Skip to main content
Dan Goodin

Dan Goodin

Search complete. 8 mentions across 7 episodes found for "Dan Goodin".

Aug 24, 2026

Cary ParkerHOST
24:41
And coming in and firing twenty-five to fifty percent of our talent in that area and then turning around and trying to take it to the private sector is completely the wrong move.
Cary ParkerHOST
24:53
All right, next up here, a story from Ars Technica and, uh, Dan Goodin, and it's about a really massive data leak thanks to a very clever supply chain attack.
Cary ParkerHOST
25:06
Terabytes worth of credentials, terabytes worth of credentials, many belonging to the world's biggest and most sensitive organizations, have been exposed in a supply chain attack on LiteLLM.
Cary ParkerHOST
25:17
That's L-I-T-E L-L-M, as in large language model, an AI thing, uh, which it says here is an open source tool that streamlines AI-driven software development.

40 MINS LATER

Cary ParkerHOST
65:54
And then coming down the line, we've got interviews with, uh, folks from Epic about opt-out dark patterns.
Cary ParkerHOST
66:00
We will of course be talking with Bruce Schneier in the 500th episode, which is coming up very soon.
Cary ParkerHOST
66:05
Dan Goodin from Ars Technica, Tom Kemp, and some other fun surprises coming after that that came out of my trip to Defcon.
Cary ParkerHOST
66:12
So that's gonna do it for this week.
JordanHOST
5:28
It's meant to stop the amount of damage, right? It's like it's a proactive measure.
JordanHOST
5:33
I think it's really interesting at the end of this article, um, uh, Dan Goodin wrote something, um, "Ultimately, attacks like Cosnitch and Microsoft's statement are reminders that LLM security is largely built on a list of reactive restrictions rather than building a road with banked turns that proactively prevent a car from veering off a cliff.
JordanHOST
5:53
LLM developers-
JonahHOST
5:54
[laughs]
Costin RaiuHOST
67:47
I, I...
Costin RaiuHOST
67:48
This is the kind of story that you see, um, um, you know, our friends, uh, Dan Goodin, Kim Zetter write.
Costin RaiuHOST
67:54
This, this is one of those kind of stories.
Costin RaiuHOST
67:57
It's a fantastic story, so shout outs to the authors, um, Duncan Campbell from the Sussex Center for Law and Technology, and, uh, Bill Goodwin, an investigations editor for Computer Weekly.
CassidyHOST
7:32
Give us a site, a power contract, and an in-service date, then we can start treating it like capacity instead of ambition.
BillHOST
7:41
Ars Technica with Dan Goodin.
speaker_2NARRATOR
7:43
Company researchers are calling the technique cryptographic context injection.
speaker_2NARRATOR
7:48
Cryptographic context injection is one instance of a broader shift.
Jess HebenstreitHOST
16:03
Yeah.
Jake WilliamsHOST
16:03
So our, our second story that we, uh, that we're gonna cover today, um, actually comes to us, uh, from, uh, Dan Goodin, uh, over at Ars Technica.
Jake WilliamsHOST
16:11
A fantastic journalist, a fantastic human too, by the way.
Jake WilliamsHOST
16:14
Um, but, uh, uh, so, um, he's talking about...
Steve GibsonHOST
19:37
Okay, so we're gonna start by covering some important recent security events and then get into understanding this first of the two core issues of the way AI works.
Steve GibsonHOST
19:49
Last Wednesday, uh, Ars Technica's great security topic, uh, writer Dan Goodin reported under the headline, "Terabytes of credentials leaked in massive supply chain attack," was, uh, Ars headline.
Steve GibsonHOST
20:08
Uh, and of course, that was the kind of thing I would have chosen to share even a few years ago.
Steve GibsonHOST
20:12
But the thing that raised my interest another several notches was the article's tagline, which read, "That data," that is the terabytes of credentials, "was scraped and exfiltrated from twenty-five hundred users of a compromised AI package." So I thought, "Whoa, uh, okay." Uh, it turns out what's, [chuckles] what's even more significant is we're not talking some random end users in Nebraska, you know, who no one knows.
Steve GibsonHOST
19:37
Okay, so we're gonna start by covering some important recent security events and then get into understanding this first of the two core issues of the way AI works.
Steve GibsonHOST
19:49
Last Wednesday, uh, Ars Technica's great security topic, uh, writer Dan Goodin reported under the headline, "Terabytes of credentials leaked in massive supply chain attack," was, uh, Ars' headline.
Steve GibsonHOST
20:08
Uh, and of course, that was the kind of thing I would have chosen to share even a few years ago.
Steve GibsonHOST
20:12
But the thing that raised my interest another several notches was the article's tagline, which read, "That data," that is the terabytes of credentials, "was scraped and exfiltrated from twenty-five hundred users of a compromised AI package." So I thought, "Whoa.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.