Elektrine lite

โ† Feed

Royce Williams

tychotithonus@infosec.exchange

<p>Just doing my undue diligence.</p><p>ISP vet (was AS7782, now AS8047), password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.</p><p>Day job: Enterprise Security Architect for an Alaskan ISP.</p><p>Obsessed with security keys:<br />techsolvency.com/mfa/security-keys</p><p>My 2017 <a href="https://infosec.exchange/tags/BSidesLV" class="mention hashtag" rel="tag">#<span>BSidesLV</span></a> talk &quot;Password Cracking 201: Beyond the Basics&quot;:<br />youtube.com/watch?v=-uiMQGICeQY&amp;t=20260s</p><p>Followed = probably stole you from someone I respect.</p><p>Blocked inadvertently? Ask!</p><p>Am I following a dirtbag? Tell me!</p><p>Suggestions welcome!</p><p

Posts

  • View post

    That&#39;s such a good deal I should probably just pick up all four.

  • View post

    Pre-auth RCE in Shrubbery tac_plus, common TACACS+ implementation. And perhaps underneath a number of commercial solutions that provide network authentication. No CVE yet. Goes back 25 years. &quot;Shrubbery fixed it in F4.0.4.32, published on 21 September, and the Facebook fork is archived, so it will not be fixed at all.&quot; Write-up by discoverer: https://www.elttam.com/blog/att-cking-tacacs-to-pwnyour-network-via-a-pre-auth-rce Patched source: https://shrubbery.net/pub/tac_plus/ Edit...

  • View post

    The &quot;viral AI actress&quot; is only &quot;viral&quot; because they paid someone to write a piece to call them &quot;viral&quot;, and are manufacturing controversial features. It&#39;s still bullshit, just like the last time they tried to shop it. Don&#39;t give it oxygen.

  • View post

    The mocktail page of this menu is headed &quot;Absence of Proof&quot;.

  • View post

    @lzg@mastodon.social /me nods in Alaskan

  • View post

    So the Transcend flash-IDE drives (to replace spinning rust in legacy computers) ... pretend they support SMART, but all the values are zero, so you can&#39;t tell actual power-on hours, etc.?

  • View post

    All part of this Turing-complete breakfast!

  • View post

    RE: https://mastodon.social/@campuscodi/117128474535423979 Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic &quot;starve it, then declare it ineffective&quot; tactic. ๐Ÿ˜ 

  • View post

    Proofpoint appears to have commissioned these custom Lego minifigs, probably as conference schwag or similar. I think it was probably 10 to 15 years ago? Does anyone know if there are any variants beyond these? (Updated with better photo of the ones I have learned of so far) (See replies for a few more) #Lego #minifigs

  • View post

    Having this printed out on the wall behind where I normally join calls, and being able to point to it when its bingo square comes up in discussion, continues to pay dividends, @mcc@mastodon.social Edit: original post (credit where due!): https://mastodon.social/@mcc/115079977230405147

  • View post

    That&#39;s a new one. (Voicemail transcription)

  • View post

    Hey, cracking folk ... did you know that Hashtopolis 1.0.0 was just released? https://github.com/hashtopolis/server/releases/tag/v1.0.0 Total redesign, SPA based on TailwindCSS, Postgres support, Docker driven, full REST API, OAUTH2, improved supertasks, full UTF-8 support. Did a fresh install, working great so far! Thanks to @s3inlc and team!

  • View post

    RE: https://mastodon.social/@yaelwrites/117050291391403485 New security goals unlocked. &quot;So secure people think it&#39;s fake&quot; ๐Ÿ’ก

  • View post

    No shade or anything, but I do not understand the urge to wear an Emirates shirt. It just looks like you like an airline.

  • View post

    Bring back the Password Village at DEF CON! They help so many practitioners a year bootstrap from having zero cracking clue to actually getting it. That team works their butts off the whole con, often with minimal or zero external sponsorship, paying for a lot of stuff totally out of pocket, year after year, just to grow the practice and see the light bulb go off over somebody&#39;s head (when they realize that it&#39;s not just all about rainbow tables and how many GPUs you have). And the eff...

  • View post

    Good afternoon to everyone except the vendor who decided that &quot;[dayjob name] - scraping issues&quot; as a subject line, sent to my non-dayjob email, was a good way to solicit business.

  • View post

    Just got my first &quot;YouTube detected this screenshot&quot; Android notification. ๐Ÿ˜ฑ

  • View post

    All of the major third parties you rely on ... are constantly trying to reduce their dependency on third parties. Some dependencies are inevitable. Which of your third parties can prove they are actively reducing entire classes of the risk they expose you to?

  • View post

    We are living through the AI-accelerated death of security through obscurity. Which is forcing us to learn what turns out to have always been the true definition of obscurity: every possible variant of obscurity, whether deliberate or accidental. Every gap between our theoretical or practical understanding of a security model ... and its underlying reality. The maximum worst-case impact of every scrap of potential technical debt ... now has a looming balloon payment. Only the &quot;assume eve...

  • View post

    Uh ... Routledge / Vitalsource, you&#39;re obviously operating from a strange usage of the word &quot;perpetual&quot; that I wasn&#39;t previously aware of.

  • View post

    Happy Sysadmin Day, to the folks who were SRE before SRE was a thing. And this is my favorite inspirational sysadmin quote, from The Practice of System and Network Administration by Limoncelli, Chalup, and Hogan: A Concise Definition A facility had several researchers from a variety of universities visiting for the summer. That autumn, after they left, the SAs had to decommission their computers and clean the large room they had been sharing. The SAs found a scrap of paper that had been tape...

  • View post

    It&#39;s gonna be ... hard to get one of this year&#39;s DEF CON badges for the security-key collection.

  • View post

    Between Hoyt Axton&#39;s &quot;Della and the Dealer&quot; and Conway Twitty&#39;s &quot;Saturday Night Special&quot;, I seem to have an affinity for stories where good folk have to get tough with the bad folk in defense of a cutie ... and then high-tail it for the hinterlands with said cutie.

  • View post

    The purpose of Stauer, Danbury Mint, Bradford Exchange, Lillian Vernon, the various &quot;coin exchanges&quot; / &quot;mints&quot;, etc is to extract 90% markup from people who can&#39;t shop in person anymore and/or have no sense of actual market value. And newspapers, magazines, and TV stations that run their ads are complicit in the victimization of a vulnerable population.

  • View post

    Update on the FreeBSD ports cleanup after someone committed a 150M blob of the Linux Copilot CLI: https://people.freebsd.org/~kevans/core/ports-freeze-final.txt.asc Good as far as it goes, especiallly the striving for transparency, reproducibility, and minimizing downstream impacts. Notably missing, however: an explanation of how it happened in the first placeconcrete steps that will be taken to prevent it from happen again #FreeBSD

  • View post

    Looking forward the day when a RU-associated threat actor gets the code name &quot;BOUNTY BEAR&quot; https://m.youtube.com/watch?v=kKhzsx2gVgM (and RIP Sam Neill)

  • View post

    Well, that&#39;s disappointing.

  • View post

    So is Google&#39;s new &quot;Selfie Sign-In&quot; just a single factor? And it looks like it&#39;s not available if you have Advanced Protection enabled? https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/ Why doesn&#39;t the announcement mention any of this?

  • View post

    Add ID.me to the list of services that think it&#39;s a good idea to use third-party link tracking for password reset links. You are incenting the opposite of good security awareness. And you are not some random tiny website. Your entire fscking business is supposed to be secure authentication. Do better.

  • View post

    @thedarktangent@defcon.social I gotta defer to @sc00bz@infosec.exchange on this one, and his comparison calculator: https://tobtu.com/rtcalc.php