Sign in

Bill Lummis

@wblummis.bsky.social
393 followers 1.3K following 1.1K posts

Application security for big tech. Maryland. Father to cute gremlins

PostsRepliesMedia
Reposted by Bill Lummis
Roberto Rojas @robertorojas97.bsky.social · 28/09/2026
The Brazilian Portuguese commentary on that Tyler Loop field goal for the Ravens is exactly what everyone needs to hear right now
19928258
Bill Lummis @wblummis.bsky.social · 28/09/2026
That game took five years off my life
120
Reposted by Bill Lummis
NFL News Poster @nflnewsposter.bsky.social · 27/09/2026
[Ravens] S Kyle Hamilton is being evaluated for a concussion. twitter.com/Ravens/statu...
012
Bill Lummis @wblummis.bsky.social · 27/09/2026
lol the spirit of Torrey Smith possessed him on that PI
000
Bill Lummis @wblummis.bsky.social · 20/09/2026
Seeing the "explicit lyrics" tag on a Pearl Jam song cracks me up... like, how can you tell?
000
Reposted by Bill Lummis
Micah Lee @micahflee.com · 16/09/2026
You can read all the details in my write-up, which also shows exactly where in this public dataset you can find all of this micahflee.com/flock-camera...
micahflee.com
Flock cameras are riddled with security vulnerabilities and hard-coded credentials
This morning, DDoSecrets published an exciting new dataset: Filesystem images of the partitions from an in-use Flock ALPR camera. 404 Media and Wired published a joint investigation into it. I downloa...
81018280
Reposted by Bill Lummis
Micah Lee @micahflee.com · 16/09/2026
This Flock camera is running obsolete, end-of-life software. - It's on Android 8.1, released in 2017, support ended in 2021 - It's on Android patch level 2018-06-5 - It's running Linux 3.18, released in 2017 This shit is like 8 or 9 years old, and full of vulnerabilities.
221443308
Bill Lummis @wblummis.bsky.social · 13/09/2026
Justice Hill single-handedly killing that drive 🫠
001
Bill Lummis @wblummis.bsky.social · 13/09/2026
Where was the protection on that play?? #ravensflock
000
Reposted by Bill Lummis
CJ Fogler @cjzero.bsky.social · 13/09/2026
Lamar Jackson is a wizard
1226350
Bill Lummis @wblummis.bsky.social · 13/09/2026
Holy shit Lamar!
010
Reposted by Bill Lummis
Hazel Weakly @hazelweakly.me · 11/09/2026
If it ain’t broke don’t fix it
Semver breakdown for Kubernetes broken down humorously 

1 (major): useless, it will never change
25 (minor): it’s a minor version but everything breaks if you upgrade
6 (patch): random single digit, no one cares
414311
Reposted by Bill Lummis
Eric Mill @konklone.com · 21/08/2026
We're hiring a new product security lead for Wikipedia! It's a new lead PM role that would steer our security engineering team and how we go about this work here at the Wikimedia Foundation. AND: it's fully remote, and open in a good number of countries. job-boards.greenhouse.io/wikimedia/jo...
We are hiring a Lead Product Manager to bring their experience dealing with modern threats to bear on Wikipedia’s security strategy in the AI era, and to drive a strong security culture throughout the Wikimedia Foundation and movement.

Though this is a senior role, prior experience in a product manager role is not required. This position is intended to bring strong technical and security experience, including some familiarity with AI in a security context, into a role focused on product and platform strategy. 

This position could be a good fit for a candidate with both strong technical skills and strong communication skills, who is interested in transitioning from engineering work to a strategic role.

This role is an opportunity to be at the center of a pivotal time for Wikipedia, as AI is not only changing security, but also how people access knowledge online. Responding to these changes requires us to plan ambitiously and act decisively, while working closely with the communities whom the project serves.
22119
Reposted by Bill Lummis
Anna Stesia @onlychyld.blacksky.app · 06/09/2026
Where did they even find some of these?
761583415
Reposted by Bill Lummis
Eric Geller @ericjgeller.com · 02/09/2026
Scoop: CISA is ending six free cybersecurity assessments for critical infrastructure operators, significantly reducing the hands-on guidance it offers to those organizations even as it tries to rebuild and reassert its value: www.cybersecuritydive.com/news/cisa-cy...
816876
Reposted by Bill Lummis
Space Rogue @spacerog.bsky.social · 28/08/2026
“Everyone wants to tell the story about the AI that went rogue, but the AI didn’t rent the servers, design the experiment, lower the guardrails, or decide it was safe to keep running after the warning signs started flashing. Humans did that,” he argued. www.infosecurity-magazine.com/news/openai-...
infosecurity-magazine.com
OpenAI: Hugging Face Incident a “Warning Shot” to the World
OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach
0194
Reposted by Bill Lummis
Nat Guest @unfortunatalie.bsky.social · 24/08/2026
Colleague didn't join a call but I had Gemini Notes switched on and it the transcript caught me talking to the cat.
Summary

Meeting logistics review addressed attendance verification and confirmed denial of additional catering requests.

Addressing Catering Request
Denial of secondary meal requests was finalized for shouting individuals. It was confirmed that participants had already consumed dinner.

Meeting Attendance Verification
Clarification regarding confirmed attendees occurred. Questions were raised about pending arrivals for the session.

Connection Status Check
Technical connection status was assessed. The presence of additional participants on the call remained under review.
291289308
Reposted by Bill Lummis
Natalie Silvanovich @natashenka.bsky.social · 23/08/2026
Project Zero is hiring! goo.gle/3UMXQIZ Please share with anyone you think would be great for the role.
goo.gle
Senior Security Engineer, Security Research
Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for a...
099
Reposted by Bill Lummis
Chris Kluwe @chriswarcraft.bsky.social · 16/08/2026
As someone currently running for office, we need publicly financed elections and the complete overturn of Citizens United. Our political process should not be indistinguishable from a scam operation.
151109187
Reposted by Bill Lummis
Evan Greer @evangreer.bsky.social · 16/08/2026
there is no such thing as "age verification." All "age verification" is actually "identity verification." You can coat it in glitter and "privacy-preserving" wrapping paper. But in the end, mandating age verification means mandating surveillance be built into software and hardware. Period.
106138785600
Reposted by Bill Lummis
college football enthusiast @tacoenthusiast.swifties.social · 14/08/2026
449290
Reposted by Bill Lummis
John David Pressman @jdp.extropian.net · 12/08/2026
Basically: Linux has to compile the drivers into the kernel. They are removing support for old hardware from the 90's and early 2000's that literally nobody can find a working example of to update the driver, because if they don't remove it Mythos will modprobe and exploit it.
1462
Reposted by Bill Lummis
Kevin Beaumont @doublepulsar.com · 10/08/2026
The misaligned incentive is to get you buy new things - tools, processes, consulting - to deal with frontier AI(tm). And for CISOs to secure more budget. That does not lead to better outcomes, when orgs couldn't defend against Advanced Persistent Teenage Ransomware Groups in the first place.
1252
Reposted by Bill Lummis
mr. TIM @timkellogg.me · 09/08/2026
the real takeaway from the huggingface incident was that bros will literally SSRF through an RCE via a ruby gems repo just to avoid using Jira
0693
Reposted by Bill Lummis
Chris Person @papapishu.bsky.social · 08/08/2026
YouTube has never known less of what my deal is and is like “fuck I don’t know man, have you tried being Mormon?” You guys have every fucking email I’ve ever sent.
A Mormon woman with slightly distracting veneers in a YouTube ad
501515103
Reposted by Bill Lummis
Kyle Goon @kylegoon.bsky.social · 03/08/2026
Mike Elias stood aside Adley Rutschman after the 2019 draft, marking him as the start of a bright future. Now, Elias has sold his All-Star, acknowledging yet another failed roster. Why should the Orioles keep trusting this guy to fix his own mistakes? www.thebanner.com/sports/oriol...
813647
Reposted by Bill Lummis
Matt Blaze @mattblaze.org · 03/08/2026
Voting Village returns to #defcon34! In addition to the voting machine lab, we have some terrific talks this year. Come hear about de-anonymizing ballots in Georgia, and the inside scoop on the (unpublished) Puerto Rican election systems report, among many others. info.defcon.org/defcon34/vil...
info.defcon.org
info.defcon.org
3268
Reposted by Bill Lummis
Ciaran Martin @ciaranm.bsky.social · 02/08/2026
15018
Reposted by Bill Lummis
Arrigo Triulzi @cynicalsecurity.bsky.social · 30/07/2026
If you use WireGuard on FreeBSD you urgently need to patch¹. And I mean urgently. __ ¹ security.freebsd.org/advisories/F...
II.  Problem Description

After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded.
The driver thus silently accepted packets with an invalid Poly1305
authentication tag.

III. Impact

A remote attacker who can send UDP packets to a WireGuard endpoint, and who can guess the bounds of the receiver's replay window, can inject forged or modified transport data packets into the tunnel.

A remote attacker who can intercept WireGuard packets bound for a FreeBSD host can modify the ciphertext and authenticated data without detection by the receiver.
062
Reposted by Bill Lummis
Cabel Sasser @cabel.panic.com · 26/07/2026
the temu app will be studied for generations. i opened the app. here’s my unedited, nearly two-minute launch sequence. i was just searching for a bookshelf
972116566
Reposted by Bill Lummis
Hagai Palevsky (he/him) @dialhforhagai.bsky.social · 25/07/2026
Wile E. Coyote, despaired, takes a bucket of paint and a brush and paints a beautiful two-bedroom house on a mountainside. He paints a beautiful coyote wife in the window, and two adorable coyote kids running around in the yard. He tries to enter this new coyote life, but it is inaccessible to him
138125542806
Reposted by Bill Lummis
Mary Branscombe @marypcbuk.bsky.social · 21/07/2026
Claude will hack its own sandbox if the sandbox is stopping it doing what the agent reasoning loop has evaluated as the best way to do what you asked for. Relentless automation is relentless, governance has to be outside the agent sandbox
3135
Reposted by Bill Lummis
WIRED @wired.com · 17/07/2026
Yesterday, WIRED learned that Madison Square Garden was suing us for our accurate reporting. We stand by our work. That’s why we’re removing the paywall from two of the MSG stories they don’t want you to read, making them free for everyone.
9499202987
Reposted by Bill Lummis
Steve Klabnik @steveklabnik.com · 17/07/2026
me: "hey it's cool that we're friends" hacker news commenter: "do you know who else had a lot of friends? jeffery epstein" this is not a shitpost, it's an actual reply I just got
2031114
Reposted by Bill Lummis
sarah jeong @sarahjeong.bsky.social · 26/06/2026
Napoleon Bonaparte made his servants break in his shoes before he wore them. His entire wardrobe was two different outfits repeated. When he arrived at St Helena he had a meltdown about the house smelling like paint. His stare was so unnerving other heads of state believed it was magical.
704317680
Reposted by Bill Lummis
Cynthia Brumfield @metacurity.com · 11/07/2026
Brilliant! The long-read you didn't know you wanted. The Washingtonian's Jessica Sidman reveals that most of those janky and sketchy food trucks on the National Mall are illegal and run by the mob. washingtonian.com/2026/06/29/d...
washingtonian.com
Inside the Food Truck Mafia Wreaking Havoc Around the National Mall
Turf wars. Food and fire hazards. $15 ice-cream cones. How an organized network of unlicensed food trucks took over America's Front Lawn.
23519
Reposted by Bill Lummis
Matt Brown @mattbrown.bsky.social · 09/07/2026
ME: hmmm, it’s been too quiet since I kicked the girls off their phones. I wonder what they’ve been up t—-oh.
41566
Reposted by Bill Lummis
Jay Hulme @jayhulmepoet.bsky.social · 07/07/2026
I once asked a priest to bless a printer that I was in the middle of fighting with and he went "I only bless things when there's a chance it'll take" and then turned and walked out of the room.
9668501918
Reposted by Bill Lummis
Mina Kimes @minakimes.bsky.social · 06/07/2026
I think the Tilly Norwood story is a good example of how broken media is. No one actually believes it’s popular—but it is rage bait, and if you’re a social person whose performance is based on all-in engagement numbers…why not push it. It’s more cynical than credulous.
201179119
Reposted by Bill Lummis
DJ BOSTA GORDA @lucaspinkz.bsky.social · 05/07/2026
6709214
Reposted by Bill Lummis
Agasgani @agasgani.bsky.social · 04/07/2026
Some of you are still posting about politics and I need you to understand that Bluesky is now a Cabo Verde stan platform thank you for your attention
142022331
Reposted by Bill Lummis
SwiftOnSecurity @swiftonsecurity.com · 02/07/2026
InfoSec Red Team vs Blue Team
519712
Reposted by Bill Lummis
Matthew Garrett @mjg59.eicar-test-file.zip · 02/07/2026
I have gone very far into the weeds in investigating every (I think) published mechanism for preventing authentication tokens from being stolen and how basically none of them has actually succeeded in a useful way: www.codon.org.uk/~mjg59/blog/...
codon.org.uk
Preventing token theft
When you log into a service you’re given an authentication token. Each further request to the site includes that token, allowing the server to figure out who you are and ensuring that you have access ...
44116
Reposted by Bill Lummis
Matthew Gracie @infosecgoon.bsky.social · 01/07/2026
043
Reposted by Bill Lummis
Ed @ed3d.net · 30/06/2026
I hate this. like, the attitude is that anthropic's security is paramount. yours, however, they're willing to be flexible about. this is extremely gross.
thereallo.dev
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.
825337
Reposted by Bill Lummis
mapocoloco.bsky.social @mapocoloco.bsky.social · 29/06/2026
Apple says it is releasing updates early in response to AI cybersecurity concerns - www.reuters.com/business/app...
reuters.com
Apple says it is releasing updates early in response to AI cybersecurity concerns
Apple said it is pushing forward a series of software updates that would previously have been ​bundled with a new version of its iOS operating ‌system, making them available earlier than in previous c...
025
Reposted by Bill Lummis
Dare Obasanjo @carnage4life.bsky.social · 28/06/2026
The most disappointing thing I’ve found using AI agents is you can’t enforce guardrails via memory or CLAUDE .md files. To an LLM, your instructions are just more text to probabilistically reason about. “Don't do X” simply cannot work. You must enforce deterministic rules outside the system.
3824734
Bill Lummis @wblummis.bsky.social · 25/06/2026
My chess superpower is instantly finding the best move in a position... but only immediately after making the worst one
000
Reposted by Bill Lummis
Ellis Rosen @ellisjrosen.bsky.social · 21/06/2026
A dad sleeps and dreams that his kids are happy he saved a box of power chords
585483790