Royce Williams's Avatar

Royce Williams

@tychotithonus.infosec.exchange.ap.brid.gy

Just doing my undue diligence. ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate […] πŸŒ‰ bridged from ⁂ https://infosec.exchange/@tychotithonus, follow @ap.brid.gy to interact

57 Followers  |  12 Following  |  1,033 Posts  |  Joined: 17.11.2024  |  1.9191

Latest posts by tychotithonus.infosec.exchange.ap.brid.gy on Bluesky

Claude showing a generic "something went wrong, please try again" error.

Claude showing a generic "something went wrong, please try again" error.

ChatGPT answering a question about its own cloudflare dependencies, talking about protection and acceleration, but core functionality expected to be unaffected.

ChatGPT answering a question about its own cloudflare dependencies, talking about protection and acceleration, but core functionality expected to be unaffected.

Gemini answering a question about cloudflare dependency, stating that client-side developer integration may be impacted, but core functionality runs on Google's own global network and Google's cloud.

Gemini answering a question about cloudflare dependency, stating that client-side developer integration may be impacted, but core functionality runs on Google's own global network and Google's cloud.

Perplexity answering a question about how it depends on cloudflare, stating that it " does not fundamentally depend on cloudflare for its own operations" with caveats about how perplexity accesses content on the web and other considerations.

Perplexity answering a question about how it depends on cloudflare, stating that it " does not fundamentally depend on cloudflare for its own operations" with caveats about how perplexity accesses content on the web and other considerations.

Of the major web-based LLM frameworks in my roster (ChatGPT, Copilot, Claude, Gemini, and Perplexity), core functionality during the Cloudflare outage seems to be fine -- except for Claude, which is completely unusable.

18.11.2025 14:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

[installs app]
[launches app]
[app immediately displays pop-up that says "[app name]" pasted from your clipboard"]
[deinstalls app]

18.11.2025 02:33 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

I swear some accounts are tracking moderately viral posts, feeding them to LLMs to amplify their virality, and then reposting.

18.11.2025 02:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
CISA, eyeing China, plans hiring spree to rebuild its depleted ranks The agency will also change some of its workforce policies to avoid driving away talented staff.

Scoop: CISA plans to embark on a hiring spree and change some workforce policies in an effort to rebuild its depleted ranks ahead of a possible conflict with China, according to a memo from its acting director that I obtained.

www.cybersecuritydive.com/news/cisa-hi...

17.11.2025 21:30 β€” πŸ‘ 29    πŸ” 26    πŸ’¬ 7    πŸ“Œ 5

I don't know how how it happened that this is how I found this out.

https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html

No one who understands the problem space thinks this is a good idea.

15.11.2025 20:15 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 2    πŸ“Œ 1

I wish I could teach speech-to-text that when I say "gotta" in the middle of a sentence, I actually want that word.

17.11.2025 23:54 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Google search results for "three-sided die", with the top half of the screen filled with the results of a simulated role of a six-sided die. To the lower right of that, a total showing six, implying that multiple roles will accumulate. Immediately underneath, a row of small icon showing other sided dies, values four, six, eight, 10, 12, 20, in a variety of colors, with a final icon in Gray showing a plus and minus symbol, as if the list of dies can be customized. Directly below that, a blue rectangular button that says "roll". Below that a row of two tabs "games and toys" and "tools" which is selected and current. Below that, the listed tools include tuner, bubble level, meditate, and one we cannot see, in a variety of basic colors.

Google search results for "three-sided die", with the top half of the screen filled with the results of a simulated role of a six-sided die. To the lower right of that, a total showing six, implying that multiple roles will accumulate. Immediately underneath, a row of small icon showing other sided dies, values four, six, eight, 10, 12, 20, in a variety of colors, with a final icon in Gray showing a plus and minus symbol, as if the list of dies can be customized. Directly below that, a blue rectangular button that says "roll". Below that a row of two tabs "games and toys" and "tools" which is selected and current. Below that, the listed tools include tuner, bubble level, meditate, and one we cannot see, in a variety of basic colors.

Huh, I had no idea Google had dice built in.

17.11.2025 23:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Notification icon in the upper right hand corner of the Google Play Store app, a little line drawing of a bell, with a badge count of six.

Notification icon in the upper right hand corner of the Google Play Store app, a little line drawing of a bell, with a badge count of six.

The first three unread "alerts" in the Google Play Store app. Titles: "tap into this month's game picks", "43 updates need approval", "find a new favorite app on play". There's also a pop-up at the top with the title "get updates faster", with the text " receive special offers, Early Access to new features and updates. Stay informed with notifications and emails."

The first three unread "alerts" in the Google Play Store app. Titles: "tap into this month's game picks", "43 updates need approval", "find a new favorite app on play". There's also a pop-up at the top with the title "get updates faster", with the text " receive special offers, Early Access to new features and updates. Stay informed with notifications and emails."

The rest the of the "alerts", titled "your favorite anime", "multiplayer fun with friends or foes" and "offline fun you can have anywhere".

The rest the of the "alerts", titled "your favorite anime", "multiplayer fun with friends or foes" and "offline fun you can have anywhere".

The notification settings area (at the Android level) for the Google Play app. The only categories enabled are "updates available" and "maintenance". Notice that neither of these seem to really cover "spam me about game crap".

The notification settings area (at the Android level) for the Google Play app. The only categories enabled are "updates available" and "maintenance". Notice that neither of these seem to really cover "spam me about game crap".

Okay, that's it, I'm turning off all notifications and badges for the Google Play Store. It's nothing but spam now, with what appears to be no way to only get functional notifications.

17.11.2025 22:59 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Buoyancy

New survivorship-bias image just dropped.

https://www.oglaf.com/buoyancy/

16.11.2025 21:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

OK, that's a new one ... my system didn't reboot, but it looks like tmux crashed (and took every child process with it)!

15.11.2025 20:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@peterhoneyman

πŸ€¦β€β™‚οΈ

And I am startled that I live there and this is how I'm finding out.

15.11.2025 20:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I don't know how how it happened that this is how I found this out.

https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html

No one who understands the problem space thinks this is a good idea.

15.11.2025 20:15 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 2    πŸ“Œ 1

@nuthatch

And I thought I Was already following you! Fixed.

@neurovagrant

15.11.2025 20:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@nuthatch Ooh, that's good!

15.11.2025 20:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Tired: "Enable JavaScript to continue"

Wired: "Enabling JavaScript to continue" πŸ€– 😱

15.11.2025 15:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If you're a "security researcher", and you send an email asking how to report vulnerabilities for a web property that I operate, and that web property has a security.txt ... you're getting marked as spam.

15.11.2025 14:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

For prompting use cases that are a little more complex, "Here is my broad goal and a couple of my constraints. Tell me the elements of a good prompt, and how to minimize hallucination"

... followed by (in a fresh session, or with a different platform):

"Here's a prompt -- don't follow it […]

15.11.2025 14:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

I just noticed that ../ looks like eyes and an outreaching arm, as if it's a victim drowning in quicksand.

I'm sure this is trenchant, somehow. cc @cR0w

14.11.2025 21:08 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Closeup of small tap-target area at the bottom right of Outlook's interface, with the plus sign (which used to be the only thing there, easily tapped with a thumb at an angle), now immediately *closer* to the thumb, a Microsoft Copilot sub-button. Chances of accidentally tapping the latter are extremely high.

Closeup of small tap-target area at the bottom right of Outlook's interface, with the plus sign (which used to be the only thing there, easily tapped with a thumb at an angle), now immediately *closer* to the thumb, a Microsoft Copilot sub-button. Chances of accidentally tapping the latter are extremely high.

Screenshot of the entire app, for scale. The tap-target area is very small in the bottom right corner.

Screenshot of the entire app, for scale. The tap-target area is very small in the bottom right corner.

This tap-target adjacency is a d--k move, Microsoft Outlook on mobile.

14.11.2025 21:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@vees He's more of an "act locally" guy, but that's absolutely how it can play out, too. πŸ˜†

14.11.2025 20:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Just described a long-time friend as "high executive function, in the service of others" ... and realized I should be trying hard to achieve that.

14.11.2025 20:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

"If you're touching the brake or turning the steering wheel _before_ activating the turn signal, you're doing it wrong" appears to be largely lost knowledge.

14.11.2025 18:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0

@north Ooh, that's good

14.11.2025 05:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

An unexpected survivor

13.11.2025 06:38 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

[USPol]

I've got Ken Burns' National Parks docuseries on in the background and I gotta say, it's a pretty patriotic experience.

Better still: streaming through Kanopy and my local library.

This is the kind of America I'm super into, which is easy to forget that in the day-to-day shenanigans […]

12.11.2025 22:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

This isn't the first transfer to aws.eu. This is the most visible and overt shift in assets by the big U.S. cloud providers I'm aware of. Others (e.g., Google and Microsoft) talk about doing more in the EU and providing isolation, but as far as I can tell Amazon's separation is going a step […]

12.11.2025 14:57 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

I swear to Nog, I never saw things just being "fraught", rather "fraught _with_ (something)", until the last year or so.

12.11.2025 14:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Really disliking the AI-augmented pfps.

12.11.2025 13:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on infosec.exchange

@Viss Troy imports the plaintexts into his "Pwned Passwords" database, which can basically be downloaded via API. He even published a downloader implementation:

https://github.com/HaveIBeenPwned/PwnedPasswordsDownloader

The password crackers pull this periodically, to track diffs over time […]

11.11.2025 22:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@Viss Not that I know of -- we're just working from the publicly available hashes

11.11.2025 22:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@tychotithonus.infosec.exchange.ap.brid.gy is following 12 prominent accounts