Sign in

VessOnSecurity

@vessonsecurity.bsky.social
349 followers 28 following 671 posts

Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9

PostsRepliesMedia
VessOnSecurity @vessonsecurity.bsky.social · 01/10/2026
Sorry, that was way before my time - I was just a 9-years old at the time. Try asking him?
100
VessOnSecurity @vessonsecurity.bsky.social · 30/09/2026
Maybe Russia was just worried that Karpov would beat Kasparov at chess again.
000
VessOnSecurity @vessonsecurity.bsky.social · 28/09/2026
Not sure about that... Trying to fly with 19 suitcases - if it's not a crime, it definitely ought to be.
010
VessOnSecurity @vessonsecurity.bsky.social · 24/09/2026
CloudFlare makes that easy: try.cloudflare.com (Yes, when I saw that for the first time, my reaction was "JFC!" too.)
try.cloudflare.com
Cloudflare Quick Tunnels
Put localhost on the Internet with a free, encrypted Cloudflare Quick Tunnel. No account, DNS, or open ports required.
000
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026
This is only a first iteration. Eventually, there will be a link to a feedback page where people will be able to submit additions/corrections.
010
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026
Don't be afraid to make a mistake - e.g., "Fnacy Baer". Press Enter after entering the APT name in the field. You get a list of aliases of that APT, MITRE ATT&CK reference for it, list of companies using these aliases, etc., with clickable links to the web pages the information is based on.
110
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026
I made a thing. APT name cross-reference database you can query: stats.nlcv.bas.bg/d/apt-name-c... Enter the apt name in the "APT name / alias" field (upper left corner). Optionally select a country. Can select only country without an APT name, to see all the APTs from that country.
stats.nlcv.bas.bg
Grafana
130
VessOnSecurity @vessonsecurity.bsky.social · 14/09/2026
In Anthropic's Claude, this setting is definitely off by default. I know, because I've turned mine on; I *want* my conversations to be used to improve the model. It is unfortunate that humans have to read them, though - I would have preferred this to be done by automatic machine learning.
020
VessOnSecurity @vessonsecurity.bsky.social · 14/09/2026
But what if I *want* my content to be used to improve the model for everyone?
010
VessOnSecurity @vessonsecurity.bsky.social · 09/09/2026
Shut up, Claude.
000
VessOnSecurity @vessonsecurity.bsky.social · 09/09/2026
Well, such a request is hardly surprising. Imagine if human soldiers routinely said "Sorry Dave, I can't do that" to their commanding officers...
001
VessOnSecurity @vessonsecurity.bsky.social · 06/09/2026
Maybe they were afraid of being deported.
000
VessOnSecurity @vessonsecurity.bsky.social · 05/09/2026
Why only 12 months?
000
VessOnSecurity @vessonsecurity.bsky.social · 01/09/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
120
VessOnSecurity @vessonsecurity.bsky.social · 27/08/2026
This totally sounds like something the EU would do.
010
VessOnSecurity @vessonsecurity.bsky.social · 26/08/2026
I mostly post on Mastodon these days: infosec.exchange/@bontchev Although, when I update my blog, I post about it on Twitter, BlueSky, LinkedIn, and Facebook too.
infosec.exchange
VessOnSecurity (@bontchev@infosec.exchange)
10.1K Posts, 51 Following, 1.54K Followers · Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9
010
VessOnSecurity @vessonsecurity.bsky.social · 25/08/2026
Was it the word "sophisticated" that shocked you?
000
VessOnSecurity @vessonsecurity.bsky.social · 25/08/2026
Is that a remake of "Oedipus"?
000
VessOnSecurity @vessonsecurity.bsky.social · 17/08/2026
I have no problem if the watermark says just "this was written by Claude". But it's hidden - who knows what else it contains? Like, which account requested it, where it is based, etc. - data, which is later sold to advertisers or abused by law enforcement.
100
VessOnSecurity @vessonsecurity.bsky.social · 16/08/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
240
Reposted by VessOnSecurity
Evan Greer @evangreer.bsky.social · 16/08/2026
there is no such thing as "age verification." All "age verification" is actually "identity verification." You can coat it in glitter and "privacy-preserving" wrapping paper. But in the end, mandating age verification means mandating surveillance be built into software and hardware. Period.
105138705603
VessOnSecurity @vessonsecurity.bsky.social · 14/08/2026
"Pax"?? As in, "solitudinem faciunt, pacem appellant"?
100
VessOnSecurity @vessonsecurity.bsky.social · 04/08/2026
Too early. China is not ready. They think long-term. Give it another 5-7 years.
000
Reposted by VessOnSecurity
Electronic Frontier Foundation @eff.org · 04/08/2026
On Wednesday, the Senate Commerce Committee will vote on four bills that would expand age verification, increase online surveillance, and make it harder to access lawful speech online. Take one minute to tell your senators to vote NO. www.acteff.org/campaign/16...
acteff.org
Tell the Senate: Don't Turn the Internet Into an ID Checkpoint
Tell the Senate to Reject Bills That Expand Age Verification
7215159
VessOnSecurity @vessonsecurity.bsky.social · 24/07/2026
030
Reposted by VessOnSecurity
Asa Dotzler @asadotzler.com · 22/07/2026
A company that uses distillation to make its AI models should not be called "Moonshot," but rather "Moonshine." Ba-dum-tss
062
VessOnSecurity @vessonsecurity.bsky.social · 20/07/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
021
VessOnSecurity @vessonsecurity.bsky.social · 09/07/2026
TEMU?
010
VessOnSecurity @vessonsecurity.bsky.social · 08/07/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
020
VessOnSecurity @vessonsecurity.bsky.social · 01/07/2026
They already have. Claude Sonnet 4.6 (one of the relatively low-grade "safe" models) has been giving me warnings every day because I use it for "dangerous" purposes like fixing bugs in the Cowrie honeypot. ☹️
000
VessOnSecurity @vessonsecurity.bsky.social · 01/07/2026
Yeah, we Europeans are big on eco stuff.
000
VessOnSecurity @vessonsecurity.bsky.social · 01/07/2026
Obviously, it's to fight pirates, what.
000
VessOnSecurity @vessonsecurity.bsky.social · 30/06/2026
No.
000
VessOnSecurity @vessonsecurity.bsky.social · 25/06/2026
*Watto voice*: Cancer always wins.
010
VessOnSecurity @vessonsecurity.bsky.social · 25/06/2026
No dormant cyber pathogens?
000
Reposted by VessOnSecurity
foxfirefey @foxfirefey.bsky.social · 23/06/2026
Brian Graham (tribute)
@iroasmas
• • •
me: "a lot of this old code was written by an idiot dev who was flagrantly ignorant of the business context. we're all still paying for those sins"
them: "git says it was written by you 3 years ago?"
me: "that's right"
7:24 AM • Aug 3, 2023
333481
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026
Friend? No. But, as somebody noted, it's a combination of a wise mentor, and unpaid intern, and a garbage can full of rabid raccoons.
030
Reposted by VessOnSecurity
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/06/2026
NEW: I took a look at the history of using export controls to limit the proliferation of cyber capabilities. From the 1990s Crypto Wars to limit the spread of PGP, to Wassenaar to stop spyware flowing out of Europe, and now powerful AI models, I argue that this type of regulation does not work.
techcrunch.com
From PGP to Mythos: a brief history of export controls that didn't stop anyone | TechCrunch
For the last 30 years, stopping the flow of cybersecurity-related software has proven to be ineffective. It's unclear why it would work now with Anthropic’s cybersecurity model Mythos.
53725
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026
Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId... (Sorry about the delay, the room where the server is, is undergoing renovations and the power is occasionally off.)
blog.bontchev.nlcv.bas.bg
My battle with cancer
Bye
030
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026
If I'm around, the Nando's won't last ten minutes.
000
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026
Ah, yes, the worm that never dies. Although, TBH, I haven't seen it hitting my SMB honeypot for a long time (like, 2-3 years). Now do WannaCry. (Chart from that SMB honeypot for the past 3 months.)
010
Reposted by VessOnSecurity
Kevin Beaumont @doublepulsar.com · 21/06/2026
UK politics explained
4498
VessOnSecurity @vessonsecurity.bsky.social · 16/06/2026
1999, Kosovo.
020
VessOnSecurity @vessonsecurity.bsky.social · 13/06/2026
I thought the word was "fascism"?
110
VessOnSecurity @vessonsecurity.bsky.social · 12/06/2026
It's not just Fable. I got this from Claude Sonnet while discussing an ancient virus for mainframes:
150
Reposted by VessOnSecurity
Viva 🇺🇦 @vivaf1.bsky.social · 11/06/2026
Making Iran look like the good guys is quite an achievement.
4808
VessOnSecurity @vessonsecurity.bsky.social · 11/06/2026
Wouldn't it be easier to maintain a DB of the not-yet-abused ones?
000
VessOnSecurity @vessonsecurity.bsky.social · 07/06/2026
Not sure if this says bad things about the U.S. government, about the SPIEF, or about the RSA Conference...
130
VessOnSecurity @vessonsecurity.bsky.social · 05/06/2026
I always thought that Americans said this sarcastically.
030
Reposted by VessOnSecurity
Dean Pierce @deanpierce.net · 01/06/2026
My "NOT A BOMB" bluetooth device name has people asking a lot of questions already answered by the device name.
0165