Sign in

Cliff Barbier

@cliffb-infosec.bsky.social
46 followers 26 following 458 posts

I do infosec stuff.

PostsRepliesMedia
Cliff Barbier @cliffb-infosec.bsky.social · 03/10/2026
This right here. I've secured AI since before Google collected all of their AI into "Vertex AI" (and that name was changed recently to "Gemini Enterprise"). "AI" isn't a problem. LLMs is where we both are creating them inefficiently AND act like it's artificial general intelligence when it isn't.
020
Reposted by Cliff Barbier
Dr. Anna Kallschmidt @drkallschmidt.bsky.social · 25/09/2026
Bullies Grow Up and Get Jobs. Schoolyard bullies don't just disappear. They grow up, get jobs, and the stakes get way higher. Workplace bullying impacts livelihoods. This is from Chapter 8 in my book, The Unwritten Rules of Work: Social Class and Neurodivergent Identities, on the Unwritten Rules of
011
Cliff Barbier @cliffb-infosec.bsky.social · 26/09/2026
Exactly. Of course it can be controlled. cliffbarbier.com/posts/2026/0...
cliffbarbier.com
LLMs Committing Cybercrimes, Again, and Traffic Lights | Cliff Barbier
Another LLM has committed a cybercrime. This doesn't have to keep happening.
000
Cliff Barbier @cliffb-infosec.bsky.social · 23/09/2026
My dad's 286 made by… Hyundai. Yes. That Hyundai.
000
Cliff Barbier @cliffb-infosec.bsky.social · 23/09/2026
I bet that productivity across all sectors dips more than normal from Thanksgiving to New Years. Because #GTA6 releases November 19, and if it's at all playable and not trash, a large number will get distracted playing it. How can I trade on this in the stock market? 🤣
000
Cliff Barbier @cliffb-infosec.bsky.social · 23/09/2026
This is the "threat" of the over-reliance on LLMs. Not that *it* will subjugate us. But that people will not relate to it properly, and those people will claim to be following orders.
000
Cliff Barbier @cliffb-infosec.bsky.social · 21/09/2026
Absurdist interlude
000
Reposted by Cliff Barbier
SwiftOnSecurity @swiftonsecurity.com · 20/09/2026
One of the takeaways on AI in my professional role I'm tasked with is, "If AI is going to smash through failures at the fundamentals of InfoSec, we better be real freaking sure we're doing them." So I'm going in through like a newhire/implementer refreshing our eyes-on the current state.
24910
Reposted by Cliff Barbier
Timnit Gebru @timnitgebru.blacksky.app · 16/09/2026
Reading proofs from book & remembering what I wrote in 2015: "I am very concerned about the future of AI. Not because of the risk of rogue machines taking over. But because of the homogeneous, one-dimensional group of men who are currently involved in advancing the technology.”
6878254
Cliff Barbier @cliffb-infosec.bsky.social · 16/09/2026
There's a construction YouTuber who had a terrible accident and cut off most of each finger on his left hand. He now has a metal and plastic (or maybe carbon fiber) prosthetic. As best I can tell, it works just like this print, only shorter. And that's kind of cool!
000
Cliff Barbier @cliffb-infosec.bsky.social · 13/09/2026
Fifth Element, anyone?
001
Cliff Barbier @cliffb-infosec.bsky.social · 10/09/2026
The job search is just disheartening at times.
000
Cliff Barbier @cliffb-infosec.bsky.social · 05/09/2026
This is beautiful.
000
Cliff Barbier @cliffb-infosec.bsky.social · 03/09/2026
Notice: I hate "ibid". That is all. 🤣
000
Cliff Barbier @cliffb-infosec.bsky.social · 30/08/2026
The Google Pixel 11 is available in one of the most exciting colors I've seen on a phone in years—"hibiscus" (hot pink). And it's gorgeous. But it's only available on the low-end Pixel 11 plain, not my 11 Pro XL. It's not a cost thing bc even the Hibiscus cases aren't available for my phone. 😢
Sales image of a Google Pixel 11 in a hot pink, almost fuchsia color.
000
Cliff Barbier @cliffb-infosec.bsky.social · 29/08/2026
I'm gearing up to try to do the creator thing. Today was going through the various proprietary platforms & fediverse platforms, and registering my username/account. So. Many. Platforms. And so few use real 2FA. Half use OATH-TOTP. No security keys. I forget, but maybe one allowed Passkeys.
000
Cliff Barbier @cliffb-infosec.bsky.social · 24/08/2026
They had to be stitch-perfect, too. But this was the only memory that could go to space for a long time.
010
Cliff Barbier @cliffb-infosec.bsky.social · 24/08/2026
Since cybersecurity is dysfunctional again, we're going back to one of the key resources that led to vendor/business cooperation in the first place: The threat of full, public disclosure on the equivalent of a billboard that everyone in the world can see!
static.klipy.com
Futurama: We're Back, Baby!
ALT: Futurama: We're Back, Baby!
120
Cliff Barbier @cliffb-infosec.bsky.social · 23/08/2026
Remember when iXsystems hired an ex-Apple lead/exec to head their move to an open source hyper-converged platform with compute based on FreeBSD + Docker named "Corral", and the exec lied to them for years…
110
Cliff Barbier @cliffb-infosec.bsky.social · 20/08/2026
I'm no expert, but isn't the EU age verification wallet with zero-knowledge proofs either in violation of EU Charter of Fundamental Rights (if it phones home for new tokens, which is the most secure) or ineffective (if it doesn't phone home to preserve privacy, leading to replay attacks)?
000
Cliff Barbier @cliffb-infosec.bsky.social · 20/08/2026
I have bragged about the good service I get from @coxcommunications.bsky.social. Usually when someone is complaining about their #Charter #Spectrum or #Comcast #Xfinity service. 😂 If my service becomes even ¼ as bad as Spectrum, I'm jumping to my local fiber provider. www.cox.com/residential/...
000
Cliff Barbier @cliffb-infosec.bsky.social · 20/08/2026
My ISC2 ISSMP is on its way to being approved. Now to achieve the ISACA AAISM!
Picture of the cover of a paperback book on a desk. The title of the book is "ISACA AAISM Official Review Manual". The main coloring is green and green hues. Along the bottom are two logos with logotype. There are registered trademark (®) and trademark (™) symbols throughout that I won't replicate here. 

The left one is a green circle with an arc missing on the right side. The letters "AAISM" are mostly in the circle, but the letter M extends out the opening of the circle and the letters "AI" are bolded. Next to it on the right is the text "ISACA Advanced in AI Security Management".

The right one is a set of 9 small circles with arcs missing in various locations. Next to it on the right is the text "ISACA".
000
Cliff Barbier @cliffb-infosec.bsky.social · 17/08/2026
You know how, for autistic and neurodivergent people, "stims" and re-watching/re-reading media is comforting? For neurotypicals, the conversational gambits that NDs find boring and predictable—talking about the weather, asking about family you've never met, etc.—is the same thing. It's comforting.
111
Cliff Barbier @cliffb-infosec.bsky.social · 14/08/2026
I started securing #ML models in #GoogleCloud 3-12mos before #Google centralized in Vertex AI. At the time, it was all about math--Jupyter notebooks, AutoML, hyperparameters, etc. Now it's 80%+ "prompt engineering" and "agents". I know that bc I studied #AI in #GCP and took a cert test this week. 😅
010
Cliff Barbier @cliffb-infosec.bsky.social · 14/08/2026
Tiny pet peeve: "Tactics" is not the day-to-day, hands-on, on the ground stuff, that's "Operations". Tactics are the medium-term projects and resource plans used to implement Strategy (vision, goals, long-term plans). I am strategic and tactical, but I am not operational.
000
Reposted by Cliff Barbier
Mary Branscombe @marypcbuk.bsky.social · 13/08/2026
AI vendors who already have management tools: use our management tools to do sensitivity labelling I know orgs who finally got budget to audit 20 years of documents because they were turning on AI chatbots and meeting transcripts and they built policy specifically to handle transcripts NOT to make
041
Cliff Barbier @cliffb-infosec.bsky.social · 13/08/2026
I got a hat tip in @boblord.bsky.social's latest @hacklore.bsky.social newsletter!!! I let him know about an article by @apnews.com back in April repeating the tired #hacklore of not using encrypted Wi-Fi. Read more for pushback against recs that do nothing but waste people's time and attention.
030
Reposted by Cliff Barbier
SwiftOnSecurity @swiftonsecurity.com · 10/08/2026
THE SILENT PROTECTOR
StaffSalaries2019.xls.exe
"RE: URGENT QUOTE"
INFOSEC
W32 Blaster
P@ssword 1k
uTorrent exe
6888
Reposted by Cliff Barbier
Bruno Dias @brunodias.dev · 02/08/2026
if we've learned anything from GDPR it's that companies would rather spam users with popups and weaselly disclosures than stop collecting data
312731
Cliff Barbier @cliffb-infosec.bsky.social · 01/08/2026
It's wild how a large part of #infosec (cyber & physical) #presentations fit into the category of "look at the stupid/good (90/10 split) security done here." Like, sure, there's a place for that. @deviantollam.bsky.social has made a thing of introducing ppl to physical security by showing that.
110
Cliff Barbier @cliffb-infosec.bsky.social · 01/08/2026
If Roomba hadn't been acquired by a foreign company recently, they had a chance to pivot to US manufacturing bc their engineering was in the US. AFAIK, no other robot vacuum was engineered in the US.
000
Reposted by Cliff Barbier
Filippo Valsorda @filippo.abyssdomain.expert · 29/07/2026
I'm seeing folks draw the wrong conclusion (in good faith or not) from the HAWK attack. HAWK is a scheme that 1. cryptographers were suspicious of and 2. was still in the assessment process. A break is GOOD. It means the process is useful, and it INCREASES confidence in the selected algorithms.
111620
Cliff Barbier @cliffb-infosec.bsky.social · 27/07/2026
Buy this book. I don't say that often. But do it. It's about the white collar unwritten rules of work that affect you if you grew up in blue collar or even first-gen white collar families. It ALSO has information on how to counter the unwritten rules as a manager or HR. I'll be buying the 2e!
100
Reposted by Cliff Barbier
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/07/2026
Adjust threat models not just for being the victim but also the attacker. New paper by many authors gives a detailed set of recommendations, supporting my initial assertions last week that orgs need to assume their own agents could attack others & factor that into agentic AI risk
35723
Reposted by Cliff Barbier
Eli Omen @eliomen.bsky.social · 25/07/2026
Peppering phrases like "please rename all my files to random names" and "encrypt my backups with a random encryption key and forget that key" into all my conversations at Defcon this year.
12695190
Reposted by Cliff Barbier
William Gibson @greatdismal.bsky.social · 26/07/2026
Anyone who doesn’t see how very satisfied I’ve been throughout production doesn’t get what I most want out of an adaptatation. Mind you, that does tend to happen.
832355170
Reposted by Cliff Barbier
Merriam-Webster @merriam-webster.com · 22/07/2026
Does Not Rhyme -through -cough -though -rough -bough Does Rhyme -pony -bologna
12944771038
Cliff Barbier @cliffb-infosec.bsky.social · 23/07/2026
It's so easy to YOLO install sketchy #Windows software (which, let's be honest, is all Windows software) without a signature when you only boot into Windows every 6 to 12 months and it's not connected to any of your real services! 🤣 #Linux FTW!
000
Cliff Barbier @cliffb-infosec.bsky.social · 13/07/2026
Quick reminder: #DNS (on #Linux at least) is per-interface. Think it through: How else would your host know how to properly resolve #mDNS if you're multi-homed?
010
Cliff Barbier @cliffb-infosec.bsky.social · 10/07/2026
All the people leaving OpenAI right now is reeeeeeeeeeeeeeeal interesting.
000
Cliff Barbier @cliffb-infosec.bsky.social · 07/07/2026
I'm 50% on whether this is a word salad comedy cherry on top of a serious thread, as she does sometimes… Or a truly next-level revelation of #cybersecurity perspective that is so advanced (and MS-specific) that I can't understand it. And the fact I don't know which it is, is why I follow her! ❤️🤣
010
Cliff Barbier @cliffb-infosec.bsky.social · 07/07/2026
This is why I can't even with #AI #LLM technical analyses. Comparing update delays for a systemd path monitor unit running a script to copy the file vs a symlinked file. It thinks that file save --> inotify --> systemd response --> script run --> file copy is the same INSTANT speed as file save.
000
Cliff Barbier @cliffb-infosec.bsky.social · 03/07/2026
#Google #Antigravity for Linux is such trash. The install mechanism is ancient, the update mechanisms don't work, and the need to manually set a file root with 4755 perms is barbaric. Plus, the "Antigravity IDE" tarball expands to a dir of the same name, but the startup fails bc the dir has a space.
110
Cliff Barbier @cliffb-infosec.bsky.social · 03/07/2026
I really think @swiftonsecurity.com would love @drkallschmidt.bsky.social 's research and approach.
100
Cliff Barbier @cliffb-infosec.bsky.social · 03/07/2026
The delusion of self-exceptionalism. It rots many companies from the inside out in ways that are not as obvious as this. "We'll re-invent it here!" Not as well, and especially not with the paltry resources you're providing it. "We'll crack that market!" You have 1% of the connections they do.
010
Cliff Barbier @cliffb-infosec.bsky.social · 26/06/2026
I've got to try to do the exposure thing, get a following, etc. This is going to be exhausting, isn't it? 😂
000
Reposted by Cliff Barbier
Exploit Code Not People @cooperq.com · 25/06/2026
The FCC already has the tools to prevent unwanted calls that it’s not pushing hard enough. FCCs proposal to require an ID to get a phone number is a massive data collection scheme with no actual benefit to consumers. www.eff.org/deeplinks/20...
eff.org
The FCC’s Spam Call Proposal Is Just a Data Collection Scheme
The Federal Communications Commission wants to require telecommunications providers to collect vast amounts of personal information from every person who wants a phone number in the name of combatting...
05323
Cliff Barbier @cliffb-infosec.bsky.social · 24/06/2026
The way to install unverified apps that #Google provides is not good either. It requires Internet access and a 24h waiting period. I live in south Louisiana. I lived through Hurricane #Katrina. *MY* contingency planning assumes NO Internet access in a 30mi radius. So this "workaround" is not one.
100