Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

JohnsNotHere

@JohnsNotHere@infosec.exchange
  • Open on infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV.

I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

0 Followers
0 Following
12 Posts
Joined August 24, 2018
EliteSec Consulting:
https://elitesec.io

Posts

Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · 6d ago
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Replying to @JohnsNotHere@infosec.exchange
To be fair, I'm looking at this stuff form a pentesters perspective, not a corporate security perspective, so my use case is different and I'm not installing agents on my client's machines. Also this is just one part of the process, I don't take any vulnerability scanners results as the final word, but it does help speed things up if it's accurate. When stuff is missed, I have to do a deeper dive with manual checks, which just takes time that I don't always have.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · 6d ago
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
What exactly am I missing? I remember OpenVAS/Greenbone being this clunky, entry-level vulnerability scanner that took forever to setup. Nessus was the gold standard, and the masochists went with Qualys or Rapid7 for different reasons. I've used Nessus, Qualys, and Greenbone for the past few years, and now I have opinions. I actually moved to Kaseya's VulScanner last year, and I loved it for all the wrong reasons. It was easy to setup as a Docker image, meaning I could install it in a VM without much fuss. It worked well, but had a habit of eating disk space. I found out after about 3 months that it's just running Greenbone/OpenVAS under the covers, albeit with a nicer UI. I was happy. I recently did some subcontracting work with another firm, and they were also using Greenbone/OpenVAS, albeit the commercial version with a commercial feed. Lots of interesting findings. I decided to scan the same systems with VulScanner, but I didn't even come up with half the results. Odd. I reached out to Kaseya, and they confirmed that they are only using the community feeds, and the specific vulnerabilities I flagged as "missing" from their scan are just not in the free feed. I was paying like $350 / month for their software. Yes, I had support and an easier UI/setup than a generic OpenVAS/Greenbone install, but the number of missing findings was shocking. I then downloaded a trial of Nessus Expert, because Nessus Professional won't let you scan external targets. Oh, and Expert is a good $2,000 more expensive for the privilege. Guess what? Same type of results as what I saw from the free feed of Greenbone/OpenVAS. So yeah, I could spend around $10.5k CAD for Nessus Expert, or about $4.5k CAD for OpenVAS/Greenbone BASIC with their enterprise feed. For the sake of my clients, I'll spend the extra cash. Seriously, am I missing something? I'm not new to Nessus, and I'm trying a few different scans to find similar findings, but no luck. Is this just a case of Tenable being comfortable in their position that they just let things slide, or am I just missing something? Great example, the target I'm scanning has an outdated version of Grafana installed. Commercial version of Greenbone/OpenVAS catches it, but the free version does not. Likewise, Nessus ignores it completely as well. A manual scan would catch it for sure, but why am I paying for a commercial tool that doesn't actually find something so basic? It's literally running on port 443 under /grafana!
1
1
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Aug 03, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Remember, Joey is not an addict. #hackers
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 30, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Man there are gatekeepers everywhere. I'm part of a few vCISO groups, joined back when I offered vCISO services (it didn't work out, but that's a longer story). One of these groups had a meetup in a nearby city, so I decided to go. This was last year, but it still bothers me. I knew only a few folks, but it was essentially a giant group of strangers for me. I did meet some folks, but the one big thing I noticed was the cliques and established barriers to conversations with other people. When I said I ran a pentesting company, it was if I was a leper. "Oh, how interesting!", then getting ignored and the group closing off. It was such a group of elitists who were staying with their former CISOs hanging out acting like they saved the world. I get it, I'm just part of that world, but I did spend a few years as a CSO for a company and spent a fair amount of time doing the hard work before I started my company. Don't get me wrong, I also met a few very kind folks who I still stay in contact with, but that was the minority in a group of posers. This isn't the community I embraced nearly 20 years ago. I understand that executives think different and CISO gigs are hard, but if you're selling fractional services or vCISO, I would have thought having more contacts would be better. But no. I no longer participate with these groups. I don't try to sell my services to members, but in the past I would reach out if someone asked. It was good for the most part, and I have one vCISO who I've worked well with for a few years now. It just sucks to see the "larger, more famous" former CISOs acting like their the new prom king/queen and ice people out. Sorry, feeling ranty today.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 27, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Replying to @JohnsNotHere@infosec.exchange
Looking at my electric bill, I'm also using significantly less energy with this heat pump than I was with my AC. I understand that the bill will be higher in the winter due to the increased usage, but my gas bill will be lower too, so it's a bit of a wash. Honestly, I'll take the savings as is. I won't say that heat pump is great for everyone, but for me I'm feeling good about my particular choice. Oh yeah, and for my fellow Canadians, fuck Reliance.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 27, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
My AC and furnace apparently decided to conk out at me at the same time. Long story, but suffice it to say that I needed to replace both. I used to rent them, but found out my agreement expired a year ago and they never told me - basically no warranty work, only a new 7 year contract. No thanks. I've moved to a heat pump with a furnace as a backup heating unit for cold Canadian winters, and I must say that I'm impressed. I splurged on the system, but I regret nothing. This is my 3rd furnace in 25 years, so yeah, I'm not going cheap anymore. I love my heat pump. This thing is quiet! I mean, holy crap it's quiet. I've had a central air unit for decades, and that sucker was loud. This heat pump is super quiet, doesn't shake or rumble the house (it's attached via a mount to the wall), and cools very well. I absolutely love this thing. I look forward to see how things work out in the winter, but I'm happy so far.
1
1
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 22, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange A modern funding pitch I see.
3
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 17, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
I'm not going to lie, there are days I miss working with coworkers or just having close friends I can talk to about work stuff. I do have my wife, but she's off visiting family, and I'm not going to bug her. Ah well, I'm old enough to know I can wait a few days, but reality is a bitch sometimes and some things can't be shared on the wider Internet.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 08, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Replying to @marcotietz@infosec.exchange
@marcotietz@infosec.exchange Yeah, he started strong but faded fast. Not going to move forward because of it. Lots of talented drywallers around, so I'm not worried.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 08, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
I had a general contractor admit to me that he completely forgot about my request because he had other jobs on the go. Nothing major, just some roof flashing that needed to be repaired and some drywall on my garage ceiling that had some water damage from the rain due to the flashing. He couldn't find a roofing contractor willing to quote the job because it was too small. So I found my own roofer to fix it, and now he wants to do the drywall, but can't get to me until August because he's busy with his other 2 clients. No quote yet either. I may just find someone else because my faith in him is not high. I understand being busy, and I've had my share of dropping the ball on prospects, but this is something else entirely. Not a great sense of professionalism. Not a young guy either, he's older, likely past or close to retirement, but apparently still wants to run the business. Whatever. I'm looking elsewher I think.
0
1
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jul 03, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Don't blink first. That's the rule. Wait it out and trust your instincts.
0
0
0
0
Open post
JohnsNotHere
JohnsNotHere @JohnsNotHere@infosec.exchange · Jun 27, 2026
JohnsNotHere
@JohnsNotHere@infosec.exchange

Infosec practitioner, Founder of EliteSec (https://elitesec.io), podcaster, father, and knowledge junkie. Defender of the Oxford comma, and lover of good BBQ. Posts are my own, but YMMV. I toot about #cybersecurity topics and #entrepreneurship, plus random thoughts in between.

infosec.exchange
Never doubt your worth, and don't let anyone else dictate what it is or diminish your value in yourself. Find allies to validate your thoughts, but first and foremost stay true to yourself.
0
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:55:01 UTC