Profile

unixronin: Galen the technomage, from Babylon 5: Crusade (Default)
Unixronin

December 2012

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Most Popular Tags

Expand Cut Tags

No cut tags
Thursday, September 18th, 2025 07:29 am
Air temperature 58 F, wind southwest about 5 mph, overcast. Light mist or shower overnight, drying off now. Watered the salvia in the planter out front anyway. Asters and chicory doing their evasive maneuvers, blooming below blade height in mowed areas when they'd really prefer to be 2' tall.
Thursday, September 18th, 2025 11:06 am

Posted by Bruce Schneier

This is a nice piece of research: “Mind the Gap: Time-of-Check to Time-of-Use Vulnerabilities in LLM-Enabled Agents“.:

Abstract: Large Language Model (LLM)-enabled agents are rapidly emerging across a wide range of applications, but their deployment introduces vulnerabilities with security implications. While prior work has examined prompt-based attacks (e.g., prompt injection) and data-oriented threats (e.g., data exfiltration), time-of-check to time-of-use (TOCTOU) remain largely unexplored in this context. TOCTOU arises when an agent validates external state (e.g., a file or API response) that is later modified before use, enabling practical attacks such as malicious configuration swaps or payload injection. In this work, we present the first study of TOCTOU vulnerabilities in LLM-enabled agents. We introduce TOCTOU-Bench, a benchmark with 66 realistic user tasks designed to evaluate this class of vulnerabilities. As countermeasures, we adapt detection and mitigation techniques from systems security to this setting and propose prompt rewriting, state integrity monitoring, and tool-fusing. Our study highlights challenges unique to agentic workflows, where we achieve up to 25% detection accuracy using automated detection methods, a 3% decrease in vulnerable plan generation, and a 95% reduction in the attack window. When combining all three approaches, we reduce the TOCTOU vulnerabilities from an executed trajectory from 12% to 8%. Our findings open a new research direction at the intersection of AI safety and systems security.

Wednesday, September 17th, 2025 02:58 pm
"Buy on the rumor, sell on the fact."
Wednesday, September 17th, 2025 11:05 am

Posted by Bruce Schneier

Vulnerabilities in electronic safes that use Securam Prologic locks:

While both their techniques represent glaring security vulnerabilities, Omo says it’s the one that exploits a feature intended as a legitimate unlock method for locksmiths that’s the more widespread and dangerous. “This attack is something where, if you had a safe with this kind of lock, I could literally pull up the code right now with no specialized hardware, nothing,” Omo says. “All of a sudden, based on our testing, it seems like people can get into almost any Securam Prologic lock in the world.”

[…]

Omo and Rowley say they informed Securam about both their safe-opening techniques in spring of last year, but have until now kept their existence secret because of legal threats from the company. “We will refer this matter to our counsel for trade libel if you choose the route of public announcement or disclosure,” a Securam representative wrote to the two researchers ahead of last year’s Defcon, where they first planned to present their research.

Only after obtaining pro bono legal representation from the Electronic Frontier Foundation’s Coders’ Rights Project did the pair decide to follow through with their plan to speak about Securam’s vulnerabilities at Defcon. Omo and Rowley say they’re even now being careful not to disclose enough technical detail to help others replicate their techniques, while still trying to offer a warning to safe owners about two different vulnerabilities that exist in many of their devices.

The company says that it plans on updating its locks by the end of the year, but have no plans to patch any locks already sold.

Wednesday, September 17th, 2025 06:54 am
Air temperature 48 F, wind near calm, partly cloudy. Appointment early, then foraging later. You'll have to save the world without me.

(Yes, the title is redundant . . .)
Tuesday, September 16th, 2025 12:17 pm
Here's the worst thing about all this Charlie Kirk idolatry – the threats of firing and deportation and confiscation of passport and all the other shit the red-caps are doing – it's not because the people pulling the strings actually care about Kirk. Trump didn't even bother to go to the "vigil" at the Kennedy Center, he played golf instead. (perhaps because Kirk was in favor of releasing the Epstein files?)

It's a test-run. If they can get away with getting people fired or deported or jailed for "saying things that make them sad about some guy who incited hatred and violence", then they can do it for nearly anything. Criticize the cops? Jail. Organize a protest against ICE? Jail. Write a post critical of Stephen Miller? Jail. Be a member of a militia that's not right wing? (e.g.: Pink Pistols) Jail.

And make no mistake: When Trump finally has a stroke or heart attack or whatever and the republican party collapses with no cult figurehead to maintain a semblance of cohesion and the democrats are back in power, they're going to do exactly the same thing, but with friendlier words.
Tuesday, September 16th, 2025 12:03 pm
The fruit used to be called a napple. But it sounded a lot like "an apple", so the "n" got removed.

The snake used to be called a nadder.

The cloth thing you wear to protect your clothes used to be a napron.


I learned today that I'd been using (spelling? pronouncing?) "a semblance" wrong since forever. It's not "an assemblance" It's "a semblance"

I'm 100% sure there's a linguistic term for this spelling/pronunciation error/change, but I can't remember what it's called.
Tuesday, September 16th, 2025 10:31 am
City mower herding the gulls around the park. They don't want to leave whatever mayhem they pursue. And I'm sure the mower leaves a swath of injured bugs behind.
Tuesday, September 16th, 2025 11:06 am

Posted by Bruce Schneier

Senator Ron Wyden has asked the Federal Trade Commission to investigate Microsoft over its continued use of the RC4 encryption algorithm. The letter talks about a hacker technique called Kerberoasting, that exploits the Kerberos authentication system.

Tuesday, September 16th, 2025 07:04 am
Air temperature 48 F, wind near calm, partly cloudy claimed at the airport but hazy clear out my window. I have turned up the heat for a couple of mornings now. We still need rain.
Monday, September 15th, 2025 06:37 pm
Gulls advancing in skirmish lines across the park.
Monday, September 15th, 2025 05:54 pm
I do not exist.
Monday, September 15th, 2025 11:05 am

Posted by Bruce Schneier

Attaullah Baig, WhatsApp’s former head of security, has filed a whistleblower lawsuit alleging that Facebook deliberately failed to fix a bunch of security flaws, in violation of its 2019 settlement agreement with the Federal Trade Commission.

The lawsuit, alleging violations of the whistleblower protection provision of the Sarbanes-Oxley Act passed in 2002, said that in 2022, roughly 100,000 WhatsApp users had their accounts hacked every day. By last year, the complaint alleged, as many as 400,000 WhatsApp users were getting locked out of their accounts each day as a result of such account takeovers.

Baig also allegedly notified superiors that data scraping on the platform was a problem because WhatsApp failed to implement protections that are standard on other messaging platforms, such as Signal and Apple Messages. As a result, the former WhatsApp head estimated that pictures and names of some 400 million user profiles were improperly copied every day, often for use in account impersonation scams.

More news coverage.

Monday, September 15th, 2025 06:56 am
Air temperature 50 F, wind near calm, sunny. Gulls driving game on the far side of the park, whatever their game may be. Walk later. Still not interested in power over others.
Sunday, September 14th, 2025 04:02 pm

Posted by B. Schneier

This is a current list of where and when I am scheduled to speak:

  • I’m speaking and signing books at the Cambridge Public Library on October 22, 2025 at 6 PM ET. The event is sponsored by Harvard Bookstore.
  • I’m giving a virtual talk about my book Rewiring Democracy at 1 PM ET on October 23, 2025. The event is hosted by Data & Society. More details to come.
  • I’m speaking at the World Forum for Democracy in Strasbourg, France, November 5-7, 2025.
  • I’m speaking and signing books at the University of Toronto Bookstore in Toronto, Ontario, Canada on November 14, 2025. Details to come.
  • I’m speaking with Crystal Lee at the MIT Museum in Cambridge, Massachusetts, USA, on December 1, 2025. Details to come.
  • I’m speaking and signing books at the Chicago Public Library in Chicago, Illinois, USA, on February 5, 2026. Details to come.

The list is maintained on this page.

Sunday, September 14th, 2025 10:13 am
Accomplishment maybe. We have seal-coated about 90% of the driveway and run out of seal. Now, do I leave it as is or buy another pail of seal and finish an edge we never use, then double coat the actual 10' path we drive over? Anyway, done for the day.
Sunday, September 14th, 2025 07:07 am
Air temperature 55 F, wind southeast about 3 mph, cloudy. Alleged to be showers in the vicinity. Gulls working the park. Whatever is drawing them seems to be continuing, and doesn't extend to our "lawn" and those of our neighbors.
Saturday, September 13th, 2025 06:47 pm
No Man Is an Island

No man is an island,
Entire of itself;
Every man is a piece of the continent,
A part of the main.

If a clod be washed away by the sea,
Europe is the less,
As well as if a promontory were:
As well as if a manor of thy friend's
Or of thine own were.

Any man's death diminishes me,
Because I am involved in mankind.
And therefore never send to know for whom the bell tolls;
It tolls for thee.
Saturday, September 13th, 2025 11:41 am
The large brilliant purple asters have started blooming on this route. Most of the loosestrife is done, phragmites seed heads nodding in the breeze, chicory and goats-beard still blooming.

No interesting metal birds out at the airport, but had a group of geese browsing the roadside grass along the dead-end spur of road leading to the fence gate. One of them kept a wary eye on me as I rode past, both ways.

Either a mink or a young otter lay dead next to the road, dark brown fur, weasel shape, furry tail. Also, gray squirrel and probable red squirrel dead on the asphalt, all at different locations.

Got out on the bike, mid 50s F when I started so I put my ski top on over the bike togs. Sweating by the time I got home. Did not die.

15.75 miles, 1:29:34