Chris's Avatar

Chris

@brompwnie.bsky.social

Likes to hack things. GitHub.com/brompwnie

316 Followers  |  272 Following  |  18 Posts  |  Joined: 25.05.2023  |  1.8936

Latest posts by brompwnie.bsky.social on Bluesky

Dependabot's implementation of Go modules continues to be poor.

FWIW, I recommend Go projects just turn it off, run govulncheck in a scheduled GitHub Action for security updates, and otherwise update dependencies manually when it makes sense in their release cycle.

14.03.2025 09:01 โ€” ๐Ÿ‘ 101    ๐Ÿ” 14    ๐Ÿ’ฌ 8    ๐Ÿ“Œ 0

This thread (and the answers) are a small gem, covering an almost forgotten piece of history of the security field.

06.03.2025 06:38 โ€” ๐Ÿ‘ 19    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
1. Three new bad practices on use of known insecure or outdated cryptographic functions, hardcoded credentials, and product support periods.
2. Additional context added to the memory safety section.
3. Added additional examples of recommended actions to prevent SQL injection vulnerabilities.
4. Added additional examples of recommended actions to prevent command injection vulnerabilities.
5. Clarified timelines for patching Known Exploited Vulnerabilities (KEVs).
6. Added language for multi-factor authentication (MFA) specific to operational technology products.
7. Added that software manufacturers should support phishing-resistant MFA.
8. Other updates to phrasing throughout.

1. Three new bad practices on use of known insecure or outdated cryptographic functions, hardcoded credentials, and product support periods. 2. Additional context added to the memory safety section. 3. Added additional examples of recommended actions to prevent SQL injection vulnerabilities. 4. Added additional examples of recommended actions to prevent command injection vulnerabilities. 5. Clarified timelines for patching Known Exploited Vulnerabilities (KEVs). 6. Added language for multi-factor authentication (MFA) specific to operational technology products. 7. Added that software manufacturers should support phishing-resistant MFA. 8. Other updates to phrasing throughout.

The FBI has released version 2.0 of its Product Security Bad Practices

PDF: www.ic3.gov/CSA/2025/250...

The changes are detailed in the image below

19.01.2025 18:39 โ€” ๐Ÿ‘ 14    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Oui oui, when in France!

05.12.2024 20:35 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
New era of slop security reports for open source I'm on the security report triage team for CPython, pip, urllib3, Requests, and a handful of other open source projects. I'm also in a trusted position such that I get "tagged in" to other open sou...

Seth Larson, the maintainer of several crucial Python projects, says he is seeing an increase in "extremely low-quality" security reports submitted by bug hunters, suggesting researchers are using AI/LLM tools to discover vulnerabilities and put together reports.

sethmlarson.dev/slop-securit...

05.12.2024 15:45 โ€” ๐Ÿ‘ 30    ๐Ÿ” 13    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 2
Preview
the man is wearing a suit and tie and clapping his hands . ALT: the man is wearing a suit and tie and clapping his hands .
21.11.2024 14:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

All thatโ€™s left is Giphy integration!

21.11.2024 14:43 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

If it sounds like a duck and looks like a duck, its probably not a duck

21.11.2024 12:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™ve experienced similar and bsky feels to be ticking all the boxes for me at least. This feels like Twitter of 2014(in a good way)

21.11.2024 10:30 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ‘‹๐Ÿ‘‹๐Ÿ‘‹๐Ÿ‘‹ botb was/is something useful in this spaceโ€ฆ

19.11.2024 17:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Wow so is bsky really maybe potentially becoming a thing now?

14.11.2024 14:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Ok, where are the South African hackers at? Post handles in replies if you see this please, and Iโ€™ll attempt a starter pack.

cc
@leonjza.bsky.social
@haroonmeer.canary.love

13.11.2024 19:01 โ€” ๐Ÿ‘ 7    ๐Ÿ” 3    ๐Ÿ’ฌ 5    ๐Ÿ“Œ 0
Post image

Once you are specifically targeted, chances are very good you will continue to see attempts to breach your defenses. APTs come for a purpose and thereโ€™s a reason the Persistent part of the name was chosen.

11.10.2023 11:35 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This could be gnarly if your proxychains setup is somewhat exposed..which it shouldnโ€™t

11.10.2023 13:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

So everybody from Musk's site seems to be here, yet my feed feels a bit anemic. What's a good trick to synch follows?

02.10.2023 11:51 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Total blast from the pastโ€ฆ

15.09.2023 18:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

In January, the Bluesky app began with a few hundred users. Weโ€™ve since grown past 1 million. Iโ€™m proud of what our team has accomplished in the last 9 months: weโ€™ve open sourced the protocol and app, introduced self-verification via custom domains, and enabled algorithmic choice with custom feeds.

12.09.2023 22:50 โ€” ๐Ÿ‘ 2999    ๐Ÿ” 373    ๐Ÿ’ฌ 91    ๐Ÿ“Œ 34

Tale as old as time: hackers hack stalkerware company because stalkerware is low-quality crap.

techcrunch.com/2023/08/26/b...

29.08.2023 04:06 โ€” ๐Ÿ‘ 65    ๐Ÿ” 12    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Now thatโ€™s a flex to aim for

21.08.2023 20:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

NEW: Several attendees at Def Con saw mysterious alerts on their iPhones.

A researcher claimed responsibility and said it was a research project to teach people to turn off Bluetooth and "to have a laugh."

https://techcrunch.com/2023/08/14/researcher-says-they-were-behind-iphone-popups-at-def-con/

14.08.2023 20:01 โ€” ๐Ÿ‘ 8    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

Today in 2000, 23 years ago, we introduced libcurl into the world. curl 7.1 was the first release featuring a separate library for Internet transfers, that curl was then made to use.

Today we estimate 20 BILLION installations worldwide.

07.08.2023 07:03 โ€” ๐Ÿ‘ 14    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Worse than npm or pip etc?

03.08.2023 07:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Wait, itโ€™s summer camp next week already? #itsbeenawhile

01.08.2023 16:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
01.08.2023 09:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Code Kept Secret for Years Reveals Its Flawโ€”a Backdoor A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isnโ€™t pretty.

For 25+ yrs police, military, intel agencies and critical infrastructure around the world relied on the TETRA radio standard to secure critical communications. But now Dutch researchers have examined secret algorithms used in TETRA and found something startling - an intentional backdoor, and more

24.07.2023 10:17 โ€” ๐Ÿ‘ 33    ๐Ÿ” 20    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 3

Ask @patrick.risky.biz to go on vacation?

27.06.2023 11:22 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is valuable insight, thanks for sharing. How are you defining downturn? And what kind of timescales would you see as not crazy?

17.06.2023 17:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Yeah definitely thatโ€™d be great, let me know when youโ€™re in London again!

30.05.2023 10:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Howsit bru!

26.05.2023 06:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@brompwnie is following 20 prominent accounts