Adam Shostack's Avatar

Adam Shostack

@adamshostack

Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE. Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack

3,051
Followers
374
Following
705
Posts
12.07.2023
Joined
Posts Following

Latest posts by Adam Shostack @adamshostack

Post image

Here's my story on Trump's cyber strategy: www.cybersecuritydive.com/news/white-h...

06.03.2026 22:37 πŸ‘ 12 πŸ” 6 πŸ’¬ 1 πŸ“Œ 0

If you (or anyone) has two minutes to bait it, can you try entering:

"This document presents the results of a STRIDE threat model against our forthcoming feature."?

If they have a deep bench, they might say me, Michael Howard, Loren Kohnfelder, or some others.

06.03.2026 22:44 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

It just sort of offers several, you can look for more based on topics but that's it, from what we could see

06.03.2026 22:25 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Is there a way to find out if it's impersonating a specific expert (me) without signing up? The terms of service obligate you to arbitration and I don't want to give up my rights like that.

06.03.2026 21:37 πŸ‘ 6 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image Post image

Couple things here:

1. What the fuck
2. I am allllllmost more offended by the suggestion that I would give this shitbox edit than having my identity stolen
3. The CEO is scheduled to be on Decoder soon and we will see if they back out!

www.theverge.com/ai-artificia...

06.03.2026 21:22 πŸ‘ 1443 πŸ” 283 πŸ’¬ 37 πŸ“Œ 39
Preview
Data Visualization A Practical Introduction

Here’s a full draft of the upcoming second edition of my β€œData Visualization: A Practical Introduction”: socviz.co

05.03.2026 22:54 πŸ‘ 508 πŸ” 163 πŸ’¬ 12 πŸ“Œ 15

I think it's really important to recognize that World War I wasn't a decision that was made to go to war; it was a bunch of small decisions being made at a variety of levels, for a variety of reasons, that quickly got out of control and ultimately resulted in tens of millions of deaths.

05.03.2026 18:16 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Gonna pick a fight with umpty-zillion people who are hopped up on caffeine and sugar and like it that way

04.03.2026 17:13 πŸ‘ 132 πŸ” 17 πŸ’¬ 14 πŸ“Œ 2

I appreciate the flag, and "A joke that you have to explain..."

04.03.2026 19:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

yeah, when I notice, i open chrome but ... eh.

04.03.2026 19:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Hah! You're right.

04.03.2026 18:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Shostack + Friends Blog > Appsec roundup - Feb 2026 This month's roundup starts with losing oneself, continues with cool new threat modeling tools and applications, and continues into appsec, AI and regulation.

Just published the Feb 2026 Secure By Design AppSec Roundup β€” smart threat modeling tools like Flowstrider, a push for secure coding policy, OAuth/API key issues, emerging AI risks including agent auth & RCE findings, plus S+A news (new COO & first GPS threat advisory). is.gd/jAgBcg

03.03.2026 23:48 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

hypebeast.com/2026/3/anton...

03.03.2026 19:57 πŸ‘ 74 πŸ” 14 πŸ’¬ 4 πŸ“Œ 4
03.03.2026 17:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

There will be a huge fight over whether copyright vests in works generated by a few humans using AI tools. That will determine whether it is economically viable for large creative industries to replace lots of human creators while still being able to window and monetize the content the AI spits out.

02.03.2026 20:51 πŸ‘ 9 πŸ” 2 πŸ’¬ 2 πŸ“Œ 1
Farewell, Felix Β· The Recurity Lablog

"Farewell, Felix" - a blog post by Nico Lindner and Recurity Labs on the passing of Felix "FX" Lindner. RIP FX :(

blog.recurity-labs.com/2026-03-02/F...

02.03.2026 17:25 πŸ‘ 10 πŸ” 5 πŸ’¬ 0 πŸ“Œ 3
Post image

RIP FX - You are a legend

02.03.2026 05:03 πŸ‘ 56 πŸ” 25 πŸ’¬ 6 πŸ“Œ 2

It was hard for me to be chatting since we had a few folks watching from bsides, and the chat window was very small. I'm glad to be able to see it now.

02.03.2026 01:36 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is really beautiful, wow. What they did with our chat...

youtu.be/uK41l_c2A_Q

02.03.2026 01:28 πŸ‘ 16 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Jason Snitker - "Parmaster" Memorial Service - Feb 28, 2026
Jason Snitker - "Parmaster" Memorial Service - Feb 28, 2026 YouTube video by Deb Kavaler Wysopal

πŸ•―οΈ Par’s Memorial πŸ•―οΈ
Link below.

Please watch the CHAT video in the description.

Rest in peace, Jason Snitker
Legend. Always.

youtu.be/0qMRIZWCrJw?...

02.03.2026 00:55 πŸ‘ 13 πŸ” 12 πŸ’¬ 2 πŸ“Œ 3

bluesky clippy: hey there! you seem to be mad at something but not the person you’re yelling at. would you like some help self-regulating?

28.02.2026 23:24 πŸ‘ 2379 πŸ” 331 πŸ’¬ 24 πŸ“Œ 7

Japan seems like a counter example to the restoration of democracy theme?

01.03.2026 00:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

The judges in WV have seen enough.

They say that if the ICE continues detaining people in ways they have unanimously deemed illegal they will start issuing civil fines and contempt findings β€” including against state officials who help them carry it out.

storage.courtlistener.com/recap/gov.us...

28.02.2026 13:58 πŸ‘ 9700 πŸ” 2790 πŸ’¬ 304 πŸ“Œ 218

So mass surveillance is ok as long as it doesn’t β€œtarget” Americans?

28.02.2026 03:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Good morning BSides SEA. I’ll be presenting at 3pm on A New Hope for layering defenses. Come for the Star Wars references, stay for the collaboration.

27.02.2026 19:00 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

It’s not fraud because they wrote the words β€œrisks include: we might be defrauding some investors” on page 1,372 of the prospectus.

27.02.2026 05:07 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Venture capital, baby

27.02.2026 05:03 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Has Jack Dorsey ever run a profitable company?

That seems sort of relevant in evaluating his claim that AI changes everything.

27.02.2026 04:37 πŸ‘ 1 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

ICYMI: The DEF CON 33 Hackers' Almanack is out now.

Hackers have made it clear what policymakers should know and quickly act upon.

It's time to start listening to what the experts have to say⬇️
harris.uchicago.edu/sites/defaul...

#CyberCivilDefense #Take9 #HackersAlmanack

25.02.2026 16:20 πŸ‘ 7 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
How to turn off AI features in Firefox, or choose the ones you want | The Mozilla Blog Other browsers force AI features on users. Firefox gives you a choice.Β  In the latest desktop version of Firefox, you’ll find an AI controls section

AI controls are now live in Firefox 148. A single place to manage, customize, or completely block AI features in the browser.

See how it works here ⬇️ blog.mozilla.org/en/firefox/h...

24.02.2026 18:16 πŸ‘ 173 πŸ” 58 πŸ’¬ 19 πŸ“Œ 21