Shostack + Friends Blog

 

Appsec roundup - April 2026

The importance of slow time in work is a theme for April, along with how Claude optimized away its own security rules. Also fun games collected at RSA! a photograph of a robot, sitting in a library, working on a jigsaw puzzle. The robot holds up the jigsaw puzzle

This month leads off with Buying Back Our Slack and Which Way Is Downhill?, both by Ryan Moser. The first considers the impact on AI on work, the second how people work in large systems. (I would argue slightly with the framing of the first: work like building a deck or writing tests are not “cognitive rest” but a chance to reflect on our work and “sensemake.”)

Both have a great deal to say about application security, if you take time and think about them. But if you don’t want to do that, articles by Stephen de Vries, the Cloudflare sandbox, and Robert Hansen’s Thoughts on PQC are all thoughtful bits. On the other hand, NIST doesn’t have time to stop and think about all the vulnerabilities anymore.

Threat Modeling

Appsec

AI

Regulation

Quantum 🔥

  • Robert J. Hansen has Thoughts on PQC (Post Quantum Cryptography). He is not kind to people who have gone beyond earning skepticism to earning scorn.
Secure By Design Story cards, Magic cards from Cribl, and Pentest
Blitz

Games Received

  • Finite State’s Pentest Blitz.
  • Bob Lord’s Secure By Design Storycards.
  • A set of Magic: The Gathering cards which I believe are from Cribl, but they’re very minimally branded and I can’t find anything about them online.

Shostack + Associates News


Image by midjourney: ”a photograph of a robot, sitting in a library, working on a jigsaw puzzle. The robot is spotlighted by light streaming in through a small window"