Post #2855099
2026-01-29 01:03 UTC
@thedarktangent@defcon.social I thought it would be really neat to crowd-source a graph database of this stuff. Nodes would be services (gmail, iCloud, your own mail server), edges would be attack vectors (password reset, social engineer support, brute force something, etc). Any person could select the nodes that are important in their life and then run analyses. E.g. my main email is yahoo.com, my web site is blah, my registrar is blah. Edges have various attributes like cost in time, cost in money, noise level/detectability, etc.
Then, using some kind of path/graph logic, an individual (or business) can chart the shortest (or easiest, or cheapest) path from a starting point to an end point. If I compromise a domain registrar for example.net, how many steps am I from getting access to bob@example.net’s google drive?
The idea behind crowdsourcing is to capture attributes of the various services: password recovery for this mobile phone provider is SMS and birthdate. Password recovery for this bank is a recent statement amount and last 4 of the account number. People would enter (and the system would somehow store) what they knew for various service providers so that over time we build and maintain all the nodes, Wikipedia style. And then anyone who also uses a certain provider benefits from the data in their graph.
Events like the recent bitlocker key disclosure revelation from Microsoft change the graph. Suddenly there is a path to something where previously we didn’t have one in the graph. A provider switching from TOTP to passkeys would change its properties and, thus, a bunch of graphs and paths.
I just don’t have the brains or the time to implement it. But it seems fun.
Replies (0)
No replies.