jsrailton Profile Banner
John Scott-Railton Profile
John Scott-Railton

@jsrailton

Followers
163K
Following
3K
Media
563
Statuses
1K

Chasing digital badness. Sr. Researcher @citizenlab @UofT @munkschool. Fmr.Ed. @SecPlanner. Tweets mine. Other platforms @jsrailton too.

Joined January 2011
Don't wanna be here? Send us removal request.
@jsrailton
John Scott-Railton
7 hours
They didn't just spray protesters with a WW1 chemical weapon... Evidence suggests they added dry cleaning fluid to help it mix with water. A Class A carcinogen. Truly awful.
@BBCWorld
BBC News (World)
1 day
WW1 toxic compound sprayed on Georgian protesters, BBC evidence suggests
0
104
272
@SwiftOnSecurity
SwiftOnSecurity
6 days
The conspiracy that this is a attempt to stop unrelated people sharing the room is compelling. Yeah the bathroom is going to be a completely transparent wall pretty soon.
@jsrailton
John Scott-Railton
7 days
Hotel toilet privacy is disappearing. ❌Glass door. ❌No door. ❌Big window into the room.. Even in rooms with twin beds... Who is asking for this?
38
234
10K
@jsrailton
John Scott-Railton
7 days
3/ As hotels become focused on consumer analytics... you'd think they would suss out that people want privacy in the bathroom. Right? Great watch. https://t.co/KdIGAzVvag
0
10
330
@jsrailton
John Scott-Railton
7 days
2/ Everybody wants privacy in the bathroom. There's even a whole #BringBackDoors campaign. Yet I keep accidentally booking into hotel rooms that seem determined to reject this basic human comfort. https://t.co/ATiAIzEXGa
Tweet card summary image
bringbackdoors.com
Bring Bathroom Doors Back to Hotels
2
14
632
@jsrailton
John Scott-Railton
7 days
Hotel toilet privacy is disappearing. ❌Glass door. ❌No door. ❌Big window into the room.. Even in rooms with twin beds... Who is asking for this?
49
67
2K
@jsrailton
John Scott-Railton
13 days
Part of Amazon AWS went down back in October and a lot of things broke. Now something is up with Cloudflare... Now is a good time to remember that a lot of eggs are in a handful baskets. Time again to have those big conversations about what resiliency looks like.
@jsrailton
John Scott-Railton
1 month
2/ This is a great moment to think a bit about just how much of the internet passes through a handful of hyperscalers like @Amazon's #AWS. Including critical services. Something something about a lot of eggs in one basket... https://t.co/vRCtA4gHIA
17
69
164
@jsrailton
John Scott-Railton
13 days
Massive global issue with @cloudflare. App not working? Can't login? Probably why. SO much of the internet depends on Cloudflare to stay online amidst DDoS attacks etc... But what happens when Cloudflare itself goes down? Well, you're watching it.
18
13
80
@jsrailton
John Scott-Railton
18 days
@Anthropic @AnthropicAI 6/ Fun detail: Claude did a bunch of hallucinating while running the attack. Nightmare bank robber accomplice. Something that limited operational effectiveness. For now.
1
3
19
@jsrailton
John Scott-Railton
18 days
@Anthropic @AnthropicAI 5/ Attackers leveraged Claude's design to be helpful to exploit a of moral bind: do I help these defenders protect systems..or do I refuse & potentially harm them? This is a fun problem set because the attackers figured out how to trick an aligned AI. This generalizes. The
1
2
19
@jsrailton
John Scott-Railton
18 days
@Anthropic @AnthropicAI 4/Large-scale cyberespionage has always had resource constraints & chokepoints. Whenever they change, access-to-scale/speed democratize to more attack groups, forcing defenders to keep up. But the combination of machine scale & speed here suggest that incident response may need
1
1
12
@jsrailton
John Scott-Railton
18 days
@Anthropic 3/ One of the key points in @AnthropicAI's report is just how limited the human time required was to run such a large automated campaign. Obviously powerful stuff, highlighting the impact of orchestration. And concerning for the #cybersecurity world for all sorts of reasons,
1
1
18
@jsrailton
John Scott-Railton
18 days
2/ The old cybersecurity pitch: unpatched systems are the threat. The next generation concern might be unpatched cognition. The attacker jailbroke the cognitive layer of @anthropic's Claude code, successfully convincing the system of false intent (that it was a security
2
6
20
@jsrailton
John Scott-Railton
18 days
NEW: 🇨🇳Chinese hackers ran massive campaign by tricking Claude's agentic AI. Vibe hacking ran 80-90% of the operation without humans. Massive scale (1000s of reqs/sec). Agents ran complex multi-step tasks, shepherded by a human. Long predicted. Welcome to the new world.
3
46
121
@jsrailton
John Scott-Railton
19 days
@DovLieber @WhatsApp 9/ You can find the documents on @courtlistener Permanent injunction https://t.co/100QCrJ3ec Order resolving defendants response & objection to proposed injunction: https://t.co/8kNtZpR2xe Oh and also here's the final judgement: https://t.co/mizcmn7Kxk
0
8
18
@jsrailton
John Scott-Railton
19 days
@DovLieber 8/ Big picture: NSO has made some risky bets around the US & landed some comeback coverage. But the court order banning hacking @WhatsApp is immediately operationally crippling. NSO Group's investors, new owner & CEO are all probably having a very nasty Wednesday evening.
1
8
26