<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Linkdump on Designing Secure Software</title>
    <link>https://designingsecuresoftware.com/tags/linkdump/</link>
    <description>Recent content in Linkdump on Designing Secure Software</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Tue, 05 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://designingsecuresoftware.com/tags/linkdump/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>April 2026 Link dump</title>
      <link>https://designingsecuresoftware.com/writings/2026apr/</link>
      <pubDate>Tue, 05 May 2026 00:00:00 +0000</pubDate>
      <guid>https://designingsecuresoftware.com/writings/2026apr/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;Anthropic Mythos: security superpowers?&lt;/li&gt;&#xA;&lt;li&gt;Threat model scope matters&lt;/li&gt;&#xA;&lt;li&gt;Anyone ready for quantum break in 2029?&lt;/li&gt;&#xA;&lt;li&gt;Trains with 5G windows and noise-cancelling cabins: only in Japan&lt;/li&gt;&#xA;&lt;li&gt;The NAND gate of continuous mathematics: all elementary functions from one operator&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Anthropic holding back Mythos because they claim it has &lt;a href=&#34;https://red.anthropic.com/2026/mythos-preview/&#34;&gt;extraordinary powers to discover security flaws&lt;/a&gt; (whether the claims hold up or not) was a master marketing/PR move. It instantly made a big splash, generated great demand, and as a side effect it at least made the software security community wonder, &amp;ldquo;what if it&amp;rsquo;s true?&amp;rdquo; Naturally, there are all kinds of &lt;a href=&#34;https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html&#34;&gt;opinions&lt;/a&gt;, &lt;a href=&#34;https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/&#34;&gt;rebuttals&lt;/a&gt;, and &lt;a href=&#34;https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv92.pdf&#34;&gt;reactions&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>March 2026 Link dump</title>
      <link>https://designingsecuresoftware.com/writings/2026mar/</link>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://designingsecuresoftware.com/writings/2026mar/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;Google security methodology compendium&lt;/li&gt;&#xA;&lt;li&gt;Threat modeling&lt;/li&gt;&#xA;&lt;li&gt;Are attacks the only threat?&lt;/li&gt;&#xA;&lt;li&gt;Why is threat modeling ignored?&lt;/li&gt;&#xA;&lt;li&gt;Miscellaneous&lt;/li&gt;&#xA;&lt;li&gt;e16n next Stage 4&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Google is sharing a lot of their impressive security methodology in a recent collection of articles: &lt;a href=&#34;https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/how-google-does-it-security-series/&#34;&gt;How Google Does It: An inside look at cybersecurity&lt;/a&gt;. Of special interest to me: &lt;a href=&#34;https://cloud.google.com/transform/how-google-does-it-threat-modeling-from-basics-to-ai&#34;&gt;Threat modeling, from basics to AI&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>February 2026 Link dump</title>
      <link>https://designingsecuresoftware.com/writings/2026feb/</link>
      <pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://designingsecuresoftware.com/writings/2026feb/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;On &amp;ldquo;the end of security bugs&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;STRIPPED&lt;/li&gt;&#xA;&lt;li&gt;Incident response threat modeling?&lt;/li&gt;&#xA;&lt;li&gt;Using CSS and PDF as emulators running code&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.anthropic.com/news/claude-code-security&#34;&gt;Claude Code Security has people predicting the end of security bugs as we know them&lt;/a&gt;&#xA;I can&amp;rsquo;t imagine &lt;em&gt;anything&lt;/em&gt; in the forseeable future doing that&#xA;because all software has bugs, and vulnerabilities are by definition&#xA;a subset of all the bugs (in a properly designed system).&#xA;Bug-free code seems computationally infeasible for large systems,&#xA;if only for the amount of testing required to confirm there are no bugs.&#xA;What am I missing, or is it AI hype?&lt;/p&gt;</description>
    </item>
    <item>
      <title>January 2026 Link dump</title>
      <link>https://designingsecuresoftware.com/writings/2026jan/</link>
      <pubDate>Sun, 01 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://designingsecuresoftware.com/writings/2026jan/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;on &amp;ldquo;Bitlocker, the FBI, and Risk&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;threat models to address hacklore&lt;/li&gt;&#xA;&lt;li&gt;software bloat&lt;/li&gt;&#xA;&lt;li&gt;software update release quality&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
