @theregister@geeknews.chat avatar theregister Bot , to random

    The Unix Epochalypse might be sooner than you think

    Museum boffins find code that crashes in 2037 A stark warning about the upcoming Epochalypse, also known as the "Year 2038 problem," has come from the past, as National Museum Of Computing system restorers have discovered an unsetting issue while working on ancient systems.…

    https://go.theregister.com/feed/www.theregister.com/2025/08/23/the_unix_epochalypse_might_be/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @theregister A T-shirt I was given some years ago…

    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    Jeez, Trump is now joking that Ukraine suspending elections during wartime might be something to explore in America.

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @kevinrothrock Well, sure; there's lots of precedent in the US for that, like 1864, 1944, 1952, 1968, 1972, and 2004. Oh, wait…

    @evacide@hachyderm.io avatar evacide , to random

    I have injured my shoulder and instead of treating it like a moral failing and working through the pain, I have taken it easy, iced it a lot, and worked on my splits. Please clap.

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @evacide Ouch! Being only lately recovered from a fractured shoulder, I feel your pain. Be well, take it easy, and take care of yourself—that's more important than work. 👏

    @dangillmor@mastodon.social avatar dangillmor , to random

    Reminder that the Trump regime is actively working to wreck public health. Policy is the predictable result, which means the policy here is to make millions of unnecessary deaths in America and around the world much more likely.

    These people are monsters.

    https://apnews.com/article/kennedy-vaccines-mrna-pfizer-moderna-1fb5b9436f2957075064c18a6cbbe3c9?utm_source=onesignal&utm_medium=push&utm_campaign=2025-08-05-Breaking+News

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar
    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random
    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @kevinrothrock We know what radioactive spider bites can do, but what about radioactive wasp stings?

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random

    Nice to know that this battery is made of cotton and is machine-washable.

    ALT
    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random

    Where are we going, and why are we in this handbasket?

    @w7voa@journa.host avatar w7voa , to random

    CBS News - Stephen Colbert's show to end in May 2026 as the network retires The Late Show franchise, which it says is "purely a financial decision." https://www.cbsnews.com/news/the-late-show-stephen-colbert-end-may-2026/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa Profiles in corporate cowardice.

    @ProPublica@newsie.social avatar ProPublica , to random

    When George Mason University president Gregory Washington received notice that the Trump administration had opened an investigation into complaints of antisemitism, he was “perplexed.”

    But there are signs it may be part of a coordinated campaign to oust him.
    https://www.propublica.org/article/george-mason-university-antisemitism-investigation-trump?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @ProPublica And by a curious coincidence, the president of the university is a Black man.

    @w7voa@journa.host avatar w7voa , to random

    To celebrate the Nation’s Semiquincentennial, the US Mint will be making changes to most of its circulating coins. Final designs set to be shared with the public later this year. https://www.usmint.gov/coins/coin-programs/semiquincentennial/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa What are the odds that the new coinage will have something Trump-centric?

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random

    I swear, as I was scrolling I thought this was an Onion headline.
    https://flipboard.com/@newyorktimes/science-jpuunj5gz/-/a-KhzVHy5QRYm-yk515emFNQ%3Aa%3A3195393-%2F0

    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    I think I learned this years ago and shamefully forgot, but today I re-learned that strategic bombers don’t actually carry nuclear warheads on “patrol flights.” The whole thing is for show. (A happy surprise to me, a layman.)

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar
    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    The unfortunate “Pearl Harbor” analogy for Sunday’s drone operation must belong to the same historically illiterate spindoctors who decided to refer to Ukraine’s European allies as the “Coalition of the Willing.”

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @kevinrothrock True fact: the US Navy wargamed an attack on Pearl Harbor by carrier-based Japanese planes in May 1941, but forgot about it. (Source: a document in the Friedman Collection of papers released by the NSA. But it will be a few weeks before I can dig up the precise URL.)

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random
    @w7voa@journa.host avatar w7voa , to random

    A tall ship of the Mexican Navy has struck the Brooklyn Bridge. https://abc7ny.com/post/ship-strikes-brooklyn-bridge-emergency-response/16453075/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa I saw a number of Mexican Navy sailors yesterday, on the subway and in Central Park. Now I know what they were doing around here.

    @w7voa@journa.host avatar w7voa , to random

    "We are aware of the recent social media post by former FBI Director James Comey, directed at President Trump. We are in communication with the Secret Service and Director Curran,” says FBI Director Kash Patel, reacting to Comey’s “86 47” seashell arrangement on Instagram.

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa Per https://en.wikipedia.org/wiki/86_(term) it's mostly for just getting rid of someone or something, but occasionally can be used with a violent meaning.

    @w7voa@journa.host avatar w7voa , to random

    WPIX TV - Newark Mayor Ras Baraka was taken into custody by DHS at an ICE facility in New Jersey this afternoon. https://pix11.com/news/local-news/newark-mayor-ras-baraka-taken-into-custody-by-ice-in-new-jersey/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa Note that Baraka is also a candidate in the NJ Democratic primary for governor.

    @w7voa@journa.host avatar w7voa , to random

    Columbia Spectator - Barnard and Columbia have issued interim suspensions to four student journalists who covered a pro-Palestinian protest in Butler Library. https://www.columbiaspectator.com/news/2025/05/09/barnard-suspends-wkcr-and-spectator-reporters-who-covered-butler-library-protest/

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa As a Columbia faculty member, Columbia alum, and former student journalist at Columbia during a time of turmoil and building occupations, I'm glad that the interim suspensions have been lifted—but they never should have been imposed in the first place. I can tell you that back then, being able to identify myself as a journalist was a serious concern, especially because at the time NYC press credentials were issued by the police department (https://www.nyc.gov/site/mome/press-card/press-card.page) and only to "members of the working press".

    @w7voa@journa.host avatar w7voa , to random

    Politico - The Trump administration has ordered State Department employees to report on any instances of coworkers displaying “anti-Christian bias." https://www.politico.com/news/2025/04/11/state-report-anti-christian-bias-033535

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @w7voa Hmm: Matthew 25:40 says ‘Verily I say unto you, inasmuch as ye have done it unto one of the least of these My brethren, ye have done it unto Me.’ Does bashing the poor, the sick, the immigrants count as anti-Christian bias? And as for Musk, there’s Matthew 19:23-24: “Truly I tell you, it is hard for someone who is rich to enter the kingdom of heaven. Again I tell you, it is easier for a camel to go through the eye of a needle than for someone who is rich to enter the kingdom of God.”

    @arstechnica@mastodon.social avatar arstechnica , to random

    Are new Google E2EE emails really end-to-end encrypted? Kinda, but not really.
    Yes, encryption/decryption occurs on end-user devices, but there's a catch.
    https://arstechnica.com/security/2025/04/are-new-google-e2ee-emails-really-end-to-end-encrypted-kinda-but-not-really/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @arstechnica There's another problem here. If the encryption is being done client-side by any browser, it's being done by JavaScript—and who knows what the JavaScript is doing? I call this the trust-binding problem. When you download software or an update to it, you're making your decision to trust the vendor at that point. With JavaScript encryption and decryption, you're making that decision every time you load the page. This is a very different concept, and one that isn't make clear to users. (In theory, there could be browser extensions to do the encryption and decryption, but that's not easy for users, and there are many different browsers out there, with very different policies on extensions.)

    @briankrebs@infosec.exchange avatar briankrebs , to random

    Let's be honest: Haven't we all at one point drunk texted a reporter an invitation to discuss plans for an upcoming military attack? Something tells me Hegseth will be hitting the sauce pretty hard tonight.

    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @briankrebs The story would have been much more believable in that sense if it had been Hegseth who first invited the journalist…

    @SteveBellovin@infosec.exchange avatar SteveBellovin , to random

    The official statement from Columbia is at https://president.columbia.edu/content/fulfilling-our-commitments. The link to that was in an email so bland and uninformative that I ignored the links (one of which doesn't work anyway).

    My undergrad degree is from Columbia, and I'm a faculty member for a few more months, though no longer teaching. I intend to continue wearing my mask, since I wear it for health reasons and not “for the purpose of concealing one’s identity in the commission of violations of University policies or state, municipal or federal laws.” After all, it's for health reasons, which is explicitly permitted by policy. My next step: an email to my chair and the dean. I have two thesis defenses coming up this semester; other than those, I don't need to be inside any campus buildings, and I'll run the defenses over Zoom if I have to.
    https://flipboard.com/@newyorktimes/new-york-bat3un55z/-/a-0zIWJwAfQXmPJsJLILatFg%3Aa%3A3195393-%2F0

    @briankrebs@infosec.exchange avatar briankrebs , (edited ) to random

    Someone riddle me this: Why would Trump's Jan. 29 Executive Order on "Additional Measures to Combat Anti-Semitism" be given the executive order number it has, which is 14188? Surely, even with the flood of EOs this POTUS has issued already, we're not up to that number.

    So where did it come from? Check out the Wikipedia entry for "fourteen words," also abbreviated 14 or 1488), which says it is a reference to "two slogans originated by the American domestic terrorist David Eden Lane, one of nine founding members of the defunct white supremacist terrorist organization The Order, and are accompanied by Lane's "88 Precepts". The slogans have served as a rallying cry for militant white nationalists internationally."

    "Lane used the 14-88 numerical coding extensively throughout his spiritual, political, religious, esoteric, and philosophical tracts and notably in his "88 Precepts" manifesto. According to the Southern Poverty Law Center, inspiration for the Fourteen Words "are derived from a passage in Adolf Hitler's autobiographical book Mein Kampf."

    "The Fourteen Words have been prominently used by neo-Nazis, white power skinheads and certain white nationalists and the alt-right. "88" is used by some as a shorthand for "Heil Hitler", 'H' being the 8th letter of the alphabet,[16] though Lane viewed Nazism along with America as being part of the "Zionist conspiracy."

    [edit: several readers have rightly pointed out that this is likely just a coincidence, and that the EOs are cumulatively numbered already into the 14,000s. still, it's unfortunate]

    https://en.m.wikipedia.org/wiki/Fourteen_Words

    ALT
    SteveBellovin ,
    @SteveBellovin@infosec.exchange avatar

    @briankrebs Many years ago, I was on the Internet Architecture Board. The IAB and the Internet Engineering Steering Group were about to issue an RFC on cryptography policy. Looking at the RFC numbers published around then, I sent a note to Jon Postel, the RFC editor, and asked if we could have RFC 1984. He replied, "We never reserve RFC numbers—but coincidences can happen." Guess what number the eventual RFC had…