Royce Williams
tychotithonus@infosec.exchange
<p>Just doing my undue diligence.</p><p>ISP vet (was AS7782, now AS8047), password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.</p><p>Day job: Enterprise Security Architect for an Alaskan ISP.</p><p>Obsessed with security keys:<br />techsolvency.com/mfa/security-keys</p><p>My 2017 <a href="https://infosec.exchange/tags/BSidesLV" class="mention hashtag" rel="tag">#<span>BSidesLV</span></a> talk "Password Cracking 201: Beyond the Basics":<br />youtube.com/watch?v=-uiMQGICeQY&t=20260s</p><p>Followed = probably stole you from someone I respect.</p><p>Blocked inadvertently? Ask!</p><p>Am I following a dirtbag? Tell me!</p><p>Suggestions welcome!</p><p
Posts
-
View post
That's such a good deal I should probably just pick up all four.
-
View post
Pre-auth RCE in Shrubbery tac_plus, common TACACS+ implementation. And perhaps underneath a number of commercial solutions that provide network authentication. No CVE yet. Goes back 25 years. "Shrubbery fixed it in F4.0.4.32, published on 21 September, and the Facebook fork is archived, so it will not be fixed at all." Write-up by discoverer: https://www.elttam.com/blog/att-cking-tacacs-to-pwnyour-network-via-a-pre-auth-rce Patched source: https://shrubbery.net/pub/tac_plus/ Edit...
-
View post
The "viral AI actress" is only "viral" because they paid someone to write a piece to call them "viral", and are manufacturing controversial features. It's still bullshit, just like the last time they tried to shop it. Don't give it oxygen.
-
View post
The mocktail page of this menu is headed "Absence of Proof".
-
View post
@lzg@mastodon.social /me nods in Alaskan
-
View post
So the Transcend flash-IDE drives (to replace spinning rust in legacy computers) ... pretend they support SMART, but all the values are zero, so you can't tell actual power-on hours, etc.?
-
View post
All part of this Turing-complete breakfast!
-
View post
RE: https://mastodon.social/@campuscodi/117128474535423979 Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic "starve it, then declare it ineffective" tactic. ๐
-
View post
Proofpoint appears to have commissioned these custom Lego minifigs, probably as conference schwag or similar. I think it was probably 10 to 15 years ago? Does anyone know if there are any variants beyond these? (Updated with better photo of the ones I have learned of so far) (See replies for a few more) #Lego #minifigs
-
View post
Having this printed out on the wall behind where I normally join calls, and being able to point to it when its bingo square comes up in discussion, continues to pay dividends, @mcc@mastodon.social Edit: original post (credit where due!): https://mastodon.social/@mcc/115079977230405147
-
View post
That's a new one. (Voicemail transcription)
-
View post
Hey, cracking folk ... did you know that Hashtopolis 1.0.0 was just released? https://github.com/hashtopolis/server/releases/tag/v1.0.0 Total redesign, SPA based on TailwindCSS, Postgres support, Docker driven, full REST API, OAUTH2, improved supertasks, full UTF-8 support. Did a fresh install, working great so far! Thanks to @s3inlc and team!
-
View post
RE: https://mastodon.social/@yaelwrites/117050291391403485 New security goals unlocked. "So secure people think it's fake" ๐ก
-
View post
No shade or anything, but I do not understand the urge to wear an Emirates shirt. It just looks like you like an airline.
-
View post
Bring back the Password Village at DEF CON! They help so many practitioners a year bootstrap from having zero cracking clue to actually getting it. That team works their butts off the whole con, often with minimal or zero external sponsorship, paying for a lot of stuff totally out of pocket, year after year, just to grow the practice and see the light bulb go off over somebody's head (when they realize that it's not just all about rainbow tables and how many GPUs you have). And the eff...
-
View post
Good afternoon to everyone except the vendor who decided that "[dayjob name] - scraping issues" as a subject line, sent to my non-dayjob email, was a good way to solicit business.
-
View post
Just got my first "YouTube detected this screenshot" Android notification. ๐ฑ
-
View post
All of the major third parties you rely on ... are constantly trying to reduce their dependency on third parties. Some dependencies are inevitable. Which of your third parties can prove they are actively reducing entire classes of the risk they expose you to?
-
View post
We are living through the AI-accelerated death of security through obscurity. Which is forcing us to learn what turns out to have always been the true definition of obscurity: every possible variant of obscurity, whether deliberate or accidental. Every gap between our theoretical or practical understanding of a security model ... and its underlying reality. The maximum worst-case impact of every scrap of potential technical debt ... now has a looming balloon payment. Only the "assume eve...
-
View post
Uh ... Routledge / Vitalsource, you're obviously operating from a strange usage of the word "perpetual" that I wasn't previously aware of.
-
View post
Happy Sysadmin Day, to the folks who were SRE before SRE was a thing. And this is my favorite inspirational sysadmin quote, from The Practice of System and Network Administration by Limoncelli, Chalup, and Hogan: A Concise Definition A facility had several researchers from a variety of universities visiting for the summer. That autumn, after they left, the SAs had to decommission their computers and clean the large room they had been sharing. The SAs found a scrap of paper that had been tape...
-
View post
It's gonna be ... hard to get one of this year's DEF CON badges for the security-key collection.
-
View post
Between Hoyt Axton's "Della and the Dealer" and Conway Twitty's "Saturday Night Special", I seem to have an affinity for stories where good folk have to get tough with the bad folk in defense of a cutie ... and then high-tail it for the hinterlands with said cutie.
-
View post
The purpose of Stauer, Danbury Mint, Bradford Exchange, Lillian Vernon, the various "coin exchanges" / "mints", etc is to extract 90% markup from people who can't shop in person anymore and/or have no sense of actual market value. And newspapers, magazines, and TV stations that run their ads are complicit in the victimization of a vulnerable population.
-
View post
Update on the FreeBSD ports cleanup after someone committed a 150M blob of the Linux Copilot CLI: https://people.freebsd.org/~kevans/core/ports-freeze-final.txt.asc Good as far as it goes, especiallly the striving for transparency, reproducibility, and minimizing downstream impacts. Notably missing, however: an explanation of how it happened in the first placeconcrete steps that will be taken to prevent it from happen again #FreeBSD
-
View post
Looking forward the day when a RU-associated threat actor gets the code name "BOUNTY BEAR" https://m.youtube.com/watch?v=kKhzsx2gVgM (and RIP Sam Neill)
-
View post
Well, that's disappointing.
-
View post
So is Google's new "Selfie Sign-In" just a single factor? And it looks like it's not available if you have Advanced Protection enabled? https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/ Why doesn't the announcement mention any of this?
-
View post
Add ID.me to the list of services that think it's a good idea to use third-party link tracking for password reset links. You are incenting the opposite of good security awareness. And you are not some random tiny website. Your entire fscking business is supposed to be secure authentication. Do better.
-
View post
@thedarktangent@defcon.social I gotta defer to @sc00bz@infosec.exchange on this one, and his comparison calculator: https://tobtu.com/rtcalc.php