's Avatar

@icesurfer

Infosec Swiss Army Knife. Tec diver. Occasional (but published) travel photographer. Opinions are all mine and usually wrong.

111
Followers
185
Following
611
Posts
23.05.2023
Joined
Posts Following

Latest posts by @icesurfer

Post image

AuthN/Z is always a #security minefield & MCP adds even more complexity with agents, remote servers, and transitive trust.

This Teleport-sponsored deep dive breaks down attack vectors & why each authN/Z step is a potential trust boundary.

πŸ”— blog.doyensec.com/2026/03/05/m...

#doyensec #appsec #ai

06.03.2026 14:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Brilliant planning and flawless execution are the hallmarks of the Trump regime.

06.03.2026 11:44 πŸ‘ 486 πŸ” 178 πŸ’¬ 19 πŸ“Œ 9

holy fuckin shit lmao

a supply chain attack perpetrated by a prompt injection in a github ISSUE TITLE

eh. coding agents? what could go wrong

06.03.2026 05:11 πŸ‘ 380 πŸ” 97 πŸ’¬ 12 πŸ“Œ 1
Post image Post image

5 March 1945 | Shlomo Dragon, former Sonderkommando prisoner, recovered the manuscript of ZaΕ‚men Gradowski near the ruins of gas chamber & crematorium III at Auschwitz II-Birkenau.

This unique account is published based on a new translation: E-book: https://bit.ly/4ucs9WP

05.03.2026 11:00 πŸ‘ 255 πŸ” 78 πŸ’¬ 2 πŸ“Œ 0
Post image

If anyone is friends with any Georgian air traffic controllers, buy them a nice bottle of wine. As guardians of pretty much the only narrow gap still available between Europe and Asia that avoids both Iran, the Gulf, Ukraine and Russia, they are under some substantial pressure.

03.03.2026 14:26 πŸ‘ 3960 πŸ” 1279 πŸ’¬ 71 πŸ“Œ 131

Is that plane headed to the Middle East? No? You could have made far worse choices.

03.03.2026 16:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I'm constantly trying (/failing) to get this point across.

If you're a trained expert in a field, then it may be worthwhile to question the scientific consensus of your peers.

If you're not, the scientific consensus is absolutely the best you can do and it's arbitrary foolishness to disregard it.

24.02.2026 16:04 πŸ‘ 3759 πŸ” 853 πŸ’¬ 54 πŸ“Œ 50

Raytheon Executive: I know you’re skeptical about buying American again. But hear me out. The MIM-104 Patriot is the only surface to air missile system with a proven track record of success against the US Air Force.

Danish Defense Minister: Continue.

02.03.2026 14:43 πŸ‘ 5847 πŸ” 1296 πŸ’¬ 53 πŸ“Œ 39

deconflicting airspace is woke DEI.

02.03.2026 13:42 πŸ‘ 128 πŸ” 22 πŸ’¬ 3 πŸ“Œ 0

Even orcs are more civilised than those GOP bigots.

27.02.2026 00:42 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

DRINK WATER FROM THE SKULLS OF YOUR ENEMIES! IF YOU HAVE CRUSHED THEIR SKULLS, USE A GLASS.

23.02.2026 21:30 πŸ‘ 74 πŸ” 17 πŸ’¬ 0 πŸ“Œ 1

This is seriously profound.

20.02.2026 17:20 πŸ‘ 14 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

*very* striking to me that trump's two big losses at SCOUTS--first the fed, now tariffs--are both about core macroeconomic institutions, namely free trade and an independent central bank. "go nuts on culture, go nuts on immigration, but DO NOT TOUCH the neoliberal consensus"

20.02.2026 17:19 πŸ‘ 1924 πŸ” 366 πŸ’¬ 39 πŸ“Œ 36

My friends, if Amazon, with all its governance and change control, is getting these kinds of outcomes, (respectfully) you have no chance.

20.02.2026 08:52 πŸ‘ 59 πŸ” 17 πŸ’¬ 2 πŸ“Œ 1

Social media is terrible... except when it isn't πŸ™‚

19.02.2026 13:25 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Dude, sending you lots of hugs. And I fully agree that timely healthcare is a basic human right. Get better soon.

19.02.2026 11:13 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Aka: the ultimate test to ascertain if any computing platform is worth the copper it's made of

16.02.2026 19:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

"Bandits now at 50 miles and closing in. Our Gentoo F-35s will be ready for takeoff as soon as libc has finished compiling"

16.02.2026 18:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

"Well, my dear Sir, I'll see your iPhone 17 and I'll raise you a fighter jet..."

16.02.2026 18:22 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

That said, there is some very interesting research going on. For instance:
arxiv.org/pdf/2503.10566

16.02.2026 17:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

"They want us to fight a cultural/race war because they are terrified of a class war"

16.02.2026 15:57 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

1990s: you can inject code into data, but you need to learn assembly plus stack/heap management
2000s: you can inject code into data, and you only need to learn some Javascript
The future: can you read and write? Excellent, you're good to go.

16.02.2026 11:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The previous skeet is brought to you by the latest hilarious examples of prompt injection in agentic AIs.

16.02.2026 11:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The year is 2893 and infosec professionals have gathered yet again for the largest event in the industry: KuiperCon.
Humans and humanoid AIs crowd the main hall, and greet the panelists with thunderous applause. The topic today is "Separating instructions from data. A solution is finally in sight?"

16.02.2026 11:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 1

I think it is pretty much universally accepted that there is no such thing as too many screens :)

12.02.2026 14:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

Absolutely unreal: I found a fifth bug in libcrux, this time in its PSQ implementation that would allow a denial of service via a malcrafted AES-GCM ciphertext.

I couldn't submit my PR: Cryspen blocked me after I submitted my first four PRs, which included a fix for a critical nonce reuse bug.

08.02.2026 11:14 πŸ‘ 9 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0
07.02.2026 10:45 πŸ‘ 16673 πŸ” 4678 πŸ’¬ 130 πŸ“Œ 154

Get the hell out of Twitter. You'll only benefit from it.

06.02.2026 15:29 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Original post on defcon.social

Looks like someone built a tool to check your LinkedIn network for names from the Epstein documents. Soon I expect other tools will follow to work with other social media platforms. This is what the beginning of what community accountability looks like. Just because the legal system is captured […]

05.02.2026 11:38 πŸ‘ 28 πŸ” 14 πŸ’¬ 0 πŸ“Œ 1
Economics of Orbital vs Terrestrial Data Centers

Interested in a rational discussion about the economics of orbital datacenters? Make some hypotheses (e.g.: launch cost, sunlight fraction, GPU degradation, etc.) and compare orbital vs terrestrial.

Code is public. Amazing work. Kudos.

andrewmccalip.com/space-datace...

03.02.2026 13:21 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0