Avatar
Ian Campbell 🏴
a516f2358a20a90c560bed25b34fb39ee5bd12a7187837df8c96a19e0070ce6d
Security ops engineer for DomainTools, DT Investigations threat researcher, writer, voracious reader. he/him. Fan of good trouble. Opinions here mine only. No LLM content from me, all flaws detected are human-generated. Autistic/depressed/anxious/hungry. #infosec #cybersecurity #privacy #actuallyautistic #neurodivergent

nostr:npub1q2xak5mfrp36unklpx7kfshsadxsafqr4s79xg5p207f6w5vhudq46jpej If you haven't encountered it yet, I highly recommend Mozilla's "Multi-Account Containers" plugin for Firefox - takes a minute or two of setup but lets you silo browsing in a very gratifying manner.

Me, nearly thirty years ago. Age 15 or so.

The greatest trick the devil ever pulled was

making a messenger service out of Sharepoint, calling it Teams, and making it popular with bean counters.

nostr:npub1cys3t4rnxstcld66zq9q5xnwsludqx0q7vdr3x3em7dcxc6d3weqttaf48 Thank *YOU*! Coming up in IT support but being hungry for security, it made such a difference watching you talk about empathy and the centrality of people. Now that I'm in security it's been a game-changer.

fuckin cloudflare...

Been a while since I've had an actual curated thread of interesting reads. Here are a few, with Recorded Future's 'The Record' absolutely dominating this week with some great reporting.

Attackers use EvilProxy phishing kit to take over executives’ Microsoft 365 accounts - https://therecord.media/evilproxy-phishing-kit-targets-ceos-executives

IRS confirms takedown of bulletproof hosting provider Lolek - https://therecord.media/lolek-bulletproof-hosting-seizure-fbi-irs

Next-gen OSDP was supposed to make it harder to break in to secure facilities. It failed. - https://arstechnica.com/security/2023/08/next-gen-osdp-was-supposed-to-make-it-harder-to-break-in-to-secure-facilities-it-failed/

New Downfall attacks on Intel CPUs steal encryption keys, data - https://www.bleepingcomputer.com/news/security/new-downfall-attacks-on-intel-cpus-steal-encryption-keys-data/

Lawsuit: ByteDance’s CapCut app secretly reaps massive amounts of user data - https://therecord.media/capcut-privacy-lawsuit-illinois-bipa-bytedance-china

Tunnel Vision: CloudflareD AbuseD in the WilD - https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/

nostr:npub1756rerytkxdwvjfe5ffmpryws2pvxqfkafkjg7474jxwuguaextq7qpuzs definitely appreciate you sharing that info, thank you. It’s a world I have very little experience in.

This is some wicked neat solutions thinking and sharing: Target EasySweep card skimmer detection

https://tech.target.com/blog/cybersecurity-easysweep

This is true for you too.

As I've seen elsewhere, "you deserve environments that bring out the softness in you."

(image filched from FB)

i'm gonna have an aneurysm.

32 bits derived from system clock time.

they secured the wallets with...a timestamp?

"the milksad vulnerability is absolutely wild, a bunch of bitcoin wallets have been drained over the last few months because a libbitcoin tool was generating root entropy with a mersenne twister seeded with 32 bits (yes, bits) derived from system clock time https://milksad.info "

https://twitter.com/isislovecruft/status/1689331203684577280