Sign in

VessOnSecurity

@vessonsecurity.bsky.social
349 followers 28 following 671 posts

Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9

PostsRepliesMedia
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026
I made a thing. APT name cross-reference database you can query: stats.nlcv.bas.bg/d/apt-name-c... Enter the apt name in the "APT name / alias" field (upper left corner). Optionally select a country. Can select only country without an APT name, to see all the APTs from that country.
stats.nlcv.bas.bg
Grafana
130
VessOnSecurity @vessonsecurity.bsky.social · 01/09/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
120
VessOnSecurity @vessonsecurity.bsky.social · 16/08/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
240
Reposted by VessOnSecurity
Evan Greer @evangreer.bsky.social · 16/08/2026
there is no such thing as "age verification." All "age verification" is actually "identity verification." You can coat it in glitter and "privacy-preserving" wrapping paper. But in the end, mandating age verification means mandating surveillance be built into software and hardware. Period.
106138745601
Reposted by VessOnSecurity
Electronic Frontier Foundation @eff.org · 04/08/2026
On Wednesday, the Senate Commerce Committee will vote on four bills that would expand age verification, increase online surveillance, and make it harder to access lawful speech online. Take one minute to tell your senators to vote NO. www.acteff.org/campaign/16...
acteff.org
Tell the Senate: Don't Turn the Internet Into an ID Checkpoint
Tell the Senate to Reject Bills That Expand Age Verification
7215159
Reposted by VessOnSecurity
Asa Dotzler @asadotzler.com · 22/07/2026
A company that uses distillation to make its AI models should not be called "Moonshot," but rather "Moonshine." Ba-dum-tss
062
VessOnSecurity @vessonsecurity.bsky.social · 20/07/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
021
VessOnSecurity @vessonsecurity.bsky.social · 08/07/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
020
Reposted by VessOnSecurity
foxfirefey @foxfirefey.bsky.social · 23/06/2026
Brian Graham (tribute)
@iroasmas
• • •
me: "a lot of this old code was written by an idiot dev who was flagrantly ignorant of the business context. we're all still paying for those sins"
them: "git says it was written by you 3 years ago?"
me: "that's right"
7:24 AM • Aug 3, 2023
333481
Reposted by VessOnSecurity
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/06/2026
NEW: I took a look at the history of using export controls to limit the proliferation of cyber capabilities. From the 1990s Crypto Wars to limit the spread of PGP, to Wassenaar to stop spyware flowing out of Europe, and now powerful AI models, I argue that this type of regulation does not work.
techcrunch.com
From PGP to Mythos: a brief history of export controls that didn't stop anyone | TechCrunch
For the last 30 years, stopping the flow of cybersecurity-related software has proven to be ineffective. It's unclear why it would work now with Anthropic’s cybersecurity model Mythos.
53725
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId... (Sorry about the delay, the room where the server is, is undergoing renovations and the power is occasionally off.)
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
030
Reposted by VessOnSecurity
Kevin Beaumont @doublepulsar.com · 21/06/2026
UK politics explained
4498
Reposted by VessOnSecurity
Viva 🇺🇦 @vivaf1.bsky.social · 11/06/2026
Making Iran look like the good guys is quite an achievement.
4808
Reposted by VessOnSecurity
Dean Pierce @deanpierce.net · 01/06/2026
My "NOT A BOMB" bluetooth device name has people asking a lot of questions already answered by the device name.
0165
Reposted by VessOnSecurity
Frovo @frovo.bsky.social · 01/06/2026
boss just asked me to “send her the link” yeah okay zelda
8715110
Reposted by VessOnSecurity
Robert Graham @erratarob.bsky.social · 01/06/2026
Do not name your Bluetooth devices "BOMB", or your flight maybe diverted. I suggest something like "NOT A BOMB" to avoid confusion.
2224
Reposted by VessOnSecurity
Robert Graham @erratarob.bsky.social · 29/05/2026
It's unethical for hackers to break into computers they don't own (or have permission for). It's unethical for vendors to threaten criminal penalties for lawful actions, especially disclosure. These are equivalent ethical breaches.
1184
Reposted by VessOnSecurity
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 29/05/2026
Not that ‘responsible’ disclosure shit again 🙄 No vendor uses that term unless they want to call someone irresponsible. Even if someone drops 0day, patch & move on. Going after a researcher is a great way to turn 1 bad relationship into many terrible relationships.
18831
Reposted by VessOnSecurity
Catalin Cimpanu @campuscodi.risky.biz · 28/05/2026
Watch out bug hunters! Microsoft will release its DiGiTaL cRiMeS uNiT on you if you don't play along and let them delete your MSRC account and bury bugs for the billion dollar corporation
3333
Reposted by VessOnSecurity
Jason Kikta @kikta.net · 26/05/2026
Google: AI will make software development so much faster Me: Finally, they will finish Google Workspace Google: Nah, we’ve just jammed our garbage AI into every crevice and updated our icons for a preschool look
25410
Reposted by VessOnSecurity
NY Times Pitchbot @nytpitchbot.bsky.social · 24/05/2026
Donald Trump promised the war in Iran would end with unconditional surrender. But he never said which country would do the surrendering.
623286720
Reposted by VessOnSecurity
Matthew Green @matthewdgreen.bsky.social · 22/05/2026
My son is doing an internship where (against all my attempts to persuade him into a different career) he’s looking for security vulnerabilities in Chinese-made medical devices, and oh boy is he finding them. I feel like this is unhealthy validation for an 18 year old’s first job.
822124
Reposted by VessOnSecurity
Andrea @valkyrie.hacker.gf · 17/05/2026
What the hell is this cancer, reCAPTCHA?
106117
VessOnSecurity @vessonsecurity.bsky.social · 14/05/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
040
Reposted by VessOnSecurity
kourge the jafnhár 🏳️‍🌈 @kourge.net · 12/05/2026
enough. i’m tired of github actions. it’s time for github consequences
292577665
Reposted by VessOnSecurity
SwiftOnSecurity @swiftonsecurity.com · 08/05/2026
Next time you call America racist I want to show you a picture of how multi-ethnic and multi-cultural our auto theft rings are.
8833
Reposted by VessOnSecurity
Opinion Editor @ Bluesky @dly.bsky.social · 07/05/2026
god forbid a French rat live out his dream of becoming a chef on a cruiseship
143976739
Reposted by VessOnSecurity
spooky tail latency @bluespacecanary.bsky.social · 28/04/2026
microsoft may actually have managed mismanage github so badly that it loses its effective monopoly despite none of its aspiring competitors being remotely prepared to replace it. incredible
4792117
VessOnSecurity @vessonsecurity.bsky.social · 28/04/2026
Health (or lack thereof) update. The old single web page has become too large and unwieldly. People have trouble reading the newest entries without cleaning their browser cache. So, a friend and a colleague of mine helped me create a more professionally-looking blog.
120
Reposted by VessOnSecurity
Javvad Malik @j4vv4d.com · 27/04/2026
South Africa’s draft AI policy was just withdrawn because the references were hallucinated by AI. The department regulating "AI Ethics" couldn't even be bothered to check if their own footnotes existed. It’s a masterclass in irony: using AI to write the rules for AI. iol.co.za/news/south-a...
iol.co.za
Minister Solly Malatsi's withdrawal of draft national AI policy for its fabricated sources 'embarrassing and damning'
Minister Solly Malatsi faces criticism after withdrawing South Africa's draft AI policy due to fabricated sources in its reference list.
0167
VessOnSecurity @vessonsecurity.bsky.social · 16/04/2026
Health (or lack thereof) update: bontchev.nlcv.bas.bg/bye.html#202...
bontchev.nlcv.bas.bg
Bye
030
Reposted by VessOnSecurity
Natalie Brender @nataliebrender.bsky.social · 16/04/2026
1. Kids motivated to get around the age verification requirement can *easily* do so 2. Age verification means *every* social media user must give ID to tech companies 3. Kids in need of social/identity support unavailable IRL would suffer 4. The real solution is to regulate tech companies not kids
1125
Reposted by VessOnSecurity
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 12/04/2026
It’s pretty jarring to read articles about the war in Iran that mention the energy crisis and the strait of Hormuz as its consequence, but don’t mention civilian casualties at all. I feel like every article that discusses the war should include the worst consequences of it — even just two lines.
212831
Reposted by VessOnSecurity
hikikomorphism @hikikomorphism.bsky.social · 12/04/2026
I have a long-running Claude session just for talking about Iran war news/economic shocks from the blockade. I shared the latest Trump tweet and it told me that it can no longer keep role-playing this fictional scenario because it's becoming concerning and detached from reality. Love this timeline.
923132
Reposted by VessOnSecurity
Abolish ICE 🐦‍⬛ @schuyler.info · 10/04/2026
(via @atomjack.com)
a split image, showing the Earth and the words "Apollo 11" and "That's one small step for man, one giant leap for Mankind - Neil Armstrong"

under that an image of a crescent earth partly set behind the limb of the moon, and the words "Artemis II" and "I have two Microsoft Outlooks and neither one of those are working - Reid Wiseman"
08322
Reposted by VessOnSecurity
Zack Whittaker @zackwhittaker.com · 08/04/2026
New, by me at TechCrunch: The developer of the widely popular Wireguard VPN says he is also unable to ship software updates to Windows users after Microsoft locked his account, marking the second high-profile app developer (VeraCrypt) in the past few weeks to face this issue.
techcrunch.com
WireGuard VPN developer can't ship software updates after Microsoft locks account | TechCrunch
The popular open source VPN maker is the second high-profile developer to say Microsoft locked his account without notifying him and are blocking their ability to send software updates to users.
410866
Reposted by VessOnSecurity
Zack Whittaker @zackwhittaker.com · 08/04/2026
New, by me: Mounir Idrassi, the developer of the popular file encryption software Veracrypt, says Microsoft has locked his account used for sending software updates, and warned that Windows users who encrypt their PCs with his software may soon find it "impossible to boot," Idrassi tells me.
techcrunch.com
Developer of VeraCrypt encryption software says Windows users may face boot-up issues after Microsoft locked his account | TechCrunch
The maker of the popular open-source file encryption software VeraCrypt said Microsoft locked his online account, which may prevent device owners from booting up their computers.
22216
Reposted by VessOnSecurity
Matthew Green @matthewdgreen.bsky.social · 08/04/2026
We should be able to slow down AI takeover by a few years just by telling the model to find every bug in ffmpeg.
5859
VessOnSecurity @vessonsecurity.bsky.social · 01/04/2026
Health (or lack thereof) update: bontchev.nlcv.bas.bg/bye.html#202...
bontchev.nlcv.bas.bg
Bye
140
Reposted by VessOnSecurity
Catalin Cimpanu @campuscodi.risky.biz · 31/03/2026
Despite losing the US and EU market, Kaspersky reported a record revenue of $836 million last year www.kaspersky.ru/about/press-...
034
Reposted by VessOnSecurity
David Buchanan @retr0.id · 29/03/2026
47% of all statistics were hallucinated by claude
1923
Reposted by VessOnSecurity
Eric Rescorla @rtfm.com · 28/03/2026
This week on the newsletter: "How not to mandate device-based age assurance" educatedguesswork.org/posts/device... In this post, we examine a number of enacted or proposed requirements for device-based age assurance and some of the ways they can go wrong.
educatedguesswork.org
How not to mandate device-based age assurance
Software design by legal mandate
154
Reposted by VessOnSecurity
Matthew Green @matthewdgreen.bsky.social · 26/03/2026
Ask Claude about the string “ba7816bf8f01cfea414140de5dae2ec73b00361bbef0469f11ef0b01d449c8e6”. When it gives you an answer: ask it to verify that this number is correct.
9296
VessOnSecurity @vessonsecurity.bsky.social · 24/03/2026
Health (or lack thereof) update: bontchev.nlcv.bas.bg/bye.html#202...
bontchev.nlcv.bas.bg
Bye
000
Reposted by VessOnSecurity
Ned Pyle @nedpyle.com · 20/03/2026
I don’t want mass layoffs but every manager up the chain in Windows who signed off on copilot in Notepad should be terminated with cause
310326
Reposted by VessOnSecurity
Matthew Green @matthewdgreen.bsky.social · 20/03/2026
Things are going well with Google AI.
7386
Reposted by VessOnSecurity
Matthew Green @matthewdgreen.bsky.social · 20/03/2026
Using Tor in 2026.
39211
VessOnSecurity @vessonsecurity.bsky.social · 18/03/2026
Health (or lack thereof) update: bontchev.nlcv.bas.bg/bye.html#202...
bontchev.nlcv.bas.bg
Bye
111
VessOnSecurity @vessonsecurity.bsky.social · 10/03/2026
Health (or lack thereof) update: bontchev.nlcv.bas.bg/bye.html#202...
bontchev.nlcv.bas.bg
Bye
000