Nicholas Weaver
@ncweaver.skerry-tech.com
8.5K followers 310 following 7K posts
Researcher, Computer Security @ ICSI Chief Mad Scientist @ Skerry Technologies Putting the Science in "Mad Science" Digital, Explainable, and (usually) Adversarial Systems Looking for employment: CV is here https://skerry-tech.com/cv.html he/him
Posts Media Videos Starter Packs
Reposted by Nicholas Weaver
faineg.bsky.social
I don’t feel bad about eating lamb because it’s basically only slightly more ethically fraught than eating a potato, sentience-wise.
bganderson.bsky.social
My farm-working friend is sure that if a sheep can find a way to kill itself, it will. He places them at the low end of the agricultural intelligence scale, just below barley.
ncweaver.skerry-tech.com
Housecats too, but housecats are small and lack opposable thumbs, so we are safe...
Reposted by Nicholas Weaver
faineg.bsky.social
People sometimes try to use “ah, you eat pigs but you WON’T eat a dog” as if it’s some kind of clever gotcha, and man, I dunno, dogs usually aren’t scheming to eat us when we turn our backs as a *default*
johnsmillie42.bsky.social
I met a pig farmer in a bar once. I asked him what they were like. He said "Like dogs, but without the loyalty. They're really smart, but definitely never turn your back on a pig."
faineg.bsky.social
i have met a number of pigs, including pigs i later went on to eat (we have small farmers in our family) and quite frankly, getting to know pigs has made me feel even less bad about eating them

they would 100% eat us if given the chance
ncweaver.skerry-tech.com
Chili-Mac.

Ye cliche box Mac & Cheese (gluten free these days) with canned chili mixed in.
faineg.bsky.social
What foods do you love that you fully acknowledge make you a pervert for loving them?
ncweaver.skerry-tech.com
From Terry Pratchett, "Feet of Clay"
ncweaver.skerry-tech.com
This piggy was the size of a pony. This piggy had tusks. And it wasn't pink. It was a blue-black colour and covered with sharp hair but it did have little red piggy eyes.

This little piggy looked like the little piggy that killed the boarhounds, disembowelled the horse and ate the huntsman.
ncweaver.skerry-tech.com
JetBrains stuff already does a pretty good job w/o the AI enabled.

It wouldn't surprise me if we even see open source running locally "Spicy autocomplete" for various languages in the near future.
ncweaver.skerry-tech.com
And you don't need a massively sophisticated model for decent autocomplete.
Reposted by Nicholas Weaver
jamellebouie.net
very cool that if you are working on behalf of right-wing culture warriors, you no longer need standing to have your claim adjudicated by the supreme court
tomscocca.bsky.social
It's not just that they're going to strike down a law against conversion therapy, it's that they're going to do it on behalf of made-up claims from a straw plaintiff who can't honestly show the law affected her at all
tomscocca.bsky.social
One thing about American's widespread distrust and disapproval of the Supreme Court is that mainstream news coverage mostly doesn't dwell on stuff like standing, so people don't even begin to grasp how rigged the Court truly is www.nytimes.com/live/2025/10...
ncweaver.skerry-tech.com
I don't think Nvidia will go broke, but dropping 90% in value will have some serious knock-on effects...
Reposted by Nicholas Weaver
briankrebs.infosec.exchange.ap.brid.gy
New, by me: A cybercriminal group that used voice phishing attacks to siphon more than a billion records from Salesforce customers earlier this year has launched a website that threatens to publish data stolen from dozens of Fortune 500 firms if they refuse […]

[Original post on infosec.exchange]
A screenshot of a scan of the trojan at virustotal.com shows 11 of the 72 security tools detected it as malicious. The malicious indicators are marked in red.
ncweaver.skerry-tech.com
It is long, LONG past time that OFAC just designate all ransomware gangs. It must be illegal to pay these assholes, and it is the only way the problem will be solved is to stop the profit motive.
briankrebs.infosec.exchange.ap.brid.gy
New, by me: A cybercriminal group that used voice phishing attacks to siphon more than a billion records from Salesforce customers earlier this year has launched a website that threatens to publish data stolen from dozens of Fortune 500 firms if they refuse […]

[Original post on infosec.exchange]
A screenshot of a scan of the trojan at virustotal.com shows 11 of the 72 security tools detected it as malicious. The malicious indicators are marked in red.
Reposted by Nicholas Weaver
rahaeli.bsky.social
It's one of those things where the solution we have isn't GREAT, it isn't ideal, but it's so, SO much better than the way things used to run that anyone who's ever worked in the industry is so incredibly thankful even for the imperfect solution because it's still so much better than it was
Reposted by Nicholas Weaver
hacks4pancakes.com
I guess I haven't clearly articulated this in writing, but friends do not let friends without substantive IT work experience and/or a credible IT degree take cybersecurity career bootcamps in 2025.

They are up to no good. Shenanigans. Malfeasance. They are not a safe way to get a job.
ncweaver.skerry-tech.com
Really starting to wonder if Nvidia is going to become a bigger scandal than Enron:
Where is Chewco in this diagram?
ncweaver.skerry-tech.com
And I may be down on the coding useage (I hate finding subtle bugs in my own code), that is a huge candidate for smaller and specialized: create a languaged-specialized instance that not only runs locally but safely can have the full user's codebase access w/o the leakage concerns.
Reposted by Nicholas Weaver
emptywheel.bsky.social
Top candidates:
1) Lindsey the Insurance lawyer is DQed w/in days, making the indictment a nullity
2) Statute of Limitation problems
3) Discovery problems
4) Vindictive prosecution
5) Kash Patel melting down on the stand
ncweaver.skerry-tech.com
"When the family tree becomes a family bush you just can't hide as much underneath it anymore!"
ncweaver.skerry-tech.com
But it does make me ask: "Do you use an anatomically accurate Donald Duck drawing as well?"
ncweaver.skerry-tech.com
Which means the AI datacenter is only needed for training the models, which cuts demand for the AI datacenter massively. And since training isn't realtime, a smaller & cheaper datacenter takes longer but, in many cases, so what?
ncweaver.skerry-tech.com
An additional complication: Fundamentally these systems will always be wrong a non-zero percentage of the time. Going smaller, shrinking the model to run on the end-user device, only increases the error slightly but greatly reduces the cost: eliminating the need for the datacenter to run it.
Reposted by Nicholas Weaver
maxkennerly.bsky.social
A bunch of these circular AI deals are treating GPUs like they're real estate or Treasury bonds or something, rather than rapidly depreciating equipment with a high risk of obsolescence well within 5 years due to energy inefficiency and rising electricity costs.
/1
www.bloomberg.com/news/article...
XAI’s financing would be split between about $7.5 billion of equity and as much as $12.5 billion of debt in the SPV, the people said. The vehicle will be used to buy Nvidia processors, and Musk’s artificial intelligence startup would then rent the chips out for five years, allowing Wall Street financiers to recoup their investment. The unique deal structure, backed by the GPUs as opposed to the company, could provide a playbook for tech firms looking to decrease debt exposure.
ncweaver.skerry-tech.com
The bet: It is the Sky Blue Flu that is going to get the Republicans to actually get serious about things: either actually negotiate or nuke the fillibuster.
ai6yr.m.ai6yr.org.ap.brid.gy
If they go to no ATC at BNA will be... interesting. That's a much bigger airport than BUR. They are ground stopped right now, but doesn't look like they are officially at zero staff (yet). 10/8/25 0013UTC #bna #aviation #groundstop
Oct. 7, 2025 | The Metropolitan Nashville Airport Authority (MNAA) was notified at 1:25 p.m. by the Federal Aviation Administration (FAA) that flights arriving and departing from Nashville International Airport® (BNA®) will be reduced beginning at 2:30 p.m. (CST) due to a shortage of air traffic controllers. This reduction will remain in effect until further notice. All airlines have been informed. Travelers should check the status of their flight with their respective airline before arriving at BNA. As a reminder, FAA has sole responsibility for the National Airspace System.

For additional questions, please contact the FAA.