TC Fox πŸ’»'s Avatar

TC Fox πŸ’»

@tech.tc.nz

TC’s IT and InfoSec thoughts

70 Followers  |  114 Following  |  62 Posts  |  Joined: 17.08.2023  |  2.4944

Latest posts by tech.tc.nz on Bluesky

Apologies for the extended break by the way. Had a rough couple of years. In a much better place now but it’s taking a lot longer for me to get my stride back than I realised.

Doing the social is hard for me right now, I’m just taking life gently for a while.

31.07.2025 12:15 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

GET / HTTP/1.1
User-Agent: HI I CAN BE WHOEVER YOU WANT ME TO BE PLEASE LOVE ME

27.05.2025 01:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

The β€œMozilla” browser, on Windows NT or Win64 or x64 or something, running on AppleWebKit (like KHTML except actually Gecko) except that’s a lie it’s actually Chrome which is like Safari (which is actually AppleWebKit again) but that’s also a lie because it’s actually Edge

I love User-Agent strings

27.05.2025 01:47 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

TIL that service accounts, machine accounts etc are sometimes referred to as β€œNon-Human Identities” and I’m like

Yeah

18.05.2025 22:20 β€” πŸ‘ 20    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0

lol, younger users of the internet are not going to take those seriously. *Especially* mumble, c’mon

Spacebar looks to be a promising alternative from what I could see, and if Matrix sorts its jank arse user experience and dodgy cryptography out I agree it could be a solid option

29.04.2025 13:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This has occurred to me on more than one occasion. πŸ€”

15.04.2025 22:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
The Reg translates Oracle's weak breach confession letter : TL;DR: Move along, still nothing to see here - an idea that leaves infosec pros aghast

This might actually be the lamest vendor response I’ve ever seen: www.theregister.com/2025/04/10/o...

11.04.2025 02:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Legitimately incredibly useful. I don’t normally do this but Tailscale is genuinely an awesome product for helping control access to things while *also* making the complexities of networking easier for me to deal with. #5yearsofTailscale

03.04.2025 21:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Firefox’s ambiguously worded legal document means it could be interpreted that they might steal my data? Guess I have to switch to *checks notes* Google

04.03.2025 21:32 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Is anyone able to explain to me what parts of Microsoft is a 365, what a Copilot is, and what Windows does?

Because I’m finding examples where 365 is sometimes not a cloud thing, Copilot is sometimes not an AI thing, and Windows sometimes is not an OS, and I’m thoroughly fucking confused

04.03.2025 00:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I’m probably getting ahead of myself though, given that isn’t not even supported by *Firefox or Safari* yet πŸ™ƒ

16.02.2025 06:55 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I get that there’s a lot of security/privacy reasons for the complexity of FedCM on the IdP’s end, but I am seriously worried it’s gonna harm adoption if IdP’s have to jump through so many hoops to support it.

I have a hunch this is going to supported by Google, Google’s FedCM demo, and nobody else

16.02.2025 06:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

this haptic display absolutely rocks. basketball is for everyone.

06.02.2025 21:56 β€” πŸ‘ 21496    πŸ” 6923    πŸ’¬ 251    πŸ“Œ 1048

Sorry I’ve been so quiet on this account lately! There’s so much I want to talk about and 99% of it is β€œoops that’s related to a pentesting client for work, can’t talk about that” πŸ˜’

22.01.2025 23:46 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

Definitely been taking a while to get the Wellington OWASP meets back up again, but ducks are now in a row and only thing left is to present something!

Currently making progress on my presso to get the ball rolling, should be ready for a (tentatively!) February meetup! Watch this space!

31.12.2024 23:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Interviewer: Can you explain this gap in your resume?

Pentester: It’s called time-based blind SQL injection.

21.12.2024 20:59 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1

Yes, I’m largely referencing vanilla PHP here, the β€œindividually sanitise every single time and if you forget that’s your fault” attitude still seems to prevail there. But they’re not the only ones at fault of this.

18.12.2024 22:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It’s exhausting having to push back against security arguments that boil down to β€œYou’re safe if you don’t make mistakes”.

If the tools you work with require manual, iterative and individual protections against exploitation multiple times, they’re shit tools.

18.12.2024 22:15 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Looking forward to seeing lots of you at #chcon tomorrow!

21.11.2024 10:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Something ingrained, that I realize now others do not have, is knowing the solution to failure is offering a better solution. I have tried shame I have endured compliance. I ground this axe years. You need the market to decide you've won. I sold modern policy baselines to fix user experience. I won.

14.11.2024 04:48 β€” πŸ‘ 271    πŸ” 27    πŸ’¬ 8    πŸ“Œ 1
Post image

So glad that Apple moved away from that weird arse design pattern where windows could not be maximised and toolboxes were just floating there and just appeared/disappeared depending on which window had focus, was a pain in the arse πŸ˜…

23.10.2024 02:52 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Photograph of entrance of Congress Center Hamburg, showing two banners hanging, one on the left is code.talks, and the one on the right is Eurofurence.

Photograph of entrance of Congress Center Hamburg, showing two banners hanging, one on the left is code.talks, and the one on the right is Eurofurence.

A developer conference running in parallel with a furry convention is pure comedy

18.09.2024 14:08 β€” πŸ‘ 101    πŸ” 21    πŸ’¬ 6    πŸ“Œ 1

HL7: The healthcare β€œstandard” that people β€œfollow”

12.09.2024 05:24 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Apple is definitely having a gap year. iOS 18 has been a total snoozefest too, ah well.

At least they’ve done a little catch up on some small areas where they’ve been lagging behind competition.

10.09.2024 03:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Security and foxes is a disaster recipe that will result in all of your chicken/eggs being stolen Ɛ:

06.09.2024 12:22 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Two hobbies crossing over is where the interesting stuff happens! Especially security and anything else

06.09.2024 12:18 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Had a good time at OWASP New Zealand Day this year! Had a lot of awesome conversations with many interesting people, and definitely inspired to get another talk done soon!

Also working through the initial plans for an interesting contribution to the AppSec scene, watch this space!

06.09.2024 12:12 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Is this the tcpip.sys RCE thing potentially?

30.08.2024 03:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It's only a one-time pad if it comes from the Padua region of Italy. Otherwise, it's just sparkling preshared key.

29.08.2024 12:21 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

@tech.tc.nz is following 19 prominent accounts