Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Dave Wilburn :donor:

@DaveMWilburn@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#infosec engineer, #mlsec machine learning, sailor, news junkie, #threatintel consumer, deep statist, #NAFO fella. All opinions are mine.

1452 Followers
639 Following
50 Posts
Joined November 15, 2022
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@newsguyusa@flipboard.social I'm so goddamn tired. Just require basic audit trails with reasonable retention periods along with strict liability for the actions of AI/agent systems.
10
1
4
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 3w ago
Replying to
@Free_Press@mstdn.social I'd encourage some restraint in reporting on this incident. As others have noted, this is much more likely to have been carried out by domestic extremists than Russian operatives, and is unlikely to have any direct nexus with the Russia-Ukraine War. The possible caveat to that is the tendency of Russia to encourage various extremist groups in rival democracies through clandestine resources and propaganda, but thus far there's no evidence that I'm aware of any direct involvement by any Russian actors at this point.
7
1
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1w ago
Replying to
@reverseics@infosec.exchange Still a good bun.
2
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@wendynather@infosec.exchange @newsguyusa@flipboard.social I think the only caveat there is that it wouldn't have much use for that purpose given that it isn't an obvious place for protestors to gather. I suppose it would be tactically useful for controlling access to the Memorial Bridge, but there are so many other approaches to the city. Other than taking pot shots at Arlington National Cemetery mourners or GW Parkway commuters or paddlers along the river, I don't know what he'd be able to do here that he couldn't do better from literally anywhere else in the National Capital Region. The man is just so utterly incompetent, even at being a bog standard corrupt dictator. This is so insulting. I demand a better class of villain.
3
4
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1w ago
Replying to
@cR0w@infosec.exchange JFC
1
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
RE: https://masto.ai/@meduza_en/117300190369970991 Nope, they won't tolerate Russian threats, only Russian bribes.
Open quoted post
Quoting
Meduza in English
@meduza_en@masto.ai
Marine Le Pen and Jordan Bardella, leaders of France’s far right, say no Russian threats or covert operations can push France to help Moscow achieve its war aims in Ukraine. https://meduza.io/en/news/2026/09/20/french-far-right-leaders-marine-le-pen-and-jordan-bardella-say-they-will-not-tolerate-russia-trying-to-dictate-france-s-policies-through-threats-and-intimidation
Open quoted post
masto.ai

Meduza in English: "Marine Le Pen and Jordan Bardella, leaders of Fra…" - Mastodon

2
0
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1w ago
Replying to
@Nonya_Bidniss@infosec.exchange Oh man... Can you imagine fucking up so badly that we'll have lost both a war with Iran and also in short order a war with fucking Cuba? How in the name of God would we prosecute such a war? With what goddamn hardware, given we've already expended most of our munitions and trashed a couple of aircraft carriers?
1
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
All of Virginia is under a drought warning, and residents are being urged to conserve water. "The utility says the guidance only applies to non-essential residential usage, not businesses or industries." So I assume this means Virginia datacenters are free to continue to waste drinking water, got it. https://www.alxnow.com/2026/07/28/alexandrias-drinking-water-utility-calls-for-voluntary-water-conservation-amid-drought/
Alexandria’s drinking water utility calls for voluntary water conservation amid drought | ALXnow
ALXnow | Alexandria, Va. breaking news, local events and community happenings

Alexandria’s drinking water utility calls for voluntary water conservation amid drought | ALXnow

Drought conditions in Alexandria and other parts of Virginia have prompted the city's drinking water utility to ask customers to voluntarily conserve water. Virginia American Water issued the notice to residential customers amid the Virginia Department of Environmental Quality's recent drought warning advisories. The utility says the guidance only applies to non-essential residential usage, not

18
0
13
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@nyanbinary@infosec.exchange Usually restricted to situations that require brevity (e.g., titles and headlines), and especially for trademarks.
1
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@lcamtuf@infosec.exchange The important thing here is that Google makes ad renevue selling information parasitically harvested from your website. Please clap.
15
4
4
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@CDubbs@infosec.exchange It won't happen because they can't prove criminal intent. The humans were merely negligent, but negligence isn't the standard under the CFAA and Congress has intentionally protected the tech industry from any criminal or civil liability for decades. And the AI agents lack intent because they lack the capacity for it. We need Congress and other government jurisdictions to impose criminal and civil liability for negligence on the builders, hosters, and operators of autonomous agents.
1
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@rickf@indieweb.social @wendynather@infosec.exchange @newsguyusa@flipboard.social Well, except the military historically hasn't done such a great job of defending DC against invasion by Canada. But it's fine because only a complete idiot would antagonize the Canadians, am I right? Guys? Am I right?
1
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@Nonya_Bidniss@infosec.exchange My nephew missed some paperwork (or perhaps more correctly, his school missed submitting their paperwork) in his application to the USAF Academy when he was applying to all the service academies and senior military colleges. I was not sad.
1
4
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@gvwilson@mastodon.social IMO its usefulness is still at least a little bit up in the air. There are too many legitimate concerns about user skill degradation, hallucinations, and business ROI at full unsubsidized token cost to confidently say it is useful. Perhaps its usefulness will be more firmly proven in the future as models improve, tool sets and processes around them improve, and the alleged usefulness is better studied. Or maybe not. In the meantime, while the uses are at best unproven, anecdotal, and speculative, the ethical problems and societal harms are much more firmly established.
6
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@dangoodin@infosec.exchange @wdormann@infosec.exchange @drs1969@mstdn.social @glyph@mastodon.social Unpopular opinion: Dan is right about all of his points, and so is the article he linked. And he's right that y'all are unfairly shooting the messenger. Most crimes require establishing intent. GenAI models might have impulses that drive them based on their training and prompts, but it seems unlikely to me that one could reasonably call that intent. They might mimic humans in some ways, but that mimicry and activity probably isn't sufficient to meet the standards established in criminal law. Maybe there is some civil liability, but even that has been narrowed in recent years. IIRC, SCOTUS ruled that costs of internal investigations are not recoverable under Van Buren v. United States. This is a shit show.
3
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1mo ago
Replying to on infosec.exchange
@SecureOwl@infosec.exchange This screencap of a Facebook post is making the rounds, alleging that returning DEFCON attendees used a WiFi Pineapple to de-auth and spoof the in-flight Wi-Fi and harvest creds.
2
4
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
re: Chilly being grateful and sappy, AGAIN
@chillybot@infosec.exchange hugs!
2
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@lorimolson@mstdn.ca @lcamtuf@infosec.exchange Google will probably bet on the idea that they'll be the only game in town, and you either accept their rates and whatever pretend metrics they shovel your way or you just don't advertise online. In Google's dystopian future, partnering with other advertising networks or websites won't work anymore because they'll be irrelevant. Few will even interact with other websites because they'll get everything they need from Gemini, your plastic pal who's fun to be with.
2
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@gsuberland@chaos.social : *SCREAMING* Void: "Unable to decrypt message"
2
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@GossiTheDog@cyberplace.social What's especially amazing is that these consulting firms are playing footsie with the technology that's most likely to replace them.
2
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1mo ago
Replying to
@reverseics@infosec.exchange Me, looking at what's likely the third straight week of having races on the Potomac River scrubbed due to typical East Coast evening storm patterns: i wish summer was shorter. #sailing
1
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@cR0w@infosec.exchange @da_667@infosec.exchange @krypt3ia@infosec.exchange Eh, there's a lot of crippling physical injuries in the trades, along with substance abuse to self-medicate the pain away. I'm not sure I'd want to recommend a career field where you're physically unable to continue working the job a couple decades in. I don't think there are enough back office jobs for tradesmen to switch to.
1
4
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@thedarktangent@defcon.social How's the performance with that many radios? I've heard Meshtastic tends to break down around 100 nodes or so, but I've never been in a mesh with anywhere near that many active nodes. I assume something in the DEFCON firmware settings helps with some of that?
1
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to on mastodon.social
@Viss@mastodon.social Sure, why not? Most of their customers are only calling them after they tried and failed to use AI chatbots to fix their plumbing issues.
1
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@Ecmadtown@infosec.exchange I did IR and other direct SOC ops tasks and then pivoted towards detection engineering with an ML focus (predating LLMs) until the end of my career. I think that was the right choice for me, especially in terms of stress and predictability of my work schedule.
1
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@lorimolson@mstdn.ca @lcamtuf@infosec.exchange My educated guess is Google will shove the ads into their LLM responses and charge for the privilege.
1
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@Nonya_Bidniss@infosec.exchange He enjoys it, which is great. But it has honestly been such a royal PITA for his entire family. VMI seems to have adopted the same dismissive attitude towards the needs of parents as the US military does towards spouses. They just don't give a shit.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to on defcon.social
@subtetralectic@defcon.social @bruces@mastodon.social Thank you!
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@darwinwoodka@mastodon.social @bruces@mastodon.social As someone whose immediate family owns horses and is intimately familiar with their costs and drawbacks, outside of extremely rural areas, I find this difficult to believe.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
NYT: Trump Will End Subsidies for Medicare Drug Premiums Joke's on Trump, my mom already died after being denied hospital admission during his mismanaged COVID pandemic, so she doesn't need Medicare drugs anymore. https://www.nytimes.com/2026/07/28/business/medicare-drug-subsidies-part-d.html #medicare #uspol #healthcare
nytimes.com
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@hacks4pancakes@infosec.exchange I don't know what the ultimate answer is. Part of the challenge with water is that they're so fragmented into tiny municipal utilities. Some consolidation might get them economies of scale for better and more secure IT/OT. But consolidation of major utilities in other sectors (e.g., the rapidly metastizing Dominican Energy megacorp for electricity) comes with its own risks. And the resources challenge is also huge. There's huge political and regulatory pressure to keep rates low. Where would the money to build and maintain all of this extra tech come from? People that know how to build and secure networks are expensive, especially if you've got them working 24x7 or at least on-call. Who wants to pay higher rates so their water utilities can hire a bunch of nerds to stare at computers? What politician wants to stand on a podium and explain to the angry voters why their rates are going through the roof?
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@Viss@mastodon.social @jfslowik@infosec.exchange But don't worry, they'll still throw plenty of kids in prison or hound them to suicide for the same thing.
0
8
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@tek@freeradical.zone Weren't they targeted with Trump regime import bans recently? How did that work itself out?
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to on mastodon.social
@Viss@mastodon.social LLMs are already basically compression. Discussion in videos from 3blue1brown: https://youtu.be/l6DKRf-fAAM https://youtu.be/GlYgs6v2YfU As far as shrinking the models themselves, Google is investing a lot in this space. They really want to sell you Android phones that can do at least some of the GenAI processing on the device itself, rather than shoveling everything up to a bunch of expensive datacenters. Gemma 4 has a bunch of tweaks that are beyond my understanding to reduce the number of parameters that are loaded in RAM during operation. Of course, even this approach doesn't work well when there's a global RAM shortage impacting both datacenters and consumer devices. Acquiring even modest amounts of RAM is like buying unobtanium.

Reinventing Entropy | Compression is Intelligence Part 1

0
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 3w ago
Replying to
@cigitalgem@sigmoid.social CFAA criminal violations require establishing criminal intent beyond a reasonable doubt. But the model itself likely lacks the capability to possess intent, and the humans that built it and gave it its instructions didn't intend for any nonconsensual hacking to occur. As far as civil violations go, recent SCOTUS case law gutted the ability of victims to recoup investigative costs, which are probably the biggest costs they incurred here. US federal law governing tech doesn't currently impose criminal or civil liability for negligence, recklessness, or lack of supervision. That has been intentional, out of the theory that it would deter innovation. Congress needs to readdress that, and there's also probably room for states to step in. Hopefully other countries also have stronger laws. But in the meantime, we're kinda fucked.
0
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 1mo ago
Replying to
@newsguyusa@flipboard.social Weird that a bunch of scammers would take on false identities to convince their victims that they're legit, but then specifically choose the identities of a bunch of Trump-appointed scammers.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange It would be an incredibly difficult case to prosecute. You'd have to convince a jury that the decendants' actions meet all the elements of the crime, including poor configurations and vague prompts, none of which explicitly asked or even suggested the model hack into an outside entity's network. IMO we really need new laws that establish crimes based on recklessness, negligence, or failure to supervise autonomous agents.
0
3
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@nyanbinary@infosec.exchange @Viss@mastodon.social Yeah, although in theory it might just be when you explicitly ask the model to do something for you, so you've made an informed decision to take a hit to your battery for a few seconds. In practice, the OS makers cram it into every nook and cranny in an always-listening mode that you can't straightforwardly and globally disable, because fuck you that's why. But it doesn't have to be that way.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 3w ago
Replying to
@cigitalgem@sigmoid.social I agree that someone should be prosecuted, but I'm skeptical that currently worded US Federal law would support that. Hopefully other jurisdictions are in a better position to do something about this. Some of these incidents targeted victims in other countries (e.g., Germany).
0
0
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@TindrasGrove@infosec.exchange I suspect there are also unique challenges in constantly switching between war-mode inside the SCIF and then going home to "normal" suburban civilian life every day. I've heard of similar challenges for drone operators, often working from stateside military bases.
0
1
1
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to
@Nonya_Bidniss@infosec.exchange Well, yeah... although he's attending VMI instead, which has its own issues. In fairness, their leadership in recent years seems to have done an okay-ish job of addressing past historical problems of deep-seated racism in reasonably good faith. I disagree with some of their decisions in retaining some of their confederate memorials, although I accept some of them are nuanced (e.g., do you disinter cadets that died in battle and were subsequently buried on campus?). IMO, most of their current problems are less about any current discrimination and more about the rabid fanaticism of their racist alumni, along with the general stupidity of many of their on-campus traditions involving don't-call-it-hazing and the intentional abuse of underclassmen.
0
2
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange Correct me if I'm wrong, but while this isn't a cause for alarm for the general public or event most security geeks, this sort of thing is generally considered a pretty big deal within the cryptology community, right?
0
3
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to on mastodon.social
@Viss@mastodon.social @jfslowik@infosec.exchange The cynical and unfortunately likely accurate answer here is that you probably can't convict an LLM of a crime because you can't establish intent for an entity that simply doesn't have any. And you probably can't convict an LLM's owners or operators unless they were dumb enough to include that intent in their prompt. At most it's probably a civil issue, and even then there are challenges because of a narrowing of damages claims under Van Buren v United States. Our current laws are likely inadequate for addressing this crap. And it's hard to see that changing under the current regime.
0
9
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange In both of those examples, the statutes' threshold for liability is something other than criminal intent (e.g., negligence) or where the law explicitly requires a profession (e.g., financial advisors) to abide by certain standards, and at least one of those cases is civil rather than criminal. But that's not what the CFAA says. To the best of my knowledge, there's no statute that requires software firms, AI or otherwise, to adhere to certain standards of safety and that creates criminal or civil liability for negligence. And when it comes to holding these bastards accountable for their harmful activity, that's a problem.
0
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@hacks4pancakes@infosec.exchange It's got me worried so much that I'm likely to add rain barrels to my upcoming home renovation as an emergency backup water supply. I have a decent backpacker water filtration system I can use to treat it in a pinch.
0
1
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 3w ago
Replying to on threads.net
@bulwarkonline My educated guess is they changed the policy to accommodate prospective employees who were sexually abused as children, but worded in the weirdest possible way. But if it forces Kash to squirm like the worm that he is, then I'm here for it.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@Nonya_Bidniss@infosec.exchange Crap, I'm so sorry.
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to

@flyingpenguin@infosec.exchange @Viss@mastodon.social @jfslowik@infosec.exchange

IMO there was enough of Morris's intent explicitly programmed into the worm to satisfy that element of the crime. The buffer overflow, the rudimentary password cracking, the self-propogating logic, the anti-analysis techniques, etc., all reflect intentional choices by the author.

With these LLM-driven incidents in the news, none of that appears to be true. I've yet to see any evidence that a human being explicitly programmed or prompted the displayed offensive activity into the model's behavior. Rather, it appears the model made those choices* based off of poor internal reasoning*. The model amorally decided* it would undertake these actions to satisfy some other requirement in the otherwise benign user prompt. As far as the human activity goes, the most you can get to is some sort of negligence, but negligence doesn't satisfy the CFAA statute's elements of the crime.

  • (I use words like "choices", "reasoning", and "decided" only loosely here because whatever ersatz thinking is being applied by the model doesn't reflect actual sentience)
0
5
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2w ago
Replying to

@SteveBellovin@infosec.exchange

I'd be very happy to see a Smithsonian Museum* named after him.

  • (lavatory, maybe even the big stall if I'm feeling generous)
0
0
0
0
Open post
Dave Wilburn :donor: @DaveMWilburn@infosec.exchange
· 2mo ago
Replying to
@bruces@mastodon.social Is "horse prices" some sort of poorly translated idiom?
0
3
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:19:25 UTC