Sign in

Jeroen van der Ham

@jvdham.nl
188 followers 75 following 53 posts

Associate Professor at UTwente on vulnerability management 1sand0s@infosec.exchange and @1sand0s

PostsRepliesMedia
Reposted by Jeroen van der Ham
FIRST.org @first.org · 14/09/2026
Charles-Louis Machuron, Silicon Luxembourg, recently interviewed @jvdham.nl, @first.org liaison member and associate professor at the University of Twente, on VulnOptiCON 2026. Read more: go.first.org/JxwxD #cybersecurity #infosec #VulnerabilityManagement
siliconluxembourg.lu
Luxembourg Set To Host Cyber Event VulnOptiCON 2026 - Silicon Luxembourg
FIRST rebrands Vuln4Cast as VulnOptiCON 2026, a three-day Luxembourg conference on AI, vulnerability forecasting and cybersecurity risk, Sept 23-25.
011
Reposted by Jeroen van der Ham
Koen van Hove @koenvh.nl · 12/05/2026
The paper I wrote together with @jvdham.nl and Roland van Rijswijk-Deij titled "Domijn: The Security of Domain Registrars and the Risk of a Domain Name Takeover" for the Workshop on the Economics of Information Security (WEIS) 2026 is now available! weis2026.econinfosec.org/wp-content/u...
weis2026.econinfosec.org
011
Jeroen van der Ham @jvdham.nl · 22/04/2026
Of course everybody has hot takes on the recent hoopla around #ProjectGlasswing and #Mythos. This is not the end of the story. The AI landscape is vast and evolving and our challenge to you is to tell or show us something about #AI and #securityvulnerabilities that we haven’t already seen or heard…
000
Jeroen van der Ham @jvdham.nl · 22/04/2026
Do you like knowing stuff or maybe learning stuff? Stuff about security vulnerabilities? Maybe even data stuff (or things) about security vulnerabilities. Then heyyyy, do we have the workshop for you! CFP ends May 17! www.vulnopticon.org
vulnopticon.org
VulnOptiCON FIRST 2026
100
Jeroen van der Ham @jvdham.nl · 03/12/2025
I am continuously impressed by Export Control lists. Apparently now we can't have free lunch in space with our computers. knowledge4policy.ec.europa.eu/sites/defaul...
000
Jeroen van der Ham @jvdham.nl · 05/11/2025
Het blijft fascinerend hoezeer de kiezers loyaal zijn ondanks de puinhoop die de partij gecreëerd heeft.
010
Jeroen van der Ham @jvdham.nl · 05/11/2025
Regarding the ffmpeg drama, as discussed by @patrick.risky.biz on risky.biz: we should also consider that ffmpeg is/has been used by Google in Chrome and Youtube. Even if it's not directly, so many video makers are using that library, that Google really should bear some cost of development there.
risky.biz
Risky Business Media
News and commentary for cybersecurity and intelligence professionals
000
Jeroen van der Ham @jvdham.nl · 13/05/2025
Een artikel is sowieso beschermd als intellectueel eigendom. Daarnaast heb je als reviewer afspraken met de conferentie/journal over geheimhouding. Dus misschien niet strafbaar maar wel problematisch.
010
Jeroen van der Ham @jvdham.nl · 13/05/2025
Je mag ook niet het hele artikel als zoekopdracht gebruiken. Kernwoorden voor jezelf om dingen te begrijpen, ja. Een of twee letterlijke zinnen om plagiaat te checken, ja. Maar een heel artikel in Google gooien is niet okay. Want je geeft het daarmee weg.
110
Jeroen van der Ham @jvdham.nl · 13/03/2025
When the Dutch have to take a detour on their bike, their world turns upside down.
Bike detour sign pointing left used for pointing right
010
Jeroen van der Ham @jvdham.nl · 28/01/2025
Als de tweede kamer politie inzet zo belangrijk vindt, zullen we dan voetbalwedstrijden ook maar verbieden? #xr #anbi
000
Jeroen van der Ham @jvdham.nl · 15/01/2025
That is a really long winded video, that mentions the same settings I already have turned off. With the exception of reminders for starting a workout. But I don’t want to turn those off, just the audio notification part. But voice feedback is already off.
100
Jeroen van der Ham @jvdham.nl · 15/01/2025
Even Siri settings has something with notifications and that is also turned off.
Siri settings for announcements
000
Jeroen van der Ham @jvdham.nl · 15/01/2025
Notifications setting on Apple Watch has no separate toggle for Workout.
Notification settings for watch
100
Jeroen van der Ham @jvdham.nl · 15/01/2025
Watch settings showing workout voice feedback is off
000
Jeroen van der Ham @jvdham.nl · 15/01/2025
How do I disable announced notifications from workout on my watch? These notifications are interrupting music or podcasts when I’m cycling and I don’t want them.
300
Jeroen van der Ham @jvdham.nl · 12/01/2025
Since iOS 18.2 i have problems with Mail. It’s hardly downloading new mail from my imap server. Anybody else having this too? Anything I can do about it to fix? Nothing changed on my server end (Dovecot). I’ve even tried to disable IMAP IDLE, but that also does not help.
000
Jeroen van der Ham @jvdham.nl · 28/11/2024
A dataset with exact locations of taxis that was not anonymised correctly, and led to the discovery of where famous people lived and how often they went to the gym.
010
Jeroen van der Ham @jvdham.nl · 28/11/2024
In many of my ethics lectures I use the example of the New York taxi dataset. Imagine my surprise that the Dutch government now wants to introduce such a system. autoriteitpersoonsgegevens.nl/actueel/ap-c...
autoriteitpersoonsgegevens.nl
AP: centrale database taxi’s te groot privacyrisico
Het kabinet wil een centrale database taxi's. De privacy van passagiers moet beter beschermd worden, zegt de AP.
113
Jeroen van der Ham @jvdham.nl · 25/11/2024
The protest is really massive and keeps growing
Picture of mass of people protesting against Dutch planned budget cuts in education
000
Jeroen van der Ham @jvdham.nl · 25/11/2024
Great numbers showing up for the higher education protest
110
Jeroen van der Ham @jvdham.nl · 21/11/2024
Hakuna Mafuckit indeed.
Framed picture with cacti background saying Hakuna Mafuckit
021
Jeroen van der Ham @jvdham.nl · 20/11/2024
The security implications of storing passwords insecurely are just mind-boggling. Just look at how many leaked passwords we have already. And that’s with very actionable advice on how to do password hashing for years.
520
Jeroen van der Ham @jvdham.nl · 20/11/2024
There have been many studies on password behavior and even on leaked passwords to see how real life passwords were not getting any better. The “we need more data” argument is a well trodden path for scientists, but in this case, just don’t.
110
Jeroen van der Ham @jvdham.nl · 20/11/2024
Password policies are evil and should be burned to the ground. The piece that Stuart Schechter wrote on their history however, is so incredibly misguided. It is bonkers to think that we would have had a more secure world without password hashing.
stuartschechter.org
How some of the world's most brilliant computer scientists got password policies so wrong
The US government’s latest recommendations acknowledge that password composition and reset rules are not just annoying, but counterproductive. The story of why password rules were recommended and enfo...
262
Jeroen van der Ham @jvdham.nl · 24/10/2023
Anyone interested in researching multi-level marketing schemes/scams #mls
I got a message from someone claiming to offer work for #gamechangersf sending me an invite for gamechangersfpos[.]com
000
Jeroen van der Ham @jvdham.nl · 23/09/2023
Waarom wordt gecondenseerde melk verkocht in blikjes van 397g? #dtv
000
Jeroen van der Ham @jvdham.nl · 13/09/2023
The way we do #science 🧪currently could do with some shakeups. This blog post by experimental history builds on some earlier posts, and lays bare the pain points of the current scientific climate. But it also presents a way to get out of that! Let’s build more #ScienceHouses !
experimental-history.com
Let’s build a fleet and change the world
Abandon Big Ship, get on a Little Ship
020
Jeroen van der Ham @jvdham.nl · 06/09/2023
It's a fascinating story, where the owner has come under the influence of a cyber charlatan/Mata Hari like figure.
000
Jeroen van der Ham @jvdham.nl · 06/09/2023
Heh, we've just had an example in The Netherlands where an owner of a very large IT company was pushed by his board. They used a special legal procedure to show that he was incompetent. All of his shares in the company are now outside of his control.
110
Jeroen van der Ham @jvdham.nl · 06/09/2023
It's fascinating to see that AtlanticCouncil uses archive.ph in their latest "Sleight of Hand" report: www.atlanticcouncil.org/in-depth-res...
atlanticcouncil.org
Sleight of hand: How China weaponizes software vulnerabilities
China's new vulnerability management system mandates reporting to MIIT within 48 hours, restricting pre-patch publication and POC code. This centralized approach contrasts with the US voluntary system...
000
Jeroen van der Ham @jvdham.nl · 04/09/2023
This symbol selection is just mean. 🧪
Part of an article where they used sigma as symbol for mean and mu for standard deviation
010
Jeroen van der Ham @jvdham.nl · 31/08/2023
Also, I have yet to see a case of an actual full disclosure, i.e. a public release of a discovered bug *before* it is fixed in OpenBSD.
000
Jeroen van der Ham @jvdham.nl · 31/08/2023
Still, it would really help if OpenBSD made clear on the Security webpage where they stand. Right now it seems as though OpenBSD is only willing to do Full Disclosure.
100
Jeroen van der Ham @jvdham.nl · 31/08/2023
In my experience, OpenBSD is interested in collaborating with others on security, but just on their terms. They will release a fix when it's ready, and will not wait (long) for others. OpenBSD supports full disclosure, and does not have a disclosure policy.
100
Jeroen van der Ham @jvdham.nl · 31/08/2023
The quote has been updated indeed, as the last part has been removed.
100
Jeroen van der Ham @jvdham.nl · 31/08/2023
It’s still there, just before the closing thoughts heading. Also, this is not an unfair characterisation, openbsd would agree with this assessment, and has acted like this in the past repeatedly.
100
Jeroen van der Ham @jvdham.nl · 29/08/2023
Also a sad observation regarding OpenBSD #CVD response: "My only regret with dealing with the OpenBSD team was reporting the issue to them too quickly, as they are uninterested in waiting for any kind of coordination in disclosure."
121
Jeroen van der Ham @jvdham.nl · 29/08/2023
Interesting post on what can go wrong in BGP, how he tested for this and how this was finally fixed.
blog.benjojo.co.uk
Grave flaws in BGP Error handling
100
Jeroen van der Ham @jvdham.nl · 29/08/2023
CVE 2020-19909 in Curl has been interesting to watch. It's weird that NVD decided last week that it needed a CVSS score, and even weirder that they came up with a 9.8 for it. Now it's been marked "Disputed" with an explanation that it is not likely to be exploited.
000
Jeroen van der Ham @jvdham.nl · 24/08/2023
🧪
001
Jeroen van der Ham @jvdham.nl · 24/08/2023
Interested in a PhD Research position on internet security and post-quantum developments? Please apply! utwentecareers.nl/en/vacancies...
utwentecareers.nl
2x PhD position on transitioning internet protocols and applications to post-quantum cryptography - ...
You will perform your research as part of the DACS group, the Twente University Centre for Cybersecurity Research (TUCCR) and the international context. Interaction with international network operator...
012
Reposted by Jeroen van der Ham
PyroBatNL @pyrobatnl.bsky.social · 16/08/2023
Naomi Wu and the Silence That Speaks Volumes www.hackingbutlegal.com/naomi-wu-an…
hackingbutlegal.com
Naomi Wu and the Silence That Speaks Volumes
When China's prodigious tech influencer, Naomi Wu, found herself silenced, it wasn't just the machinery of a surveillance state at play. Instead, it was a confluence of state repression and the someti...
186
Jeroen van der Ham @jvdham.nl · 16/08/2023
A wonderful short introduction to the current state of LLMs, and some helpful pointers to start hacking yourself (warning: 🐰🕳️) simonwillison.net/2023/Aug/3/weird-…
simonwillison.net
Catching up on the weird world of LLMs
I gave a talk on Sunday at North Bay Python where I attempted to summarize the last few years of development in the space of LLMs—Large Language Models, the technology …
010
Jeroen van der Ham @jvdham.nl · 24/07/2023
I thought that ‘X’ looked familiar. Now you know too:
Xerox logo from 1968-2008 showing the same X as Twitters new name
000
Jeroen van der Ham @jvdham.nl · 23/07/2023
Can’t wait till they’re all talking about “x-ing”, that does not sound awkward at all.
000
Jeroen van der Ham @jvdham.nl · 21/07/2023
That’s what I did with my Sony tv. Pretty happy with it in other regards
000
Jeroen van der Ham @jvdham.nl · 09/07/2023
"Do you want ants? Because that is how you get ants"
010
Jeroen van der Ham @jvdham.nl · 09/07/2023
Mailman "works" in the sense that you need to be an expert to configure it correctly and apparently even mailop is not able to do that. Almost nobody employs people able to run a mailinglist
100