VessOnSecurity @vessonsecurity.bsky.social · 01/10/2026Sorry, that was way before my time - I was just a 9-years old at the time. Try asking him? 100
VessOnSecurity @vessonsecurity.bsky.social · 30/09/2026Maybe Russia was just worried that Karpov would beat Kasparov at chess again. 000
VessOnSecurity @vessonsecurity.bsky.social · 28/09/2026Not sure about that... Trying to fly with 19 suitcases - if it's not a crime, it definitely ought to be. 010
VessOnSecurity @vessonsecurity.bsky.social · 24/09/2026CloudFlare makes that easy: try.cloudflare.com (Yes, when I saw that for the first time, my reaction was "JFC!" too.)try.cloudflare.comCloudflare Quick TunnelsPut localhost on the Internet with a free, encrypted Cloudflare Quick Tunnel. No account, DNS, or open ports required. 000
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026This is only a first iteration. Eventually, there will be a link to a feedback page where people will be able to submit additions/corrections. 010
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026Don't be afraid to make a mistake - e.g., "Fnacy Baer". Press Enter after entering the APT name in the field. You get a list of aliases of that APT, MITRE ATT&CK reference for it, list of companies using these aliases, etc., with clickable links to the web pages the information is based on. 110
VessOnSecurity @vessonsecurity.bsky.social · 18/09/2026I made a thing. APT name cross-reference database you can query: stats.nlcv.bas.bg/d/apt-name-c... Enter the apt name in the "APT name / alias" field (upper left corner). Optionally select a country. Can select only country without an APT name, to see all the APTs from that country.stats.nlcv.bas.bgGrafana 130
VessOnSecurity @vessonsecurity.bsky.social · 14/09/2026In Anthropic's Claude, this setting is definitely off by default. I know, because I've turned mine on; I *want* my conversations to be used to improve the model. It is unfortunate that humans have to read them, though - I would have preferred this to be done by automatic machine learning. 020
VessOnSecurity @vessonsecurity.bsky.social · 14/09/2026But what if I *want* my content to be used to improve the model for everyone? 010
VessOnSecurity @vessonsecurity.bsky.social · 09/09/2026Well, such a request is hardly surprising. Imagine if human soldiers routinely said "Sorry Dave, I can't do that" to their commanding officers... 001
VessOnSecurity @vessonsecurity.bsky.social · 01/09/2026Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...blog.bontchev.nlcv.bas.bgMy battle with cancerBye 120
VessOnSecurity @vessonsecurity.bsky.social · 27/08/2026This totally sounds like something the EU would do. 010
VessOnSecurity @vessonsecurity.bsky.social · 26/08/2026I mostly post on Mastodon these days: infosec.exchange/@bontchev Although, when I update my blog, I post about it on Twitter, BlueSky, LinkedIn, and Facebook too.infosec.exchangeVessOnSecurity (@bontchev@infosec.exchange)10.1K Posts, 51 Following, 1.54K Followers · Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9 010
VessOnSecurity @vessonsecurity.bsky.social · 25/08/2026Was it the word "sophisticated" that shocked you? 000
VessOnSecurity @vessonsecurity.bsky.social · 17/08/2026I have no problem if the watermark says just "this was written by Claude". But it's hidden - who knows what else it contains? Like, which account requested it, where it is based, etc. - data, which is later sold to advertisers or abused by law enforcement. 100
VessOnSecurity @vessonsecurity.bsky.social · 16/08/2026Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...blog.bontchev.nlcv.bas.bgMy battle with cancerBye 240
Reposted by VessOnSecurityEvan Greer @evangreer.bsky.social · 16/08/2026there is no such thing as "age verification." All "age verification" is actually "identity verification." You can coat it in glitter and "privacy-preserving" wrapping paper. But in the end, mandating age verification means mandating surveillance be built into software and hardware. Period. 105138705603
VessOnSecurity @vessonsecurity.bsky.social · 14/08/2026"Pax"?? As in, "solitudinem faciunt, pacem appellant"? 100
VessOnSecurity @vessonsecurity.bsky.social · 04/08/2026Too early. China is not ready. They think long-term. Give it another 5-7 years. 000
Reposted by VessOnSecurityElectronic Frontier Foundation @eff.org · 04/08/2026On Wednesday, the Senate Commerce Committee will vote on four bills that would expand age verification, increase online surveillance, and make it harder to access lawful speech online. Take one minute to tell your senators to vote NO. www.acteff.org/campaign/16...acteff.orgTell the Senate: Don't Turn the Internet Into an ID CheckpointTell the Senate to Reject Bills That Expand Age Verification 7215159
Reposted by VessOnSecurityAsa Dotzler @asadotzler.com · 22/07/2026A company that uses distillation to make its AI models should not be called "Moonshot," but rather "Moonshine." Ba-dum-tss 062
VessOnSecurity @vessonsecurity.bsky.social · 20/07/2026Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...blog.bontchev.nlcv.bas.bgMy battle with cancerBye 021
VessOnSecurity @vessonsecurity.bsky.social · 08/07/2026Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId...blog.bontchev.nlcv.bas.bgMy battle with cancerBye 020
VessOnSecurity @vessonsecurity.bsky.social · 01/07/2026They already have. Claude Sonnet 4.6 (one of the relatively low-grade "safe" models) has been giving me warnings every day because I use it for "dangerous" purposes like fixing bugs in the Cowrie honeypot. ☹️ 000
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026Friend? No. But, as somebody noted, it's a combination of a wise mentor, and unpaid intern, and a garbage can full of rabid raccoons. 030
Reposted by VessOnSecurityLorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 22/06/2026NEW: I took a look at the history of using export controls to limit the proliferation of cyber capabilities. From the 1990s Crypto Wars to limit the spread of PGP, to Wassenaar to stop spyware flowing out of Europe, and now powerful AI models, I argue that this type of regulation does not work.techcrunch.comFrom PGP to Mythos: a brief history of export controls that didn't stop anyone | TechCrunchFor the last 30 years, stopping the flow of cybersecurity-related software has proven to be ineffective. It's unclear why it would work now with Anthropic’s cybersecurity model Mythos. 53725
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026Health (or lack thereof) update: blog.bontchev.nlcv.bas.bg/en?articleId... (Sorry about the delay, the room where the server is, is undergoing renovations and the power is occasionally off.)blog.bontchev.nlcv.bas.bgMy battle with cancerBye 030
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026If I'm around, the Nando's won't last ten minutes. 000
VessOnSecurity @vessonsecurity.bsky.social · 22/06/2026Ah, yes, the worm that never dies. Although, TBH, I haven't seen it hitting my SMB honeypot for a long time (like, 2-3 years). Now do WannaCry. (Chart from that SMB honeypot for the past 3 months.) 010
VessOnSecurity @vessonsecurity.bsky.social · 12/06/2026It's not just Fable. I got this from Claude Sonnet while discussing an ancient virus for mainframes: 150
Reposted by VessOnSecurityViva 🇺🇦 @vivaf1.bsky.social · 11/06/2026Making Iran look like the good guys is quite an achievement. 4808
VessOnSecurity @vessonsecurity.bsky.social · 11/06/2026Wouldn't it be easier to maintain a DB of the not-yet-abused ones? 000
VessOnSecurity @vessonsecurity.bsky.social · 07/06/2026Not sure if this says bad things about the U.S. government, about the SPIEF, or about the RSA Conference... 130
VessOnSecurity @vessonsecurity.bsky.social · 05/06/2026I always thought that Americans said this sarcastically. 030
Reposted by VessOnSecurityDean Pierce @deanpierce.net · 01/06/2026My "NOT A BOMB" bluetooth device name has people asking a lot of questions already answered by the device name. 0165