Sign in

Dan Goodin

@dangoodin.bsky.social
10K followers 819 following 125 posts

Cybersecurity Reporter, Ars Technica: arstechnica.com/author/dan-goodin Hungry for tips. Text me on Signal: DanArs.82. "The world isn’t run by weapons anymore, or energy, or money. It’s run by little 1s and 0s, little bits of data."

PostsRepliesMedia
Reposted by Dan Goodin
bjkeefe @bjkeefe.bsky.social · 24/09/2026
This, from @dangoodin.bsky.social, is not something to be scared about, at least not yet. But it does seem like a significant step. It is, in any case, interesting just for the theoretical aspects.
121
Reposted by Dan Goodin
Ars Technica @arstechnica.com · 21/09/2026
arstechnica.com
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
A simple ClickFix attack is only one way to completely hijack the new agent.
45918
Dan Goodin @dangoodin.bsky.social · 30/07/2026
A quantum-resistant cryptography algorithm that was under consideration to become an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken. arstechnica.com/security/202...
arstechnica.com
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
0235
Dan Goodin @dangoodin.bsky.social · 05/06/2026
You too can turn a Bluetooth device into a PC-pwning proxy arstechnica.com/security/202...
arstechnica.com
How a USB-connected speaker can infect a PC without ever being touched
Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability.
0225
Dan Goodin @dangoodin.bsky.social · 04/06/2026
If it wasn't already, 2FA spraying is now a thing, as Dashlane users now know. arstechnica.com/security/202...
arstechnica.com
Dashlane explains how attackers managed to download encrypted password vaults
By targeting large numbers of users, attackers increased their chances of success.
1101
Reposted by Dan Goodin
Jake Williams @malwarejake.bsky.social · 04/06/2026
Incident responder who gets to see behind the scenes on a lot of these: In 2026, if the company is being this obtuse it's either REALLY BAD(tm) or they have horrible incident response preparedness. Neither one is good for their customers.
1203
Dan Goodin @dangoodin.bsky.social · 04/06/2026
Can’t make sense of Dashlane’s vault theft notification? You’re not alone. arstechnica.com/security/202...
arstechnica.com
Can't make sense of Dashlane's vault theft notification? You're not alone.
Security advisory leaves out key details. Dashlane maintains complete silence.
040
Dan Goodin @dangoodin.bsky.social · 11/05/2026
Anybody know of any Linux distributions that have released fixes for Dirty Frag?
173
Dan Goodin @dangoodin.bsky.social · 21/04/2026
I just donated to SPLC because the work it does makes the world a safer and more just place. Please do the same if able.
0113
Dan Goodin @dangoodin.bsky.social · 21/04/2026
With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo.abyssdomain.expert wants to make one thing clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world arstechnica.com/security/202...
arstechnica.com
Contrary to popular superstition, AES 128 is just fine in a post-quantum world
A stubborn misconception is hampering the already hard work of quantum readiness.
0336
Dan Goodin @dangoodin.bsky.social · 17/04/2026
“Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.” arstechnica.com/security/202...
arstechnica.com
Recent advances push Big Tech closer to the Q-Day danger zone
Here's which players are winning the race to transition to post-quantum crypto.
071
Dan Goodin @dangoodin.bsky.social · 03/04/2026
Now, there's a 3rd Rowhammer attack on Nvidia GPUs that gains CPU root even when IOMMU is enabled. My story has been updated throughout. arstechnica.com/security/202...
arstechnica.com
New Rowhammer attacks give complete control of machines running Nvidia GPUs
Both GDDRHammer and GeForge hammer GPU memory in ways that compromise the CPU.
141
Dan Goodin @dangoodin.bsky.social · 02/04/2026
The cost and shortage of GPUs means they're frequently shared among dozens of users in cloud environments. 2 new Rowhammer attacks demonstrate how a malicious user can gain full root control of the host machine running high-performance Nvidia GPU cards. arstechnica.com/security/202...
arstechnica.com
New Rowhammer attacks give complete control of machines running Nvidia GPUs
Both GDDRHammer and GeForge hammer GPU memory in ways that compromise the CPU.
1218
Dan Goodin @dangoodin.bsky.social · 31/03/2026
Building a utility-scale quantum computer that can crack one of the most vital cryptosystems—elliptic curves—doesn’t require nearly the resources anticipated just a year or two ago, two independently written whitepapers have concluded. arstechnica.com/security/202...
arstechnica.com
Quantum computers need vastly fewer resources than thought to break vital encryption
No, the sky isn't falling, but Q Day is coming, and it won't be as expensive as thought.
072
Reposted by Dan Goodin
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 26/03/2026
Kaspersky has linked Coruna with Operation Triangulation. This somes a few weeks after we reported that L3Harris Trenchant was the company behind some components of Coruna. And we also reported that it was possible Coruna was used in Operation Triangulation. securelist.com/coruna-frame...
172
Dan Goodin @dangoodin.bsky.social · 25/03/2026
Google is dramatically shortening its readiness deadline for the arrival of Q Day, the point at which existing quantum computers can break public-key algorithms that secure decades’ worth of secrets belonging to militaries, banks, and nearly every individual on earth arstechnica.com/security/202...
arstechnica.com
Google bumps up Q Day deadline to 2029, far sooner than previously thought
Company warns entire industry to move off RSA and EC more quickly.
21713
Dan Goodin @dangoodin.bsky.social · 24/03/2026
I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.
Scanned newspaper article from 1997. Headline: :Breaking the code breakers." subhed: "Cindy Cohn is fighting the feds on export control and winning." Byline: "Dan Goodin."
091
Dan Goodin @dangoodin.bsky.social · 03/03/2026
Burner accounts on social media sites can increasingly be analyzed to identify the pseudonymous users who post to them using AI in research that has far-reaching consequences for privacy on the Internet, researchers said. arstechnica.com/security/202...
arstechnica.com
LLMs can unmask pseudonymous users at scale with surprising accuracy
Pseudonymity has never been perfect for preserving privacy. Soon it may be pointless.
173
Reposted by Dan Goodin
Mathy Vanhoef @vanhoefm.bsky.social · 26/02/2026
Excellent article on the work by @dangoodin.bsky.social: arstechnica.com/security/202... I'd say we bypass Wi-Fi encryption, in the sense that we can bypass client isolation. We don't break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;)
arstechnica.com
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises
That guest network you set up for your neighbors may not be as secure as you think.
276
Dan Goodin @dangoodin.bsky.social · 26/02/2026
That guest SSID you set up for your neighbors may not be as secure as you think arstechnica.com/security/202...
arstechnica.com
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises
That guest network you set up for your neighbors may not be as secure as you think.
185
Reposted by Dan Goodin
WeRateDogs @weratedogs.com · 18/02/2026
This local Wolfdog joined an Olympic ski event and triggered the finish-line camera. This is Nazgul. He snuck into a cross-country skiing sprint this morning and raced the homestretch with some competitors before being escorted home. 14/10 someone get him a medal
476235925017
Reposted by Dan Goodin
Kim Zetter @kimzetter.bsky.social · 18/02/2026
The makers of password managers like Bitwarden, 1Password, Dashlane and LastPass promise they can't see your password vault. But that's not always true. A server compromise can mean game over for you, say researchers who examined some of the top password managers on the market
arstechnica.com
Password managers' promise that they can't see your vaults isn't always true
Contrary to what password managers say, a server compromise can mean game over.
21912
Reposted by Dan Goodin
Dan Goodin @dangoodin.bsky.social · 17/02/2026
Contrary to what password managers say, a server compromise can mean game over. arstechnica.com/security/202...
arstechnica.com
Password managers' promise that they can't see your vaults isn't always true
Contrary to what password managers say, a server compromise can mean game over.
0128
Dan Goodin @dangoodin.bsky.social · 17/02/2026
Contrary to what password managers say, a server compromise can mean game over. arstechnica.com/security/202...
arstechnica.com
Password managers' promise that they can't see your vaults isn't always true
Contrary to what password managers say, a server compromise can mean game over.
0128
Reposted by Dan Goodin
Raphael Satter @raphae.li · 12/02/2026
Scoop: A report published last week outlined what Palo Alto researchers believed was a China-linked hacking campaign. But after an intervention from execs, the report's language was changed to refer more vaguely to "a state-aligned group that operates out of Asia." www.reuters.com/world/china/...
reuters.com
Exclusive: Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say
Palo Alto Networks opted not to tie China to a global cyberespionage campaign the firm exposed last week over concerns that the cybersecurity company or its clients could face retaliation from Beijing...
44027
Reposted by Dan Goodin
Dhruv Mehrotra @dmehro.bsky.social · 09/02/2026
I filed this FOIA after publishing this investigation into ICE agents abusing law-enforcement databases. www.wired.com/story/ice-ag.... Those records are here: airtable.com/appxK2tDF0YA...
wired.com
ICE Records Reveal How Agents Abuse Access to Secret Data
Documents obtained by WIRED detail hundreds of investigations by the US agency into alleged database misuse that includes harassment, stalking, and more.
12214
Dan Goodin @dangoodin.bsky.social · 09/02/2026
If throngs of people handed over their IDs in exchange for a vanity blue check from a pro-authoritarian site, what reason is there to think Discord users won't do the same?
0130
Dan Goodin @dangoodin.bsky.social · 29/01/2026
Two security professionals who were arrested in 2019 after performing an authorized security assessment of a county courthouse in Iowa will receive $600,000 to settle a lawsuit they brought alleging wrongful arrest and defamation. arstechnica.com/security/202...
arstechnica.com
County pays $600,000 to pentesters it arrested for assessing courthouse security
Settlement comes more than 6 years after Gary DeMercurio and Justin Wynn's ordeal began.
1144
Reposted by Dan Goodin
Ed Bott @edbott.com · 28/01/2026
Trump’s federal thugs beat up on His face and his chest Then we heard the gunshots And Alex Pretti lay in the snow, dead Their claim was self defense, sir Just don’t believe your eyes It’s our blood and bones And these whistles and phones Against Miller and Noem’s dirty lies (Full lyrics @ YT page)
0114
Reposted by Dan Goodin
Val @vallha11a.neocities.org · 19/01/2026
Thanks to @dangoodin.bsky.social for writing one of the few articles that actually questioned the @nytimes.com report.
011
Reposted by Dan Goodin
The Onion @theonion.com · 15/01/2026
Conservatives Say Renée Good Was Brainwashed By Bible Into Loving Thy Neighbor theonion.com/conservatives-say-rene…
Conservatives Say Renée Good Was Brainwashed By Bible Into Loving Thy Neighbor
424677961
Reposted by Dan Goodin
Zack Whittaker @zackwhittaker.com · 14/01/2026
New, by me: Security researcher Eaton Zveare spent weeks trying to alert a little-known but critical U.S. cargo tech giant that their shipping systems and customers' data were exposed to the web. After weeks of trying, Zveare asked TechCrunch for help. We heard back! ...from the company's law firm.
techcrunch.com
Exclusive: US cargo tech company publicly exposed its shipping systems and customer data to the web
Shipping tech company Bluspark left internal plaintext passwords, including those of executives, exposed to the internet, at a time when hacks in the shipping industry are on the rise.
15625
Reposted by Dan Goodin
Seanie Byrne 🦡 @seaniebyrne.bsky.social · 13/01/2026
The novel use of PassKeys to store the private key material is 👨🏻‍🍳💋 by @dangoodin.bsky.social arstechnica.com/security/202...
arstechnica.com
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging
Introducing Confer, an end-to-end AI assistant that just works.
051
Dan Goodin @dangoodin.bsky.social · 13/01/2026
Moxie Marlinspike—the engineer who set a new standard for private messaging with the creation of the Signal Messenger—is now aiming to revolutionize AI chatbots in a similar way. arstechnica.com/security/202...
arstechnica.com
Signal creator Moxie Marlinspike wants to do for AI what he did for messaging
Introducing Confer, an end-to-end AI assistant that just works.
22012
Dan Goodin @dangoodin.bsky.social · 12/11/2025
In 15 minutes, NY AG Letitia James will participate in the Conde Nast union rally supporting the immediate reinstatement of 4 of our colleagues who were illegally fired in a union-busting move. If you're near WTC in Manhattan, please come and show your support.
"Flyer: Conde Nast union: Defend our rights Wednesday, Nov 12 6 PM Reinstate the Fired four." Four images of red fists raised in the air.
0122
Dan Goodin @dangoodin.bsky.social · 12/11/2025
Dear @undetectableai.bsky.social: The comments attributed to your CEO, Christian Perry, in the WGCU post borders on quackery. There is 0 evidence AI is doing the things you say it is. Please stop spreading misinformation. Oddly, WGCU in Fort Meyers, Florida, has no removed the story. I wonder why
Headline and byline:

Detection expert says hackers likely used AI to penetrate airport system

WGCU | By Undetectable.ai/Special to WGCU
Published September 23, 2025 at 9:23 AM EDT
1122
Dan Goodin @dangoodin.bsky.social · 12/11/2025
ICYMI: 4 Conde Nast employees were illegally fired for exercising permitted speech in our workplace. Tonight, NY AG Letitia James will call out this union-busting move by our management. Please attend. Pls also sign our petition to reinstate our fired colleagues. actionnetwork.org/petitions/te...
actionnetwork.org
Tell Condé bosses to reinstate the Fired Four, reverse the suspensions and end the union-busting
On Nov. 5, 2025 in an egregious attempt at union-busting, Condé Nast management illegally terminated four union members – Alma Avalle, Jake Lahut, Jasper Lo and Ben Dewey – for participating in federa...
1196
Reposted by Dan Goodin
Sam.END.ICE.Machkovech @samred.com · 06/11/2025
Hi hi! I'm happy and proud to announce that I've spent the last few weeks preparing the relaunch of @digitalfoundry.bsky.social as its Launch Site Editor! A dream role in many ways. I'll be translating the DF team's videos in the site's early months while building exclusive content. Check it out:
digitalfoundry.net
Digital Foundry
Digital Foundry was founded in 2004 and specialises in technical analysis of video games and hardware, using our own bespoke tools for frame-rate analysis – covering everything from console, PC and be...
138613
Reposted by Dan Goodin
The New York Times @nytimes.com · 17/10/2025
The administration at Indiana University Bloomington fired the adviser to the student newspaper and barred the publication from putting out a print edition. The dispute has left student journalists and press advocates accusing the university of censorship.
nyti.ms
Indiana University Fires Adviser to Student Newspaper and Bars Print Publication
The administration at Indiana University Bloomington fired the adviser to the paper and barred the publication from putting out a print edition.
97026
Reposted by Dan Goodin
Senator Ron Wyden @wyden.senate.gov · 17/10/2025
For over 3 years my investigation has exposed how major banks enabled Epstein’s sex trafficking operation. I’m glad that his victims are able to use those findings to hold big banks accountable. I fully intend to keep following the money on Epstein. Stay tuned.
nydailynews.com
Epstein victims sue Bank of America, Bank of NY Mellon, for allegedly funding sex trafficking
Women abused by Jeffrey Epstein sued Bank of America and Bank of New York Mellon in Manhattan on Wednesday, alleging their executives violated banking laws and ignored red flags out of “absolute lo…
641737682
Dan Goodin @dangoodin.bsky.social · 13/10/2025
The problem solving required for making Signal quantum safe is as daunting as any in engineering. In less adept hands, mucking about with an instrument this complex could have led to unintended consequences. Yet this upgrade is nothing short of a triumph! arstechnica.com/security/202...
arstechnica.com
Why Signal’s post-quantum makeover is an amazing engineering achievement
New design sets a high standard for post-quantum readiness.
0306
Dan Goodin @dangoodin.bsky.social · 19/09/2025
How long until the FBI opens an investigation into this judge?
050
Reposted by Dan Goodin
Eric Goldman @ericgoldman.bsky.social · 19/09/2025
Judge Merryday has no fucks left to give for Trump's defamation complaint against the NYT: "As every lawyer knows (or is presumed to know), a complaint isn't a public forum for vituperation & invective—not a protected platform to rage against an adversary" storage.courtlistener.com/recap/gov.us...
storage.courtlistener.com
2125
Reposted by Dan Goodin
Mike Masnick @masnick.com · 19/09/2025
Wow. Florida judge makes quick work of the Trump lawsuit against the NYTimes and Penguin Random House. The lawsuit was silly and Judge Merryday does not hide how he feels about it! Trump can amend though. storage.courtlistener.com/recap/gov.us...
Even under the most generous and lenient application of Rule 8, the complaint is decidedly improper and impermissible. The pleader initially alleges an electoral victory by President Trump “in historic fashion” — by “trouncing” the opponent — and alludes to “persistent election interference from the legacy media, led
most notoriously by the New York Times.” The pleader alludes to “the halcyon
days” of the newspaper but complains that the newspaper has become a “fullthroated mouthpiece of the Democrat party,” which allegedly resulted in the “deranged endorsement” of President Trump’s principal opponent in the most recent
presidential election. The reader of the complaint must labor through allegations,
such as “a new journalistic low for the hopelessly compromised and tarnished ‘Gray
Lady.’” The reader must endure an allegation of “the desperate need to defame with
a partisan spear rather than report with an authentic looking glass” and an allegation
that “the false narrative about ‘The Apprentice’ was just the tip of Defendants’ melting iceberg of falsehoods.” Similarly, in one of many, often repetitive, and laudatory
(toward President Trump) but superfluous allegations, the pleader states, “‘TheApprentice’ represented the cultural magnitude of President Trump’s singular brilliance, which captured the [Z]eitgeist of our time.”
The complaint continues with allegations in defense of President Trump’s father and the acquisition of the Trumps’ wealth; with a protracted list of the many
properties owned, developed, or managed by The Trump Organization and a list of
President Trump’s many books; with a long account of the history of “The Apprentice”; with an extensive list of President Trump’s “media appearances”; with a detailed account of other legal actions both by and against President Trump, including
an account of the “Russia Collusion Hoax” and incidents of alleged “lawfare”
against President Trump; and with much more, persistently alleged in abundant,
florid, and enervating detail.
Even assuming that each allegation in the complaint is true (of course, that is
for a jury to decide and is not pertinent here; this order suggests nothing about the
truth of the allegations or the validity of the claims but addresses only the manner of
the presentation of the allegations in the complaint); even assuming that at trial the
plaintiff offers evidence supporting every allegation in the complaint and that the evidence is accepted by the jury as fact; and even assuming that after finally “melting”
the defendants’ alleged “iceberg of falsehoods” the plaintiff prevails for each reason
alleged in the complaint — even assuming all of that — a complaint remains an improper and impermissible place for the tedious and burdensome aggregation of prospective evidence, for the rehearsal of tendentious arguments, or for the protracted
recitation and explanation of legal authority putatively supporting the pleader’s claimfor relief. As every lawyer knows (or is presumed to know), a complaint is not a public forum for vituperation and invective — not a protected platform to rage against an
adversary. A complaint is not a megaphone for public relations or a podium for a
passionate oration at a political rally or the functional equivalent of the Hyde Park
Speakers’ Corner.
A complaint is a mechanism to fairly, precisely, directly, soberly, and economically inform the defendants — in a professionally constrained manner consistent
with the dignity of the adversarial process in an Article III court of the United States
— of the nature and content of the claims. A complaint is a short, plain, direct statement of allegations of fact sufficient to create a facially plausible claim for relief and
sufficient to permit the formulation of an informed response. Although lawyers receive a modicum of expressive latitude in pleading the claim of a client, the complaint in this action extends far beyond the outer bound of that latitude.
This complaint stands unmistakably and inexcusably athwart the requirements
of Rule 8. This action will begin, will continue, and will end in accord with the rules
of procedure and in a professional and dignified manner. The complaint is STRUCK
with leave to amend within twenty-eight days. The amended complaint must not exceed forty pages, excluding only the caption, the signature, and any attachment.
ORDERED in Tampa, Florida, on September 19, 2025.
617432
Dan Goodin @dangoodin.bsky.social · 18/09/2025
So long, #disneyplus. I stand for @jimmykimmel.com and for media independence. Also, nothing Jimmy said about the MAGA people politicizing and weaponizing Kirk's assassination was untrue. cc: @jimmykimmellive.bsky.social
Ok, your subscription has been cancelled
We’ve sent a confirmation to your email on file. You may continue to watch Disney+ until October 5, 2025.
0253
Reposted by Dan Goodin
Ars Technica @arstechnica.com · 18/09/2025
arstechnica.com
New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
Unlike most prompt injections, ShadowLeak executes on OpenAI’s cloud-based infrastructure.
03810
Reposted by Dan Goodin
Noah Shachtman @noahshachtman.bsky.social · 18/09/2025
@lurabardley.bsky.social sees this for what it is www.vanityfair.com/hollywood/st...
vanityfair.com
Late-Night TV Isn’t Dying—It’s Being Murdered
And we’re not just talking about Jimmy Kimmel. In part one of a two-part series, nearly a dozen insiders explain how one of comedy’s oldest genres is being strangled—starting with the chilling effect ...
18634163
Reposted by Dan Goodin
Matthew Green @matthewdgreen.bsky.social · 18/09/2025
Nice article by @dangoodin.bsky.social on the Ascension hack and bad Kerberos: arstechnica.com/security/202...
arstechnica.com
How weak passwords and other failings led to catastrophic breach of Ascension
A deep-dive into Active Directory and how “Kerberoasting” breaks it wide open.
1163
Dan Goodin @dangoodin.bsky.social · 05/09/2025
Wednesday’s discovery of 3 unauthorized TLS certificates for Cloudflare’s 1.1.1.1 generated intense interest and concern. Since then, new information has become available, including the issuance of 9 more certificates. This FAQ answers questions and gives the latest: arstechnica.com/information-...
arstechnica.com
The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest.
Everything to know about the mishap that threatened to expose millions of users’ queries.
180