Royce Williams
tychotithonus@infosec.exchange
<p>Just doing my undue diligence.</p><p>ISP vet (was AS7782, now AS8047), password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.</p><p>Day job: Enterprise Security Architect for an Alaskan ISP.</p><p>Obsessed with security keys:<br />techsolvency.com/mfa/security-keys</p><p>My 2017 <a href="https://infosec.exchange/tags/BSidesLV" class="mention hashtag" rel="tag">#<span>BSidesLV</span></a> talk "Password Cracking 201: Beyond the Basics":<br />youtube.com/watch?v=-uiMQGICeQY&t=20260s</p><p>Followed = probably stole you from someone I respect.</p><p>Blocked inadvertently? Ask!</p><p>Am I following a dirtbag? Tell me!</p><p>Suggestions welcome!</p><p
Posts
-
Post #4484895
That's a new one. (Voicemail transcription)
-
Post #4484894
Hey, cracking folk ... did you know that Hashtopolis 1.0.0 was just released? https://github.com/hashtopolis/server/releases/tag/v1.0.0 Total redesign, SPA based on TailwindCSS, Postgres support, Docker driven, full REST API, OAUTH2, improved supertasks, full UTF-8 support. Did a fresh install, working great so far! Thanks to @s3inlc and team!
-
Post #4484893
RE: https://mastodon.social/@yaelwrites/117050291391403485 New security goals unlocked. "So secure people think it's fake" 💡
-
Post #4484892
No shade or anything, but I do not understand the urge to wear an Emirates shirt. It just looks like you like an airline.
-
Post #4484891
Bring back the Password Village at DEF CON! They help so many practitioners a year bootstrap from having zero cracking clue to actually getting it. That team works their butts off the whole con, often with minimal or zero external sponsorship, paying for a lot of stuff totally out of pocket, year after year, just to grow the practice and see the light bulb go off over somebody's head (when they realize that it's not just all about rainbow tables and how many GPUs you have). And the eff...
-
Post #4399918
Good afternoon to everyone except the vendor who decided that "[dayjob name] - scraping issues" as a subject line, sent to my non-dayjob email, was a good way to solicit business.
-
Post #4386284
Just got my first "YouTube detected this screenshot" Android notification. 😱
-
Post #4376155
All of the major third parties you rely on ... are constantly trying to reduce their dependency on third parties. Some dependencies are inevitable. Which of your third parties can prove they are actively reducing entire classes of the risk they expose you to?
-
Post #4374421
We are living through the AI-accelerated death of security through obscurity. Which is forcing us to learn what turns out to have always been the true definition of obscurity: every possible variant of obscurity, whether deliberate or accidental. Every gap between our theoretical or practical understanding of a security model ... and its underlying reality. The maximum worst-case impact of every scrap of potential technical debt ... now has a looming balloon payment. Only the "assume eve...
-
Post #4284255
Uh ... Routledge / Vitalsource, you're obviously operating from a strange usage of the word "perpetual" that I wasn't previously aware of.
-
Post #4281347
Happy Sysadmin Day, to the folks who were SRE before SRE was a thing. And this is my favorite inspirational sysadmin quote, from The Practice of System and Network Administration by Limoncelli, Chalup, and Hogan: A Concise Definition A facility had several researchers from a variety of universities visiting for the summer. That autumn, after they left, the SAs had to decommission their computers and clean the large room they had been sharing. The SAs found a scrap of paper that had been tape...
-
Post #4279975
It's gonna be ... hard to get one of this year's DEF CON badges for the security-key collection.
-
Post #4127008
Between Hoyt Axton's "Della and the Dealer" and Conway Twitty's "Saturday Night Special", I seem to have an affinity for stories where good folk have to get tough with the bad folk in defense of a cutie ... and then high-tail it for the hinterlands with said cutie.
-
Post #4115314
The purpose of Stauer, Danbury Mint, Bradford Exchange, Lillian Vernon, the various "coin exchanges" / "mints", etc is to extract 90% markup from people who can't shop in person anymore and/or have no sense of actual market value. And newspapers, magazines, and TV stations that run their ads are complicit in the victimization of a vulnerable population.
-
Post #4070055
Update on the FreeBSD ports cleanup after someone committed a 150M blob of the Linux Copilot CLI: https://people.freebsd.org/~kevans/core/ports-freeze-final.txt.asc Good as far as it goes, especiallly the striving for transparency, reproducibility, and minimizing downstream impacts. Notably missing, however: an explanation of how it happened in the first placeconcrete steps that will be taken to prevent it from happen again #FreeBSD
-
Post #4041702
Looking forward the day when a RU-associated threat actor gets the code name "BOUNTY BEAR" https://m.youtube.com/watch?v=kKhzsx2gVgM (and RIP Sam Neill)
-
Post #4039302
Well, that's disappointing.
-
Post #4035311
So is Google's new "Selfie Sign-In" just a single factor? And it looks like it's not available if you have Advanced Protection enabled? https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/ Why doesn't the announcement mention any of this?
-
Post #3967599
Add ID.me to the list of services that think it's a good idea to use third-party link tracking for password reset links. You are incenting the opposite of good security awareness. And you are not some random tiny website. Your entire fscking business is supposed to be secure authentication. Do better.
-
Post #3944787
@thedarktangent@defcon.social I gotta defer to @sc00bz@infosec.exchange on this one, and his comparison calculator: https://tobtu.com/rtcalc.php
-
Post #3934647
So some SABRE manager (likely) overrode a programmer's recommendation to include a field for middle initial 60 years ago, so I just get to be called RoyceD Williams for the rest of my travel life?
-
Post #3908113
Hyphens, what are they even for 🤷
-
Post #3858456
TFW you UPS overnight something and you see it being processed in the recipient's actual hometown, ... and then get routed two states away -- not for central processing reasons, but "We've incorrectly sorted this package which may cause a delay" 😭
-
Post #3834385
Add Chime to the list of services that don't validate possession of email before using it. I just got someone's direct deposit enrollment.
-
Post #3805672
Missed this on the 9th: https://www.yubico.com/blog/openai-mandates-hardware-backed-passkeys-for-trusted-access-cyber-members-to-log-into-chatgpt-accounts/ starting September 1, all individual members of Trusted Access for Cyber (TAC) must enable Advanced Account Security using a hardware-backed passkey to retain access to frontier cyber models.
-
Post #3794943
RE: https://infosec.exchange/@DaveMWilburn/116914517119717634 Proof number 385 that the actual goal is the opposite of the stated goal.
-
Post #3793327
I have never heard of a " yellow team". I mean, if you mix red and blue, don't you get purple? I've only ever heard of this called purple teaming.
-
Post #3764357
Movie scene where there's an airplane, rough but manageable water landing, and the cabin is chaos, and dude grabs the nearest inflatable vest and it's the one labeled DEMO ONLY
-
Post #3764181
If you're filming a commercial using actors and characters from The Office, but you're not filming it in the "no one knows why this is a documentary" style ... what are you even doing
-
Post #3759383
Extrapolating from a couple of interesting recent Discord threads about whether laws like GDPR could compel an operator to reveal an individual's password hash ... If unsalted, the responding org might be resistant to revealing that the hash is unsalted (and therefore weak), which it could be argued would be security by obscurity that a regulator might reject (if they were aware of the nuance), and therefore unjustified Even if salted, divulging the hash doesn't reveal anything to the...