Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Public Key
npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx Profile Code
nprofile1qqsrhfhexcslfawgj0du2aqhmsngud4kzmga7r4pu8lmmyg3kjy6zhcpz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0ds62uuw4
Show more details
Published at
2026-05-01T20:47:36+02:00 Event JSON
{
"id": "8c6b3d4fdeaa367acd0c02f213d4db9c4b7bcc783521f16637737147ea81d8a4" ,
"pubkey": "3ba6f93621f4f5c893dbc57417dc268e36b616d1df0ea1e1ffbd9111b489a15f" ,
"created_at": 1777661256 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://hachyderm.io/users/evacide",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"evacide\",\"about\":\"Director of Cybersecurity\\n@EFF\\n/ Co-founder of\\n@stopstalkerware\\n/ These are my opinions, not my employers’ / I did a TED talk once\",\"picture\":\"https://media.hachyderm.io/accounts/avatars/110/023/534/681/636/317/original/592205ed198bf44a.jpg\",\"banner\":\"https://media.hachyderm.io/accounts/headers/110/023/534/681/636/317/original/3dfaf02bfcbcbd7b.jpeg\",\"nip05\":\"[email protected] \",\"fields\":[]}" ,
"sig": "d79278970bef90537f4986423e5d605c1fd78c4504ff56851af364bd9229f312da5845658c30fba8c7314ea0260a2d6c22d83580078a15df855190344ff9f490"
}
Last Notes npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide EFF is finally leaving X and here is a blog post about why: https://www.eff.org/deeplinks/2026/04/eff-leaving-x npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I was really hoping to go through life without needing to know what the plural of "apocalypse" is. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide "I'm just going to let people be wrong on the internet" remains the single most difficult New Year's Resolution I have ever made, hands down. Nothing else comes close. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Several years after I locked up my account and stopped using twitter, I have finally updated my staff bio by deleting my Twitter username and adding the URL for my Mastodon account. It feels like the end of an era. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Sometimes I wonder if working from home for so long has turned me into a goblin who cannot be trusted to interact with other people without making it weird. Then I remember that I have always been a goblin who cannot be trusted to interact with other people without making it weird. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Good news for people with older iPhones. Patch your stuff. https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-from-darksword-hacking-tool/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide EFF's Cindy Cohn sat down to talk to Jon Stewart on the Daily Show about 30 years of fighting for digital privacy. I think that's pretty cool. https://www.youtube.com/watch?v=QkC1aK7jfLo npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide My open tabs indicate that I got halfway through ordering a pair of high-waisted black sequinned booty shorts last night and then fell asleep. Let it never be said that I don't know how to party. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Yael's post demonstrates something about digital privacy/security that I think a lot of people miss: there is no right answer, just a series of trade-offs. And every person has to make their own decisions about which trade-offs are worthwhile. https://blog.yaelwrites.com/options-for-phones-at-protests/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you are traveling to or through Hong Kong, here is a new thing to consider when you are deciding whether or not to take your devices with you and how you should set them up. https://hk.usconsulate.gov/security-alert-2026032601/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide No really, I am not kidding when I say that the data broker industry must be destroyed: https://www.npr.org/2026/03/25/nx-s1-5752369/ice-surveillance-data-brokers-congress-anthropic npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide People will react to news of major security vulns with "The only way to stay secure is to live as a hermit and throw your devices into the sea" and then keep chattering on the internet in a deeply unhermitlike manner while not throwing their devices into the sea. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you have an iPhone, today is a good day to make sure you are running the latest software. https://techcrunch.com/2026/03/23/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide @nprofile…s8xx It is possible that for some threat models, a burner phone for DEFCON is appropriate. But I have been to 20ish DEFCONs and I have never felt the need to bring one. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Some tips on giving digital privacy/security advice: if you tell people they absolutely need to do a long list of difficult and expensive things before they travel, people will nod and smile and then not do it at all. This is why my advice focuses on harm reduction and understanding trade-offs. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide For people who are concerned about having their devices seized at US airports starting Monday when ICE "assists" the TSA, EFF has this guide: https://www.eff.org/deeplinks/2025/06/journalist-security-checklist-preparing-devices-travel-through-us-border npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The data broker industry must be destroyed: https://www.theverge.com/news/897145/kash-patel-ron-wyden-fbi-location-data-no-warrant npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Hey, why is everyone talking about Caesar Chavez all of the sudden? Oh. Oh no. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide It sure is a cool and normal time to be working at a civil liberties non-profit in the United States. https://www.cbsnews.com/news/fbi-irs-investigate-nonprofits-domestic-terrorism-links/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Attribution is hard. And there is a difference between getting a contractor on the record attributing the toolkit and a bunch of infosec dudes sitting around pontificating about how "everyone knows." https://techcrunch.com/2026/03/09/an-iphone-hacking-toolkit-used-by-russian-spies-likely-came-from-u-s-military-contractor/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I aspire to one day have a fraction of the confidence of a mediocre white man sitting down to do an interview with Isaac Chotiner. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide What a stupid time to have a degree in International Relations. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide When we talk about the problems with Bluetooth-enabled physical trackers, we usually talk about AirTags, but let us save some rage for Tile, powered by this paper discussing Tile's privacy, security, and accountability problems: https://arxiv.org/abs/2510.00350v1 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The greatest joke that my brain chemistry plays on me is that every few years I get an idea for a novel, which I will outline, write several chapters for, and then never touch again. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I'm just a girl, incrementing the counter on the number of times I have been sent a plaintext email from a Protonmail user telling me that the message is encrypted. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning. https://www.therage.co/persona-age-verification/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Anonymously threatening a security researcher seems like a shooting-yourself-in-the-dick level bad decision. Kudos to Allison Nixon for not taking any shit. https://www.technologyreview.com/2026/02/16/1132526/allison-nixon-hackers-security-researcher npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The most monstrous lie that I regularly tell myself is "I'll get that work done while I'm on the plane." npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I've spent the last year learning Spanish just so I could understand Bad Bunny lyrics. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Trying to explain compartmentalization to activists, but the biggest stumbling block is that most people become activists by accident, so their activism is deeply enmeshed with all of their existing accounts, platforms, and devices. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Every once in a while, someone gets the genius idea of impersonating me online and I spend an afternoon looking for the most chaotic way to make them regret that choice. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Notepad++ publishes a blog post saying they caught a probably-Chinese state actor hijacking their product in an attack against highly-selective targets that began last June: https://notepad-plus-plus.org/news/hijacked-incident-info-update/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Why do your organizing over Signal? So that you don't do your organizing on an app that hasn't been tested or reviewed, run by a guy who doesn't tell his users about data breaches and security problems. https://www.ibtimes.co.uk/stopice-hacked-names-locations-over-100k-users-were-sent-fbi-ice-hsi-1775307 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Planning to film ICE? Wired has a guide for that: https://www.wired.com/story/how-to-film-ice/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide How many people here would be interested if I did a digital security/privacy advice blog somewhere? npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide This is your regular reminder that I do not owe you an argument defending a position that you have decided that I hold. Indeed, I do not owe you an argument about anything. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Hello, it's me. I'm the one training the resistance in the diabolically professional OPSEC of setting disappearing messages in the Signal group chat. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide You don't need superspy-level OPSEC in order to protest fascism. But protest does involve risk. My goal when I teach people about digital privacy/security is to make sure that people understand what risks they're taking so they can make appropriate mitigations while still accomplishing their goals. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Trying to protect everything from everyone all the time is a good way to drive yourself crazy. This is why we threat model. Here is EFF's Surveillance Self Defense guide to putting together your security plan, also known as threat modeling: https://ssd.eff.org/module/your-security-plan npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you are organizing folks in Minneapolis right now, you may find this guide to Signal for beginners by @nprofile…upkm useful: https://freedom.press/digisec/blog/signal-beginners/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Project Zero releases a 0-click exploit chain for the Pixel 9. This one targets the Pixel, but the 0-click bug and exploit techniques used also apply to most other Android devices. https://projectzero.google/2026/01/pixel-0-click-part-1.html npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide This is your regular reminder that authoritarianism is just domestic abuse writ large. https://www.reddit.com/r/Minneapolis/comments/1qa3pmm/boxed_in_by_ice/?share_id=yENO8ZsExaP3fz058MD_f&utm_medium=android_app&utm_name=androidcss&utm_source=share&utm_term=1 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Sometimes I read the threads that experienced activists write about how to behave at protests because it reminds me that the kinds of replies I get when I give digital privacy/security advice aren't just for me. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide We are 9 days into 2026 and my New Years' Resolution to just let people be wrong on the internet is already is truly testing the limits of my willpower. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide There is no one-size-fits-all solution for digital safety at protests. You need to decide in advance what your goals are, what is important for you to protect, and what is likely to happen to you, and threat model accordingly. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide But if it is important to you to maintain your anonymity at a protest, consider leaving your phone at home, or at least turning it on/off only once you are well out of the neighborhood. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide There are other reasons you might want to take a cheap/disposable/burner phone to a protest, such as making sure that if you are arrested, the police don't seize/break/confiscate your main phone. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you don't want ICE to know you were at a protest, taking a burner phone is not going to help you stay anonymous if you go home afterwards. https://www.404media.co/inside-ices-tool-to-monitor-phones-in-entire-neighborhoods/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide All that the Turing Test proves is that human are much, much stupider than Alan Turing ever suspected. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Want to know how to track Homeland security spending by looking through government databases? EFF's Dave Maass has put together a handy how-to: https://www.eff.org/deeplinks/2025/12/homeland-security-spending-trail-how-follow-money-through-us-government-databases npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide This year, for my mental health, I'm going to practice just letting people be wrong on the internet. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The push for the TikTok ban was bipartisan and stupid. But the Trump administration's goals for the ban have always been crystal clear: to place control of TikTok in the US in the hands of people chosen by and indebted to Trump. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide @nprofile…889j You did so much good work this year. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I can't believe I have to say this, but please do not take revolutionary OPSEC advice from YA novels Cory Doctorow wrote almost twenty years ago. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide NYT reports that the TSA is giving ICE a list of every person who's to be taking a domestic flight inside the US so ICE can run it through their database looking for targets. I'm not a lawyer, but I feel like the 4th Amendment has something to say about this. https://www.nytimes.com/2025/12/12/us/politics/immigration-tsa-passenger-data.html?unlocked_article_code=1.8E8.lG_B.SvLF8g3CXiKG&smid=bs-share npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide 2025 Year In Review: Not feeling so great about the rule of law. Zero stars. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I don't dress for the male gaze. I dress for a women who are old enough to be my mother, wear oversized jewelry, and say things like "I'd dye my hair that color." npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Age verification is not the way to keep kids safe on the internet. CDT has some thoughts about what kind of child safety policies and features might actually be effective: https://cdt.org/insights/what-kids-and-parents-want-policy-insights-for-social-media-safety-features/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I gave a talk about fascism at a conference and the first reply to the conference's post on X with a photo of me in front of my slides is a rando word-vomiting about how Hitler was working for the Zionists, in case you're wondering how that place is going. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Brennan Lee Mulligan with Josh on Mythical Kitchen, eating his perfect last meal and being interviewed for more than an hour, is so wholesome and life-affirming: https://www.youtube.com/watch?v=CLVdWyNljP8 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide After two trips to the hardware store and approximately $25 in bits and bobs that did not work, I fixed the catch on my antique dresser cabinet with a single screw. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Cybersecurity professionals/ransomware negotiators turned out to be running a ransomware gang. https://breached.company/when-the-defenders-become-the-attackers-cybersecurity-experts-indicted-for-blackcat-ransomware-operations/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you are shocked that I'm happy that a man responsible for the deaths of hundreds of thousands of people is dead, I have terrible news for you about all of my other opinions. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If you think that Signal is an op and totally backdoored, my recommendation is that you should plan all of your crimes over Telegram group chat. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Every quote in this story from the founder of Ring, Jamie Siminoff has been designed in a lab to illustrate the single most wrongheaded approach to technology, surveillance, privacy, and crime: https://www.theverge.com/tech/804052/ring-jamie-siminoff-book-ding-dong-release-date-interview npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Whoever decided that the San Francisco No Kings protest should start at the same location as the bougie weekend farmers market is a political genius. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide If your protest privacy/security advice does not start with a discussion of threat models, it is probably not good advice. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide "A soldier knows what to do when they encounter another soldier. But an air-humping frog?" @sarahjeong.bsky.social on the shitposting/aura farming era of American politics. https://www.theverge.com/policy/798491/frog-portland-trump-national-guard npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide As the prophecy foretold, a major platform's third-party age verification system has been hacked and hackers had access to the government ID images of Discord's users. https://www.tomsguide.com/computing/online-security/discord-users-suffers-the-first-high-profile-age-verification-hack-and-its-unlikely-to-be-the-last npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I have spent many years willing to take big swings in my work because I knew that Cindy Cohn was the adult in the room. I am not ready to be the adult in the room. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I take it all back, there ARE violent criminals on the streets of San Francisco. They're grabbing people off the street and pepper spraying journalists. https://sf.gazetteer.co/i-reported-from-an-ice-action-on-sansome-and-all-i-got-was-a-face-full-of-pepper-spray npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide You will sure be shocked to discover that I have some things to say about AI-powered "smart" glasses that give no indication that they are recording your every word. https://techcrunch.com/2025/08/20/harvard-dropouts-to-launch-always-on-ai-smart-glasses-that-listen-and-record-every-conversation/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The founders of the Tea app tried to recruit a female co-founder and face for the app, telling her "Tea has all the safety measures that Facebook lacked and more to ensure that only women are in the group." https://www.404media.co/how-teas-founder-convinced-millions-of-women-to-spill-their-secrets-then-exposed-them-to-the-world/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide @nprofile…4dwe Trump will make an all-caps post of Truth Social. it will be devastating. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide It is sometimes necessary, in these difficult times, to spend an hour scrolling through clothing sites, hoping that one of these gowns is going to give you the strength to fight fascism. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Even when I don't go to Vegas, the Vegas gossip comes to me. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Ron Deibert is absolutely the voice that the infosec industry needs to be listening right now. We are in a moment where fascism is consolidating power and most of the infosec industry is either playing along or is busy bragging about how much AI they've shoved into their products. https://techcrunch.com/2025/08/06/citizen-lab-director-warns-cyber-industry-about-us-authoritarian-descent/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Listen, we are in a terrible and difficult time where the horrors can often feel overwhelming. Lean into the things that bring you joy. If that means that sometimes you're wringing that last drop of dopamine out of watching bad people suffer as the result of their poor choices, you do you. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide When I was a kid, I couldn't wait to be an adult because I imagined that adulthood would be a time when no one would interrupt me when I was trying to read. If I could go back in time, I would tell that little girl she has never been more wrong about anything in her life. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Writing the first draft of my FTC comments and wondering how many times I am allowed to write "fuck no, you shitweasel." https://www.ftc.gov/news-events/news/press-releases/2025/07/ftc-seeks-comment-petition-vacate-2021-order-related-provider-stalkerware-apps npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide This is just to let you know I have taken the plums out of the icebox because fruit is better at room temperature npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Pour one out for every person writing questions for a US Constitutional Law exam in the year 2025. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide This is your regular reminder that if you are the smartest person in the room, go find another room. You are not going to run out of people or rooms. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I've spent not-insignificant amount of time at protests in the US, looking for signs of IMSI catchers and never found anything, so when I saw this, my ears perked up: https://san.com/cc/exclusive-evidence-of-cell-phone-surveillance-detected-at-anti-ice-protest/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Google continues the industry-wide trend of jamming AI down users' throats, making it difficult or impossible to opt out, and potentially endangering the privacy of communications: https://www.neowin.net/guides/google-can-now-read-your-whatsapp-messages-heres-how-to-stop-it/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I was feeling entirely too confident and capable, so I decided to train press-up to handstand and now I am going to be suffering through these drills and progressions for a good long time. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Every once in a while, someone tells me that an abusive partner left them alone because they were afraid of what I would do if they didn't, and I feel like I have done something right. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Website/device age verification is a privacy and security nightmare and everyone who tells you that this is a solved problem is lying to you. https://gizmodo.com/supreme-court-says-age-verification-laws-for-porn-sites-are-constitutional-2000621265 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Do I think that the national Democratic Party will learn anything from Mamdani's win? No. Do I think it is important to enjoy a goddamn victory once in a while? Yes. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide APT1 partying like it's 2004-2013. https://www.wsj.com/tech/cybersecurity/cyberattack-on-washington-post-compromises-email-accounts-of-journalists-70bf1300?mod=author_content_page_1_pos_1 npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide I would like to be Chrisjen Avasarala: impeccably-dressed, running things, swearing like a sailor. But I am Camina Drummer: barely keeping it together, sort of in charge, with a lot of complicated relationships and a strong eyeliner game. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Seriously, if you think that it is clever to respond to a guide with advice for journalists for protecting their devices when crossing the US border with "You just shouldn't ever go to the US!" please consider posting your response in your own timeline, where I will never have to see it. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Me, looking at my work calendar: This is insane. No one can do this much work. I'm going to find the asshole that did this and give them a piece of my mind! Me, looking in the mirror: Oh no. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Did I mention that the data broker industry must be destroyed? https://theintercept.com/2025/05/22/intel-agencies-buying-data-portal-privacy/ npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Q&A from a talk I gave last week. Q: "What do you think is the biggest threat in cybersecurity right now? Is it post-quantum computing? Is it AI?" A: Fascism. It's fascism. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide The only way I can possibly touch enough grass to get through this day is to remove all of my clothes and roll around on a lawn. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide There is so much bad news out there right now that it is sometimes difficult to even see the wins. https://www.nytimes.com/2025/04/25/us/politics/trump-student-visa-cancellations.html?unlocked_article_code=1.CU8.qevX.RyotrTomoS1e&smid=url-share npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide "Signal is a commercially available app that is not authorized to be used for sensitive or classified information. It’s encrypted, but can be hacked." This is just sloppy writing, implying that the problem with Signal is that someone might break its encryption. https://apnews.com/article/hegseth-signal-chat-dirty-internet-line-6a64707f10ca553eb905e5a70e10bd9d npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide For people who are looking to shield their identities in group chats: Signal does not store past handle IDs and 7 days after changing your handle, another Signal user can claim it. npub18wn0jd3p7n6u3y7mc46p0hpx3cmtv9k3mu82rc0lhkg3rdyf590s3wshpx evacide Big Law has failed to stand up to Trump and now infosec is following suit. https://www.reuters.com/world/us/cybersecurity-industry-falls-silent-trump-turns-ire-sentinelone-2025-04-10/