Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Steve Bellovin

@SteveBellovin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

I'm an affiliate scholar at Georgetown's Institute for Technology Law and Policy, and a computer science professor emeritus and former affiliate law prof at Columbia University. Author of "Thinking Security". Dinosaur photographer. Not ashamed to say that I’m still masking, because long Covid terrifies me.

4523 Followers
284 Following
50 Posts
Joined November 16, 2024
Home Page:
https://www.cs.columbia.edu/~smb/
Pronouns:
He/Him
Photography-only account:
@urbandinosaurs@urbanists.social
License:
All of my photos available via a Creative Commons BY-NC license: http://creativecommons.org/licenses/by-nc/4.0/
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2w ago
Replying to
@mattblaze@federate.social @ProPublica@newsie.social That was the scandal that prompted Bob Morris the Elder to note that “I always realized that politicians were bribable, but I didn’t realize I could afford one—and if a Senator costs $50,000, what does the janitor who mops the floors in the [server] room cost?”
7
1
3
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1w ago
“In the Private Jet Age, the Quiet Allure of Private Rail”: https://www.nytimes.com/2026/09/23/travel/amtrak-private-train-cars.html?unlocked_article_code=1.DVE.LNIL.VawLfRzUykVD&smid=url-share (gift link)
nytimes.com
4
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1w ago
Is there *any* way to keep my iToys from backing up automatically to iCloud? My older iPad and now my new iPhone insist on doing that by default, even though iCloud backup is off in Settings on the devices.
2
0
2
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2w ago
Timeline cleanse: "Scientists heard a knock at the door. It was a pelican in need of help." https://wapo.st/4roaN8r (gift link)
wapo.st
3
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@briankrebs@infosec.exchange I'm old enough to remember when the Right was claiming that FEMA was planning on rounding people up. It's always projection…
32
5
4
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@wendynather@infosec.exchange I've never tried quite that. I have worked on securing what AT&T called "operational support systems" (OSS), the many computers that tend and feed the phone switches, plus the so-called "adjunct processors" that help the actual switches. Let me put it like this: it's a nightmare. None of these systems were built for today's environment, and they can't easily be upgraded. And if you tried to reimplement them, you'd definitely introduce far more bugs, including security bugs, than you removed. OSSes do things like associating a physical wire or fiber with a "trunk" to another switch. How many OSSes do you think AT&T has? Your guess is almost certainly too low. And adjunct processors? Suppose you dial an 800 (internationally a "free phone") number. That has to get translated to an actual phone number, and appropriate billing stuff handled. That is *not* done by the switch; rather, the switch does (in effect) an RPC call to the adjunct processor, which does the hard stuff (including the database lookup) and returns the answer to the switch. One last thought: back in the 1990s, I used to say that the Internet was becoming the data equivalent of the phone network. I no longer say "is becoming"—it is. Build your phone network lately, including what is known as "outside plant", i.e., the wires on poles or in conduits? Build your own high-capacity, production-ready switch? No, phone switching is not done today the way it was done when I joined AT&T in 1982, but apart from the fact that a lot of the complexity is inherent to the problem, you still have to interoperate with legacy gear, unless you're also building your own handsets, etc. (During a meeting in, I think, 1996, on how to do a completely "greenfield" design for a new phone switch, I completely blew a Bellhead's mind by suggesting that 800 numbers be implemented as a distributed database and cryptographically signed reverse-charge tokens…)
26
8
6
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2w ago
Trump wants to name things for himself because he knows damned well that no one else is going to name any monuments for him (except maybe a cell somewhere…)
2
1
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
RE: https://flipboard.com/@newyorktimes/home-page-91uottdbz/-/a--1AFgpJbRrygQyybRU2ysA%3Aa%3A3195393-%2F0 Are any *technical* details on this available?
flipboard.com
14
17
14
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@nixCraft@mastodon.social @cstross@wandering.shop The first version of Netnews (https://www.cs.columbia.edu/~smb/papers/netnews-hist.pdf) was a 150 line Bourne shell script, but had multiple newsgroups and cross-posting…
cs.columbia.edu
14
2
7
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2w ago
Replying to
@cstross@wandering.shop @Menhit@mstdn.strafpla.net She's bilingual, but speaks canine with an accent.
1
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@briankrebs@infosec.exchange Sounds bad, though perhaps not as bad as the time one flew into my mouth while I was bicycling and stung my tongue…
9
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@mikeloukides@hachyderm.io @briankrebs@infosec.exchange Yup. After calling my doctor—my tongue was starting to swell up—it was off to the local urgent care center for injections of a steroid, to reduce the inflammation, and an antihistamine, to deal with the allergic reaction. The latter put me right to sleep…
4
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@cryptomancer I follow @CryptoOrrDun@ioc.exchange here… That LLMs should find bugs in crypto libraries is utterly unsurprising at this point. But these results are about the algorithms, which is much more interesting.
3
9
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@jtk@infosec.exchange Alas, no. I looked for it a fair number of years ago but it was long gone. I remember how it worked and could probably reconstruct it, but it was a) too slow to be usable for production, and b) not secure, even by the standards of 1979, since it couldn't be setuid. It was a prototype to let us rapidly experiment with the protocol design, since back then on my department's PDP 11/45, compiling even a small program too a long time. I rewrote it in C (also long gone), once the protocol was set, but it was missing a few essential features, too. The first release version was a completely new version by Steve Daniel. The basic idea was that the set of newsgroups you subscribed to was a shell environment variable which could include shell meta characters, most notably * if you wanted to read everything. 'Find -newer' found articles newer than a 0-length dot file; 'ls -i | sort | uniq' was used to show cross-posted articles only once. But yes, I wish I still had it!
3
0
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@20002ist@thepit.social @joebeone@techpolicy.social There was a very energetic effort sponsored by the Biden White House on software liability, examining all sorts of issue surrounding it. For "some reason", that effort vanished about 1.5 years ago…
2
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange What concerns me is a Kobayashi Maru sort of scenario, where instead of finding a crack in an algorithm the LLM hacks the researchers' accounts and steals the file with the secret key or the plaintext, all unknown to the researchers.
2
4
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@20002ist@thepit.social Think of it as an improvement to the NY Times.
2
3
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@fgbjr@indieweb.social Plus farting in their general direction, of course.
1
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange Ross and others.
1
0
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@agreeable_landfall@mastodon.social @cryptomancer @CryptoOrrDun@ioc.exchange In a production system, probably—but in a research setting where you're challenging an LLM to break the cryptosystem? I doubt it. Besides, HSMs are often not as secure as they should be, per research done at Cambridge University.
1
2
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@Teri_Kanefield@mastodon.social Interesting thread, since I'm currently mulling if I should find an agent for a book I'm working on…
1
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@mattblaze@federate.social @20002ist@thepit.social You get to read that one… (I did notice that I had quoted the 1950 version.)
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to
@lauren@mastodon.laurenweinstein.org Fake meows.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@thefunnypages@mastodon.social @jack_daniel@mastodon.social I feel seen.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@adamshostack@infosec.exchange @briankrebs@infosec.exchange @hal_pomeranz@infosec.exchange Interesting. I don't think the swelling was any worse than the other times I've been stung, but it doesn't take a lot of tongue swelling to threaten one's airway.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@karlauerbach@sfba.social @mattblaze@federate.social I've only testified once, and my mother got very upset when she heard I was going to—her model for people testifying before a Congressional committee was HUAC or McCarthy's committee, where people were compelled to testify and either abase themselves, incriminate themselves, or take the Fifth. I had to reassure her that this was not that sort of committee, and that testifying was an honor.
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@20002ist@thepit.social @joebeone@techpolicy.social Or look on https://bidenwhitehouse.archives.gov
bidenwhitehouse.archives.gov
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@agreenberg/117011022100893459 I've been expecting this. The US attacks Iranian water systems; Iran attacks US systems.
infosec.exchange
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to on federate.social
@mattblaze@federate.social A classic case. See https://www.newscientist.com/article/1818118-technology-sorry-no-numbers-the-day-the-uss-telephone-network-crashed/ and https://catless.ncl.ac.uk/Risks/9.63.html#subj3.1 — and https://catless.ncl.ac.uk/Risks/9.69#subj5 for the precise bug: misuse of a a 'break' statement. The salient points: it was a flaw in error recovery code, which was triggered if and only if while a phone switch was rebooting, it received two incoming call requests within 1/100 second. In the aftermath, AT&T started classes in the proper use of 'break' statements…
newscientist.com
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to on threads.net
@jswatz_tx Also grifting.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@sundogplanets@mastodon.social If you want, you're more than welcome to use this very amateur photo as an example. I took it in Death Valley (a dark sky area) in mid-January of this year, and it shows *6* satellite tracks. (50mm, f/1.8, ISO 2800, 3 seconds, slightly enhanced to show all 6 tracks). I hate to think what a longer exposure would show!
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@karlauerbach@sfba.social Well, a tale told on behalf of an idiot…
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Trains, of course, have restrooms. (I believe that this work train is on a track for the Purple Line, a light rail line under construction in the Maryland suburbs of DC.)
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@karlauerbach@sfba.social The new document is immunity for past transgressions for only Trump and a few others. But critics say that it isn't legally binding: https://www.nytimes.com/2026/08/03/us/politics/todd-blanche-trump-irs-fund-loopholes.html?smid=url-share&smid=nytcore-ios-share&rsrc=cl-share
nytimes.com
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1w ago
Replying to
@fivetonsflax@tilde.zone Not even a sealed boxcar?
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@mattblaze@federate.social @karlauerbach@sfba.social Only my own, as best I recall.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@olaf@social.secret-wg.org @aka_pugs@mastodon.social And a rotary dial phone at that…
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to
@elizabethjacobs.bsky.social @20002ist@thepit.social Last week, I believe it was Rosie O'Donnell who referred to him as the Secretary of Health and Human Sacrifice.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to on mastodon.laurenweinstein.org
@lauren@mastodon.laurenweinstein.org @darkuncle@infosec.exchange As my partner often points out, I have the benefit of a liberal education (though you likely consider me sadly deficient in my knowledge of movies…).
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to
@dan@mastodon.durrans.com @cigitalgem@sigmoid.social I figure they got suspicious of people coming from LAS wearing hoodies…
0
2
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@darkuncle@infosec.exchange @mattblaze@federate.social And we lost Peter Neumann just a few weeks ago…
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to
@VeroniqueB99@mastodon.social I hope this isn’t AI slop…
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@paris@hachyderm.io @thedarktangent@defcon.social @eff@mastodon.social This is not new—I first heard of it ~25 years ago. Drivers' license scanners were originally created to help catch fake IDs; the benefits to bars, given liability issues, ar obvious. But some brands *marketed* themselves with their ability to capture other data, to help create a customer database for targeted ads, etc. See, e.g., p 59 of https://www.nationalacademies.org/publications/10656 (Disclaimer: I was on the committee that produced the report.)
nationalacademies.org
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to on elefanti.co
@adam@elefanti.co @20002ist@thepit.social I'm reminded of the refugee ship St. Louis (https://encyclopedia.ushmm.org/content/en/article/voyage-of-the-st-louis)
encyclopedia.ushmm.org
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 1mo ago
Replying to on mastodon.laurenweinstein.org
@lauren@mastodon.laurenweinstein.org Hence the patent…
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
RE: https://flipboard.com/@newyorktimes/new-york-bat3un55z/-/a-TfouDAImTVaqT-uRVBqrow%3Aa%3A3195393-%2F0 Cue the uncanny valley
flipboard.com
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@bontchev@infosec.exchange Yup, I boosted it this morning.
0
0
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@cryptomancer @CryptoOrrDun@ioc.exchange Yes, 7 rounds, and no, it doesn't scale even to 10 rounds, let alone 14. Attacking weakened versions of ciphers is a standard analytic technique—and sometimes a variant of the attack on a weakened version will scale up and sometimes it won't. (A fair number of years ago, there was a decent attack on a weakened version of Skipjack, an NSA-designed cipher. I showed that to someone I knew who had NSA contacts. His reply: "You call it worrisome; I call it good engineering." To my knowledge, no one has ever been able to scale it up to the full cipher.)
0
2
1
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
Replying to
@mattblaze@federate.social @20002ist@thepit.social "Do you advocate overthrowing the government of California by force or violence?" "Is that a multiple choice question?"
0
1
0
0
Open post
Steve Bellovin @SteveBellovin@infosec.exchange
· 2mo ago
RE: https://flipboard.com/@newyorktimes/world-5f2k3dqjz/-/a-pCnP_INfSNOk69c9sBFwbw%3Aa%3A3195393-%2F0 Look, @sundogplanets@mastodon.social
Open quoted post
Quoting
The New York Times
@newyorktimes@flipboard.com
A Ton of Space Junk Tumbles Unpredictably to Earth Every Week https://www.nytimes.com/2026/07/31/world/asia/space-debris-earth.html?utm_source=flipboard&utm_medium=activitypub Posted into World @world-newyorktimes
Open quoted post
flipboard.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:58:09 UTC