a headline showing I wrote the introduction last year
One of the hats I wear is editor for the @defcon Franklin Hackers' Almanack. If you see talks that policymakers should know about, please let me know here, tag me, etc.
I'm already seeing great stuff on voting security, resisting back doors, irresponsible […]
[Original post on infosec.exchange]
09.08.2025 14:59 — 👍 1 🔁 2 💬 0 📌 0
The frenzied activity here at @defcon is just a sight to behold!
08.08.2025 16:50 — 👍 0 🔁 1 💬 0 📌 0
Original post on infosec.exchange
The "groundbreaking" NIST report is on... a hackathon where the devs are available?
The dream of the 90s is alive in the media.
"“If the report was published, others could have learned more information about how the [NIST] risk framework can and cannot be applied to a red teaming context,” […]
07.08.2025 14:10 — 👍 0 🔁 0 💬 0 📌 0
Tabletop Security Games + Cards
The exhaustive list of cybersecurity tabletop games.
If you're at Blackhat and see interesting, physical #cybersecurity games at the business hall, please let me know. I enjoy collecting these games, and they're often limited editions.
https://shostack.org/games
06.08.2025 19:10 — 👍 1 🔁 0 💬 1 📌 0
This 40th anniversary special release of #phrack is amazing. If you’re at #blackhat or #defcon you should aim to get one.
06.08.2025 06:22 — 👍 2 🔁 4 💬 0 📌 0
This 40th anniversary special release of #phrack is amazing. If you’re at #blackhat or #defcon you should aim to get one.
06.08.2025 06:22 — 👍 2 🔁 4 💬 0 📌 0
I mean, other than the preceding quoted list items, and probably much more.
05.08.2025 20:12 — 👍 0 🔁 0 💬 0 📌 0
Certainly nothing for any technology company to learn from in any of this.
05.08.2025 20:12 — 👍 1 🔁 0 💬 1 📌 0
Original post on infosec.exchange
6) OceanGate’s failure to conduct a detailed investigations after the TITAN experienced mishaps that negatively impacted its hull and components during dives conducted prior to the incident,
7) OceanGate’s toxic workplace environment which used firings of senior staff members and the
looming […]
05.08.2025 20:12 — 👍 0 🔁 0 💬 1 📌 0
Original post on infosec.exchange
3) OceanGate’s
excessive reliance on a real-time monitoring system to assess the condition of the TITAN's
carbon fiber hull and then their failure to conduct a meaningful analysis of the data provided by
the system,
4) OceanGate’s continued use of the TITAN after a series of incidents that […]
05.08.2025 20:10 — 👍 0 🔁 0 💬 1 📌 0
The Coast Guard has released its investigation report on the Titan submersible implosion.
05.08.2025 19:55 — 👍 0 🔁 4 💬 1 📌 0
@mmasnick.bsky.social Tesla has also claimed (to the ny times) that Florida has essentially eliminated punitive damages. Is that claim as accurate as the ones covered in the electrek article?
04.08.2025 20:34 — 👍 0 🔁 0 💬 0 📌 0
Page logo: SONICWALL
Title: Recommended Mitigation Steps.
Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions:
**1. Disable SSLVPN Services Where Practical**
Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.
So the official SonicWall mitigation leads with "turn it off" ? ooooof.
04.08.2025 18:40 — 👍 3 🔁 5 💬 2 📌 0
Original post on federate.social
We can make our elections trustworthy in spite of the inevitable security weaknesses in equipment!
How? By using an architecture that *tolerates* security flaws instead of requiring you to eliminate them. This is called "Software Independence", formalized by Ron Rivest (the R in RSA) about 15 […]
03.08.2025 00:02 — 👍 7 🔁 1 💬 0 📌 0
@jik Sendgrid should absolutely do better at managing account close state. And I wonder if they have to keep the card on file for some period because of pci rules?
02.08.2025 15:34 — 👍 0 🔁 0 💬 1 📌 0
When I worked as a SGE for the White House ONCD we had to attend mandatory Hatch Act training. I just found my “Social Media Quick Guide” for what is permissible. Nowdays I bet it is quite different.
02.08.2025 02:59 — 👍 3 🔁 1 💬 0 📌 0
“I find your lack of font consistency disturbing!”
02.08.2025 01:01 — 👍 0 🔁 2 💬 0 📌 0
@JessTheUnstill See, and everyone's complaining about AI! 😂
01.08.2025 23:33 — 👍 0 🔁 0 💬 0 📌 0
You wanna know why the US economy hasn't already tipped into a huge depression?
AI.
Literally.
Megatech is throwing so much capital at AI it's legit keeping the economy afloat.
01.08.2025 20:34 — 👍 3 🔁 9 💬 4 📌 1
Original post on infosec.exchange
For the #wastewater fans, here is an informative primer on how the nationwide*] #covid #COVID19 wastewater data is collected, and the differences between the CDC's NWSS and WatewaterScan's data systems: [https://pandemics.sph.brown.edu/news/2025-01-23/wastewater-brief. Via Katelyn Jetelina.
[*] […]
01.08.2025 16:16 — 👍 0 🔁 2 💬 0 📌 0
“Where we’re going, we don’t need roads!”
#aviation #737 #manufacturing
01.08.2025 15:33 — 👍 0 🔁 2 💬 0 📌 0
The last Blue Angels pass was low enough to trigger the rain sensor on my skylight.
31.07.2025 19:15 — 👍 0 🔁 0 💬 0 📌 0
Original post on infosec.exchange
Are there sshd state machines? I'm looking for one that covers "root," "running as user" and "spawning shell"*?
I've found https://www.researchgate.net/figure/Abstract-description-of-SSH2-with-Diffie-Hellman-key-exchange_fig2_241880255 and Figure 5 of […]
30.07.2025 23:04 — 👍 0 🔁 0 💬 1 📌 0