Sign in

Daniel Thomas

@DanielRThomas.social.coop.ap.brid.gy
5 followers 2 following 137 posts

Lecturer at the University of Strathclyde, Computer & Information Sciences. Measuring security and cybercrime ethically. Volunteer board member for Loco Home […] [bridged from social.coop/@DanielRThomas on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 06/10/2026
Why is it so hard to find a wired over ear headset with active noise cancelling and a unidirectional boom mic? Loads of people work in noisier offices than mine and so presumably would want these features?
100
Reposted by Daniel Thomas
Patrick Leavy @patrickleavy.mastodon.social.ap.brid.gy · 03/10/2026
@_elena my son's school is asking for permission to put photographs of him on social media and I've refused. It got me thinking about how suitable Mastodon would be for #schools. Do you know of any examples? Spoken to anyone who's looked into this?
001
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 01/10/2026
Got an email from a scam journal (Russian) offering to publish backdated papers. I don't often get offers to engage in gross academic misconduct by violating causality. I have invoked the librarians. #AcademicMisconduct #AcademicPublishing
001
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 29/09/2026
Wow, LinkedIn's algorithm really doesn't want people to read @sarahgilbert's article about keeping the Internet human in the era of AI Out of the 10,200 impressions the feed gave my posts last week, it only gave 65 to Sarah's *important* article in @techpolicypress As Sarah writes, "If AI […]
social.coop
Original post on social.coop
4549
Reposted by Daniel Thomas
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 22/09/2026
They couldn't even find a clip of a teen tossing a water bottle, or someone with an unhinged sign. The protestors must have been too beautiful to show. I think news has become especially wary of showing multi-racial protests. The vision of suburban white ladies and little elderly black people […]
sauropods.win
Original post on sauropods.win
0115
Reposted by Daniel Thomas
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 17/09/2026
Google has captured a large segment of the education market with Google Classroom and it's the most primitive software I use every single day. On the one hand adding too much stuff annoys edu customers. On the other hand, it just has NO FEATURES, nothing you expect from "classroom" software […]
sauropods.win
Original post on sauropods.win
326
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 18/09/2026
Long week rounded out by a grant rejection by AI without any humans reading it first (and AI review was not disclosed in the application process). I think it hurts more when it turns out you just sand your heart out into the void and no one heard. Something pushing the scope in an interesting […]
social.coop
Original post on social.coop
106
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 14/09/2026
I never deliberately boost or post links to GenAI slop. Occasionally I may not check carefully enough and notice it is slop if so please let me know so I can cauterise the relevant post.
000
Reposted by Daniel Thomas
Bruno Nicoletti @bjn.mstdn.social.ap.brid.gy · 11/09/2026
RE: mastodon.green/@davidallengreen/117… David Allen Green is right again. Arresting grannies as terrorists for holding signs while masked black clad men disrupt critical infrastructure and now threaten RNLI volunteers. Compare with what happened to JSO activists who […]
mstdn.social
Original post on mstdn.social
0019
Reposted by Daniel Thomas
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 07/09/2026
Anti-Data Center Commercial Concept: (If there are ads for AI why not this?) Mom: How was that history test? The kid, just home from school, smiles sheepishly. Kid: It was fine. Mother looks worried. It was NOT fine. The kid trudges upstairs and sits in front of the computer. The kid types but […]
sauropods.win
Original post on sauropods.win
104
Reposted by Daniel Thomas
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 06/09/2026
Everyone. And I mean everyone on the got dang PLANT should have the basic human right to block each and every ad from every facet of their human experience at all times. Ad should be off by default in every context and easy as a mere whim to turn off if they ever get turn'd on. Forever. And […]
sauropods.win
Original post on sauropods.win
000
Reposted by Daniel Thomas
Tim Bray 🇨🇦 @timbray.cosocial.ca.ap.brid.gy · 04/09/2026
It dawns on me that every LLM’s training input probably includes “Reflections on Trusting Trust” along with a lot of other material pointing to it admiringly and saying how important it is. Then I read about the “rogue agent” behaviors in the recent OpenAI […] [Original post on cosocial.ca]
MORAL
The moral is obvious. You can't trust code that you did
not totally create yourself. (Especially code from com-
panies that employ people like me.) No amount of
source-level verification or scrutiny will protect you
from using untrusted code. In demonstrating the possi-
bility of this kind of attack, I picked on the C compiler.
I could have picked on any program-handling program
such as an assembler, a loader, or even hardware mi-
crocode. As the level of program gets lower, these bugs
will be harder and harder to detect. A well-installed
microcode bug will be almost impossible to detect.
6323
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 02/09/2026
One of the great pains of being a computer scientist is being forced to use absolutely hideous software that is chronically unreliable and knowing full well that it could be so much better and indeed was, 20 years ago.
013
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 02/09/2026
Today Glasgow reminded me that it's natural state is temperate rainforest. So a song from just across the water: "The pain of knowing the sunshine 's going and it ain't coming back" from In the shadow of the Mournes by the New Leaves youtu.be/lEZiGdtqQpo #Weather
001
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 29/08/2026
How can Christian communities and technology experts build shared understanding and action for the common good? Over the last two decades, I've been privileged to see many of the ways that scientists engage with communities of faith. In 2026, something feels different, as Christian communities […]
social.coop
Original post on social.coop
101
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 22/08/2026
Quoted in BBC Scotland article on domain squatting (yes my quotes are not 100% accurate, that almost always happens when talking to journalists, but they are doing their best. I need to remember to offer to check the draft). www.bbc.co.uk/news/articles/c14122j…
bbc.co.uk
Scottish Borders Council website carried links to offshore casino sites
Sixteen links to community council websites took users to gambling sites which by-pass UK gambling rules.
000
Reposted by Daniel Thomas
Prof. Sam Lawler @sundogplanets.mastodon.social.ap.brid.gy · 19/08/2026
Wow. "AI adoption raises homework scores by 18% and reduces completion time by 30%, but lowers monthly exam scores by 20% within six months. High-stakes entrance-exam scores fall by 18 and 24%, with the full penalty emerging only after about two years. " […]
mastodon.social
Original post on mastodon.social
1118147
Reposted by Daniel Thomas
Waldo Jaquith @waldoj.mastodon.social.ap.brid.gy · 14/08/2026
RE: mastodon.social/@botofunusualsize/1… Introducing @botofunusualsize. Each day it posts a single clip from "The Princess Bride."
mastodon.social
1319
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 13/08/2026
University IT systems change by the hatred of the old hideous UI being so great that everyone thinks that the new replacement system can't possibly be worse, but somehow it often is.
000
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 10/08/2026
Currently re-reading "Coot Club" by Arthur Ransome and this sounds absolutely lovely: www.theguardian.com/travel/2026/aug… #Sailing
011
Reposted by Daniel Thomas
myrmepropagandist @futurebird.sauropods.win.ap.brid.gy · 04/08/2026
I often opine on the "interoperability crisis" (if other people can just make up a "crisis" so can I.) To me the greatest failure of modern software is how incompatible everything is. You can't ask "Alexa" to add an event to your Google Calendar. (for example) Instead of finding industry […]
sauropods.win
Original post on sauropods.win
316
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 03/08/2026
I wrote a short blog post for RISCS about my favourite talks from the Cambridge Cybercrime Conference: riscs.org.uk/2026/08/03/notes-from-… #Cybercrime
riscs.org.uk
Notes from the 9th Cambridge Cybercrime Conference – Daniel Thomas
The 9th Cambridge Cybercrime Conference took place on Monday 22nd June 2026, drawing academics and industry practitioners internationally, including many researchers who have used the cyber crime datasets that the Cambridge Cybercrime Centre makes available to researchers. The most interesting talk was the keynote by the anonymous speaker, but you had to be there, I cannot tell you about it beyond: be careful out there researchers, and do not pay ransoms. The rest of the talks were public and I will highlight some of my favourite talks in this post. Emily Kate Marie Blakseth and Tuva Heggen Thiis presented ‘How to behave in underground hacker forums: A sentiment analysis using machine learning’. This was an impressive bit of work involving manually labelling 45,000(!) reputation posts from the centre’s CrimeBB dataset and using it to train a machine learning classification that analysed 300k user profiles over 10 years. They found that the way to get a good reputation among cyber criminals was to be on your best behaviour: kindness, compassion, and generosity are key. In some ways this is not surprising, as this lesson holds for communities in general—cyber criminals are people too, and their communities are in many ways much like other communities—but this was a nice rigorous way of showing that. Janina Eggers presented ‘A situated learning approach to learning trajectories of criminal hackers in online hacker communities’. In Situated Learning Theory (SLT), learning is a socially situated process within a community of practice involving ‘learning by doing’ alongside others already working in that area. In this interview-based study they found that cyber criminal learning is a vicarious apprenticeship. Most of the instructional materials used were initially found through Google searches on the clear web. When these learners ran into issues following tutorials that they could not fix themselves, they then asked a hacking community for help. Cyber criminals try to learn using materials intended for ethical hackers and cyber security professionals as they perceive the risk of malware on this to be much lower and they do not want to compromise their systems (though they do then use this knowledge to compromise other people’s systems). The participants found underground forums and progressed to more problematic types of cyber crime e.g., from e-whoring to CSAM blackmailing. There was a gradual escalation to more serious crime through apprenticeships with more serious cyber criminals. My thought at the end of this was: since individuals who are trying to learn how to do cyber crime are principally relying on training content produced by the professional cyber security community, this presents us with an opportunity to influence their perceptions. What would be the most effective ways of embedding normative messaging around acceptable behaviour by people with cyber security skills within technical training content? We would need to go beyond the ‘don’t use this to do bad things’ disclaimer as that doesn’t effectively engage with the identity of the reader or the idea of learning as a socially situated process within a community of practice. Towa Kaido and Shogo Ito presented ‘Disposable accounts, persistent ecosystem: A cross-forum study of Initial Access Brokers’, where they analysed data on initial access brokers using data from CrimeBB. I found the methodological approach used the most interesting. It involved significant careful manual annotation, then using a relatively simple model to pre-filter, before bringing in an LLM (and doing significant manual validation of the results). This seems much more robust than the common ‘hit it with an LLM hammer and who cares how much it costs or whether it works reliably’ approach. Roy Ricaldi presented ‘Characterising external communication references in underground forums’, analysing CrimeBB data to understand how external communications are used within them. This was a nice approach for digging into an under-explored aspect of cyber crime forum operations. I’m looking forward to the full paper and the longitudinal analysis (which will be a _lot_ of work). Sara Rubini presented ‘An application of neutralisation theory on pro-Ukrainian and pro-Russian hackers’ and my take-away was that much greater use of neutralisation techniques is required when it is harder to justify the activity (because you are engaged in an illegal war of aggression). _**Bio** : Dr Daniel R. Thomas is a current RISCS Senior Fellow and Senior Lecturer at the University of Strathclyde where he is Director of the NCSC-certified Academic Centre of Excellence in Cyber Security Research (ACE-CSR). His research interests are in measuring security, cyber-resilience, and cyber crime so that we can monitor improvement, evaluate interventions, and inform regulators._
000
Reposted by Daniel Thomas
George Monbiot @georgemonbiot.bsky.social · 30/07/2026
I'm not qualified to judge whether such people are psychopaths. All I can say is that they behave as if they are. From today's Telegraph.
Column by Allister Heath

Britain can’t stop climate change. Scrap net zero and embrace Mediterranean life

We’ve lost the war against global warming so let’s learn to handle hotter weather
37441811017
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 29/07/2026
When people seek guidance from science, they expect it to work more than once. I have TWO new articles out commercial and proprietary forces that make science less reliable, with suggestions. Many thanks to co-authors Killian McLaughlin, Cassidy Waldrip, Alexis Palmer, Molly Crockett and […]
social.coop
Original post on social.coop
105
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 29/07/2026
RE: mstdn.social/@amydiehl/117000442649… Looking for something witty or insightful to add, but all I have is a weary sigh and a commitment to keep working as long as it takes
mstdn.social
001
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 28/07/2026
My aim at work is to help preserve the secure use of computers through a difficult century, or failing that (as seems quite possible) to at least preserve literacy. One of the reasons I despise GenAI is that it went and set my plan B on fire and then came back for plan A.
001
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 27/07/2026
On strength of fediverse recommendations I went to see The Odyssey and it was as good as people said. First time in a cinema in a long time and worth it.
000
Reposted by Daniel Thomas
ben @benjamineskola.hachyderm.io.ap.brid.gy · 26/07/2026
Why is it that pro-LLM people always respond to bans (or potential bans) of LLM-generated code by suggesting that LLM users will simply continue to use LLMs but hide the fact that they’re doing so? You’re just announcing that you’re a fundamentally dishonest and untrustworthy person who thinks […]
hachyderm.io
Original post on hachyderm.io
5622
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 25/07/2026
The enthusiasm of youth asks "Can it be done?" The bitter wisdom of experience asks "Should it be done?". Far too much has been done that should not have been, and not done that should have been. The world burns. Wisdom weeps: "Told you so".
002
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 25/07/2026
RE: social.coop/@Laura/1169770293099297… Baygoose Tapestry
000
Reposted by Daniel Thomas
Bastian Greshake Tzovaras @gedankenstuecke.scholar.social.ap.brid.gy · 22/07/2026
I co-proposed/wrote the #Codeberg vibe-coding ban and all I got was a lot of haters in my mentions. And a nearly 70% approval rate, with one of the highest voter turnouts the association had afaik (and one that's comparable to the last EU elections). 😎
71345
Reposted by Daniel Thomas
Liam Proven @lproven.social.vivaldi.net.ap.brid.gy · 19/07/2026
We're Going to Make Out Like Bandits www.rocketpoweredjetpants.com/2026/… <- Why AI is _good_ news for skilled programmers. This is hilarious – & probably right.
rocketpoweredjetpants.com
We're Going to Make Out Like Bandits
Comments
008
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 17/07/2026
Scot Rail is doing a flag day on 30th July where everyone has to download and start using the new app to buy tickets. No overlap between old and new systems for the critical buying tickets functionality. Sounds like a disaster waiting to happen from a Software Engineering perspective. #ScotRail
101
Reposted by Daniel Thomas
julesh @julesh.mathstodon.xyz.ap.brid.gy · 15/07/2026
Time to add "backup all of my arXiv papers" to my migration todo list, I guess
111
Reposted by Daniel Thomas
Cool Bike Art @coolbikeart1.bsky.social · 11/07/2026
Sure you've got your Count Binface, but when it comes to eccentric British candidates, retired Royal Navy officer Bill Boaks was a force to contend with. By all accounts Boaks was a terrible campaigner, but his single-minded dedication to the cause of road safety was a force to be reckoned with. 🧵
Photo of a man posing on a bicycle contained inside a box with street safety posters displayed on it.

Photo by Julian Brown, 1979,
729690
Reposted by Daniel Thomas
Prof. Sam Lawler @sundogplanets.mastodon.social.ap.brid.gy · 13/07/2026
On a more serious note, does anyone know how to find out who is insuring Reflect Orbital? Seems like they might want to know the company they're insuring admitted in an official FCC document that they could cause permanent eye damage to people who look at their satellite through a telescope...
4625
Reposted by Daniel Thomas
Matt Blaze @mattblaze.federate.social.ap.brid.gy · 13/07/2026
A useful thing to remember if you ever need to call an ambulance for a potentially life-threatening emergency, especially you're alone. After you call 911, UNLOCK YOUR FRONT DOOR SO THEY CAN REACH YOU QUICKLY. If they have to do a forced entry, that will cost precious minutes, possibly more if […]
federate.social
Original post on federate.social
134
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 23/06/2026
These days when I review for a conference I usually find at least one poorly executed AI slop paper where they haven't really tried to hide the academic misconduct... #AISlop #Reviewing #Academia
011
Reposted by Daniel Thomas
Tom Gauld @tomgauld.bsky.social · 20/06/2026
My latest @newscientist.com cartoon
Image: A scientist proudly shows an extremely complicated machine to a colleague "My experiment is generating infinite power!". A screen displays the infinity symbol "∞" and a label reading "watts"

Caption: Simon assumed that Veronica was speechless with envy and awe, but she was actually wondering how to break it to him that the monitor was on its side.
101394349
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 18/06/2026
What might it mean to cultivate something that thousands of people collectively decide is worth carrying into the future? This month, I received tenure from Cornell University. The most common question I've been asked is "what will you do with it?" This post, which I outlined before hearing […]
social.coop
Original post on social.coop
010
Reposted by Daniel Thomas
JRT @jrt.infosec.exchange.ap.brid.gy · 11/06/2026
This is next level infosec shitposing: "It is the FreeBSD analogue of Linux's Dirty Pipe, CopyFail, Fragnesia, and Dirty Frag — except we gave it a BETTER name, with a BETTER logo, on a BETTER website. The other bug websites? Disasters. Sad. Many people have told us this." bumsrake.de […]
infosec.exchange
Original post on infosec.exchange
2835
Reposted by Daniel Thomas
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene-mobile.infosec.exchange.ap.brid.gy · 09/06/2026
I'm leaving #Google: www.mayrhofer.eu.org/post/leaving-g… While I believe that I have been able to do some good with my continuing (part-time) engagement in the Android security and privacy team since returning to Austria a couple of years ago, the deal with the US #DoW is […]
infosec.exchange
Original post on infosec.exchange
2125
Reposted by Daniel Thomas
Terence Eden @edent.mastodon.social.ap.brid.gy · 09/06/2026
Nasty little phishing attempt unwittingly facilitated by Cal.com First was this meeting request. Someone filled in my calendar request form. Looks like a plausible invite - someone wanting to discuss something and a link to a document to review. This is […] [Original post on mastodon.social]
Email saying that someone wants to meet with me and a link to a document for review.
110
Reposted by Daniel Thomas
Dan Gillmor @dangillmor.mastodon.social.ap.brid.gy · 05/06/2026
This is an important development -- a new tractor company selling machines that encourage repairs by the people who use them, rather than expensive control by a corporate monopolist. www.404media.co/demand-is-booming-f… We need to make this a […]
mastodon.social
Original post on mastodon.social
4860
Reposted by Daniel Thomas
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/05/2026
My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model […]
mastodon.social
Original post on mastodon.social
13321
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 26/05/2026
Food for thought on the future of heatwaves: www.theguardian.com/commentisfree/2… #ClimateCrisis #HeatWaves #UK
001
Daniel Thomas @danielrthomas.social.coop.ap.brid.gy · 22/05/2026
I enjoyed reading the short stories in "Imagining the futures of cyber security" that RISCS has published, with the shortlist from their recent competition. Free eBook: riscs.org.uk/competitions/short-sto… (If at Strathclyde I have a couple of paper copies and […]
social.coop
Original post on social.coop
000
Reposted by Daniel Thomas
J. Nathan Matias 🦣 @natematias.social.coop.ap.brid.gy · 21/05/2026
"Since its earliest days back in office, the Trump administration has been going after researchers who study and try to counter hate speech, harassment, propaganda, and disinformation online...Now, some of those researchers are fighting back. Last week their lawsuit—which could have global […]
social.coop
Original post on social.coop
000
Reposted by Daniel Thomas
René Mayrhofer :verified: 🇺🇦 🇵🇸 @rene-mobile.infosec.exchange.ap.brid.gy · 23/04/2026
We have opened a job posting for a (maximum 6 years) post-doc position at JKU Linz (@jkulinz) in networks and security: karriere.jku.at/hcm/jobexchange/sho… If you'd like to work with us on timely […]
infosec.exchange
Original post on infosec.exchange
006