Skip to content
EN

Back to the catalog

akostopoulos.blog
rss2English

Athanasios Kostopoulos

akostopoulos.blog · English

Security / Berlin

rss2 wordpress content media slash wfw atom dc sy

Open the feed

https://akostopoulos.blog/feed/

Last post
Jul 19, 2026
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
United States
Text score at discovery
8,722
Format
rss2
Features in the feed
content, media, slash, wfw, atom, dc, sy
Community
wordpress

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. What are your top three resources?
    Jul 19, 2026 · original
    Sometimes I get lucky and get access to certain people that I consider exceptional masters of their craft. If you have one question and you need to make it count, what would this question be? The one I am using is the following: “Share the top three resources for your domain of expertise. It can be a book, a video, a research paper, an article, a website, whatever you want”” (or a variation thereof, depending on the receiving party. If possible I follow up “Why these three?” (although quite often when folks share these three resources with me, state the reason for doing so). This got me thinking, if someone was to ask me “What are the top three resources in the field of information security?”, what would my answer be? Information security is a broad field after all and one can deduce from the question above that this might be a question from someone who is about to start (or has only rec
  2. Thor Arthur 66ZZD: Systems and Risk (A 2025 Retrospective)
    Feb 19, 2026 · original
    This year I started introducing my ideas to the world. Criticizing something requires discipline, lest you end up ranting, which I strive to steer clear of. Offering ideas and alternatives (essentially building toward replacing flawed foundations) is intrinsically harder. The very moment you offer solutions for any complex topic , corner cases and information gaps surface. If you happen to have what hip-hop calls “haters,” they will cherry-pick accordingly. That is expected. By offering well-founded critiques and solutions to a problem, you invite counterarguments, well-meant or not. In more cases than not, however, you help to challenge dominant risk narratives that persist without empirical validation. Bringing topics front and center creates the conditions for synthesis. Ignoring structural risk at the intersection of governance and security creates latent failure points. In today’s w
  3. Fender Studio Pro and Product Security: A study in perception problems
    Feb 3, 2026 · original
    [The Obligatory Music Analogy] One of my favorite DAWs is the DAW formerly known as Presonus Studio One (currently rebranded as Fender Studio Pro ). Personally, I got my first professional licence back in version 4 (current version is 8) and it ticked the right boxes for me. Given that these days for most musicians there is no need to follow an “industry-standard” purchasing pattern (which usually meant either Pro Tools or Cubase) and given that I did not have had access to Apple hardware as a given (how times have changed!)Studio One presented me with arguably a super-fast and efficient workflow, at the very least on par with Logic Pro’s one (a DAW running only on Apple hardware). Given that my deciding factor is workflow speed and orthogonality, it is a clear winner and both these properties increased the workflow speed even further. Being orthogonal means that when you want to utilize
  4. Can we get back to progress again, please? (Pt I)
    Jan 27, 2026 · original
    Cory Doctorow started pointing out that there is incentivized decay of major internet platforms . While he is referring mostly from the end user perspective, the repercussions of these are also seen in the information security domain. Before proceeding, let’s set up our assumptions first: Proper software security is an inherent sign of quality. Quality is one of the metrics of engineering excellence (you do not actually believe that security is part of QA, do you? If you do, can I get a ride in your time machine please?). Excellent technology does not always win and this can be OK. However, it used to win way more often than not. Deliberately downgrading existing technology is a major regression and the very definition of wasted productivity. For security, there is a significant and proven body of research work in all relevant domains so the knowledge is already existing (and should be e
  5. Five Algorithms Walk Into a CTF (Only One Walks Out)
    Nov 23, 2025 · original
    I have a soft spot for CTFs. While CTFs do not reflect the grim realities of penetration testing or red teaming – one key difference is that CTFs have an “a-ha” solution with synthesis going on, they do remain a nice activity one-in-a-while – some challenges are uniquely interesting and the time pressure element is always there (in CTF parlance “ blood” or “ firstblood” refers to the first one reaching a solution and a significant number of brownie points are attached to them). One of the most interesting ones I have seen was recently, the “floor is lava” challenge from Amateurs 2025 CTF. I want to share my discovery in solving said challenge, step by step. What are we up against? (static) The first step is to identify the file. Using file(1) we get: nm(1) confirms lack of symbols: ➜ floor-is-lava nm chal nm: chal: no symbols The next step is to check the dynamic imports objdump(1) with
  6. A Shorthand for Distributed Systems Exploit Chains
    Oct 29, 2025 · original
    If you have been following the evolution of binary exploitation (and the exploit mitigations arms-race) of the past twenty or so years you can detect a certain pattern: where binary exploitation used to be quite straightforward , adding multiple possible layers of defense made it an exercise in chaining multiple exploit primitives in order to get the desired pwnage . Scoring vulnerabilities is also another area essential to follow: I am going to use CVSS v4 as my North Star here. CVSS properly defines an Environmental metric (CVSS-BE as a bare minimum, CVSS-BTE for the full monty) – allowing vulnerabilities to be ranked on a (subjective, granted) specific per environment impact basis. As systems became more distributed (your typical Web App these days might have a more complex architecture than your n-tier of the past, multiple components running in transient containers, in elastic infra
  7. The Great Berlin Startup Swindle
    Oct 20, 2025 · original
    Before anyone loses their mind over the title, let’s take a trip down the late 20th Century’s Punk Rock Lane. Sex Pistols were one of the most influential punk rock bands ever – it would not be a stretch that their influence does exist today. In a nutshell, the band became famous in a very short amount of time, gaining notoriety and spawning a gazillion copycats until they imploded. The unfortunate death of their bassist, the aptly named Sid Vicious made sure that no real return was possible. Malcolm McLaren, the bands manager has to take credit for a lot of the publicity, however his move to release the 1980 movie “The Great Rock ‘n’ Roll Swindle” where he claims that everything was manufactured by him from the get-go raised more than a few eyebrows. This was vehemently opposed by the remaining members of Sex Pistols and, personally, while I see the value and contributions of McLaren, t
  8. Percy Bysshe Shelley and the Coinbase Hack
    May 21, 2025 · original
    I have not gone off the deep end. Ozymandias, perhaps Shelley’s most famous work and the name of the main antagonist in Watchmen bear thematic similarities to the recent Coinbase hack. Keep reading and you will see why. Ozymandias (as the antagonist of Watchmen- if we can use a word in such a philosophically and spiritually loaded comic) near the climax of the story delivers the following line towards Rorschach and Nite Owl II “ I am not a Republican serial villain. Do you seriously think I’d explain my masterstroke if there remained the slightest chance of you affecting its outcome? I did it thirty-five minutes ago ”. Perfect and chilling. A well known cliche of action narratives is that the antagonist recites his plan before being foiled at the very last minute by the hero, roll credits. The author here not only challenges this but semi-breaks the fourth wall, challenging our assumptio
  9. 72 Seasons 2025 is open!
    Jan 26, 2025 · original
    Disclaimer: “72 Seasons” is the title of a Metallica record – I am using this title it for my f ree mentorship program for persons from disadvantaged backgrounds so Lars, do not sue bitte, bitte, bitte. So, this year I have space for 4 persons. Similar rules like last year: contact me, write me why you want a part of this and what do you want to learn. Those accepted, will gain access to my chat server – which in addition to 72 seasons members, hosts some really, really cool folks. The expansion of scope is for a variety of reasons: it is the second time I am doing this, I learned a lot about folk’s motivations last time as well as effective ways to convey information. By actively mentoring, I also learned a few things myself. I am not asking for a single dime. I work and I make enough and I would rather die than become one of them snake-oil merchants who will sell you a course and promi
  10. A Greek Elegy for Marshall Amplification
    Jan 26, 2025 · original
    Yes, the post is in Greek and yes, it is not computer related – not even remotely but here it goes. It appeared first on my Facebook feed – a lot of folks liked it so I am republishing here since, in general, my Facebook feed is not open to the general public. Νομιζω η Marshall δεν χρειαζεται συστασεις αλλα θα γραψω δυο λεξεις για τους μη επαιοντες. Βρεταννικη εταιρεια, διασημη για τους ενισχυτες κιθαρας της με εμβληματικο design και λογοτυπο. Πρακτικα, μια Les Paul σε εναν Marshall ειναι ο ηχος της ροκ μουσικης (φυσικα και υπαρχουν πολλοι περισσοτεροι αλλα ο συγκεκριμενος συνδυασμος ειναι ενα απο τα κλασσικα στανταρακια). Η ιστορια της εν λογω εταιρειας ειναι ικανη να γεμισει ενα βιβλιο κυριολεκτικα, εγω θα επικεντρωθω στην δικια μου, υποκειμενικη εξ’ ορισμου, εμπειρια μαζι της. Η Marshall ξαναπουληθηκε μεσα σε λιγα χρονια – αυτη τη φορα σε private equity απο Κινα. Οι παροικουντες την Ι

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_akostopoulos_blog_35f9b029316b2f15. More from this site: akostopoulos.blog in the Feeds tab.