Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Dan Goodin

@dangoodin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.

0 Followers
1163 Following
50 Posts
Joined November 22, 2022
Site::
https://arstechnica.com/author/dan-goodin/
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
"A human who conducted such a hack would be facing years in prison. For a machine, criminal liability is harder to determine." https://www.newyorker.com/news/the-lede/inside-openai-hack-of-hugging-face
newyorker.com
68
15
46
9
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

If it wasn't already, 2FA spraying is now a thing

https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaults/

arstechnica.com
81
13
84
1
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
A quantum-resistant cryptography algorithm that was under consideration to become an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken. https://arstechnica.com/security/2026/07/mythos-uncovers-crypto-weaknesses-that-went-unknown-for-years/
arstechnica.com
20
8
24
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Mozilla has provided behind-the-scenes details on the 271 vulnerabilities it discovered with the help of Mythos. Those details include full Bugzilla reports on 12 of the vulnerabilities. I'd be curious for people to look at the reports and hear what they think. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
Behind the Scenes Hardening Firefox with Claude Mythos Preview – Mozilla Hacks - the Web developer blog
Mozilla Hacks – the Web developer blog

Behind the Scenes Hardening Firefox with Claude Mythos Preview – Mozilla Hacks - the Web developer blog

New details about what we found, and how agentic harnesses are now able to reproduce real bugs and dismiss false positives.

79
7
78
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
TV sticks that offer free streaming services are turning people's tnternet connections into vehicles for fraud. https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
krebsonsecurity.com

Read This Before You Buy That TV Streaming Stick – Krebs on Security

15
0
10
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago

With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo@abyssdomain.expert wants to make one thing perfectly clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world

https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-world/

arstechnica.com
59
2
55
1
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

Are MP3 players even a thing these days? What are some good brands/models?

32
70
37
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults.

https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343

What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacker to meaningfully exhaust key space before it resets all over -- unless the attacker has the ability to pump all 7,700 combinations in <90 seconds, and DL doesn't have any sort of rate limiting.

Also, if the attacker is brute forcing 2fa, doesn't that by necessity mean the attacker already defeated the first factor? How did that occur?

I don't know if my confusion is the result of me not knowing the how the Dashlane product works or if it's just Dashlane being opaque.

Can anyone help me read the tea leaves?

support.dashlane.com
24
9
16
1
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

You too can turn a Bluetooth device into a PC-pwning proxy

https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/

arstechnica.com
23
1
22
1
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago

Google is dramatically shortening its deadline readiness for the arrival of Q Day, the point at which existing quantum computers can break public-key cryptography algorithms that secure decades’ worth of secrets belonging to militaries, banks, governments, and nearly every individual on earth.

https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/

arstechnica.com
33
15
43
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago

Does anybody with a STRONG BACKGROUND IN WEBSITE PRIVACY have time to vet this research? Are TikTok and Meta pixels REALLY doing the things claimed? I'm concerned it may be overstating things in an attempt to sell its tag monitoring tools.

https://jscrambler.com/blog/beyond-analytics-tiktok-meta-ad-pixels

jscrambler.com
29
19
31
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago

There's a ton of skepticism over the true value of AI-assisted vulnerability discovery, and with good reason. Maybe the new details Mozilla has revealed don't tip the scales in favor of it being beneficial, but people should at least sift through them in good faith and with an open mind before declaring all of them bullshit.

https://arstechnica.com/information-technology/2026/05/mozilla-says-271-vulnerabilities-found-by-mythos-have-almost-no-false-positives/

arstechnica.com
17
7
14
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago

Dear readers. If you're not willing to support the families of those you want to read then we regretfully will be preventing you from obtaining our work for free.

@StefanThinks@beige.party@infosec.exchange

@StefanThinks@beige.party@infosec.exchange

infosec.exchange

Infosec Exchange

26
28
14
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past?

https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/

itsfoss.com
12
6
8
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

Can’t make sense of Dashlane’s vault theft notification? You’re not alone.

https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/

arstechnica.com
9
1
4
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago

I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff@mastodon.social . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.

17
0
3
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago
Replying to
For context, please see: https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/
arstechnica.com
17
0
7
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago

If I hear one more person say that Beyonce isn't a real country singer/song writer and should stay in her own RnB/hip-hop lane I'm going to lose it.

17
3
3
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Have any distributors/vendors released versions that fix CopyFail? If so, can someone help me compile with distributors and versions?
8
14
7
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago

Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.”

https://arstechnica.com/security/2026/04/while-some-big-tech-players-accelerate-pqc-readiness-others-stay-the-course/

arstechnica.com
9
2
8
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago

I'm trying to understand a bit more about CVE-2026-33579, the critical vulnerability in OpenClaw. To exploit, an attacker needs low-level paring privilege permissions. How does one acquire such privileges? Can anyone do it? I'm asking because I want to understand what's required for an attacker to exploit.

Feel free to ping me at DanArs.82, or drop an answer here.

10
8
7
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago

Can someone explain @filippo@abyssdomain.expert's post to me like I'm a 5-year-old?

https://words.filippo.io/128-bits/

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
words.filippo.io

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.

8
9
7
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago

If you could ask any question to Mozilla concerning last month's The Zero-days are Numbered post, what would it be?

https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/

blog.mozilla.org
6
4
5
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@paco I just asked Mozilla about this. Someone responded that internally found bugs like the 271 go into “roll-up” advisories with, each rollup providing a link to the bug list covered. The 3 rollups are: https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6784 https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6785 https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6786 When you look at these rollups they say that "Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code." With no way of knowing how many vulnerabilities were truly severe and exploitable, I think Mozilla, like others gushing ab out LLM-assisted vuln finding, is denying us the data to assess the true value of Mythos.
Security Vulnerabilities fixed in Firefox 150
Mozilla

Security Vulnerabilities fixed in Firefox 150

7
2
1
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

Anybody know of any Linux distributions that have released fixes for Dirty Frag?

5
14
8
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@Viss@mastodon.social So, nobody is even going to take a look?
5
3
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
Replying to
@DiogoConstantino@masto.pt OK, I'm done with this thread.
1
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
Replying to
@drs1969@mstdn.social Is this your opinion on how the law should work, or do you know the law already makes this distinction clear?
1
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange @drs1969@mstdn.social @glyph@mastodon.social I think you're all misreading the 2 sentences I quoted. I think the writer is, correctly, saying that this issue is novel and the law has yet to establish that such events are crimes, and that anyone charged would surely make this argument in trial. Contrary to your readings, the author isn't saying this is how things should be. Now everyone is jumping on me for a single quote. It's fine for people to say the law shouldn't give AI-generated crimes a free pass, but non-lawyers arguing how the law currently treats such events is a real drag. I've stayed off Mastodon for a while, because this behavior is all too common. I'm inclined to remain off the platform.
1
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 2mo ago
Replying to
@adamshostack@infosec.exchange I have the same info that everyone else does.
1
2
1
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago

Can anyone help me find my AirTag attached keys? The FindMy app shows me their general location, which is a large public building where I last had them. When I go on site, my app is mostly unable to see them at all. Occasionally my app seems to be able to see a very weak signal but I can't seem to zero in on it. This is driving me nuts. I've looking now for two weeks. Anybody got tips?

3
8
5
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@ekari@mementomori.social That's a consideration I regret not thinking of during the interview. (I've sent an email seeing if I can get it answered now.) That said, if deep-pocketed threat actors pay whatever the cost is and get a ton of useful results, it seems like devs will have to incur the same cost if their users are to stay safe.
3
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@mttaggart Agreed. Most sites far prefer subscriptions over serving ads.
5
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago
Replying to
@dubbel Yes, you're right, of course. Rotating creds at an atomic level would be quite a thing, no?
4
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 4mo ago
Replying to
@cR0w@infosec.exchange If I could just have a Nano iPod I'd have everything I need. Yes, definitely offline music playing. No streaming, just play old fashioned mp3s. I'm not seeing anything carried by Best Buy et al.
2
4
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@siliconshecky Thanks a million! So when Tenable says SUSE et al. are "patching" and Debian et al. are "not patched," what's the difference? Are there downloads for the former or just mitigation guidance?
2
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@Niklas yes, agreed. I run into this predicament multiple times per day. Interesting that micro payments has been one of the Internet's longest running unsolved problems.
2
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@notyourfanboy The statement is racist AF. No one ever says that about white country performers.
2
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@bytex64 Well, sometimes people are searching for the right word substitution, which can be hard and still convey the concept correctly. The same problem explains why we anthropomorphized computers and OSes in the first place. Still, I get what you and @Thad are saying.
2
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@WPalant@infosec.exchange @paco@infosec.exchange @zbrown@floss.social Thanks so much for looking. I'm a big proponent of skepticism, but not when it's an excuse for not keeping an open mind.
1
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago
Replying to
@esoteric_programmer Do you have a link? Quantum computing doesn't break hash algorithms, although I think it may help create collisions. Maybe @sophieschmieg knows.
1
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago
Replying to
@paulehoffman Their estimate from last June of 1 million noisy qubits? That's the most recent estimate.
1
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@passocacornio@tech.lgbt @michaelh@fosstodon.org OK, assuming that's true, what's the quality of them?
0
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@michaelh@fosstodon.org @passocacornio@tech.lgbt Yes, that's true. What I want to know is, what's the quality of the 12?
0
0
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@BalooUriza fair enough. Sounds like you and legitimate publishers trying to support workers families are at a impasse. still it's a decision people like the OP choose to make and hence blaming them on social media is waste of energy.
0
2
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 6mo ago
Replying to
@esoteric_programmer Well, for starters, did you read the Google research from last June? It's linked in the article.
0
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 7mo ago
Replying to
@kboyd yep. exactly. another person replying said "Beyonce is not real country" and used the hashtag #shesnotreal Unless there's some joke or irony i'm missing that's racist AF.
0
2
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@keithzg@fediverse.keithzg.ca So why should anyone listen to your take if you're NOT going in with an open mind?
0
1
0
0
Open post
Dan Goodin @dangoodin@infosec.exchange
· 5mo ago
Replying to
@Epic_Null@infosec.exchange Maybe, but if there is true advantage, threat actors will no doubt use them. That, in turn, will put developers who don't at a disadvantage. That's why I think it's important we keep an open mind at this early stage.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:02:23 UTC