How to Run Custom Linux Images on Oracle Free Tier
Bypass the Oracle free-tier limitation of running only Linux distributions provided by Oracle by sideloading a QCOW2 image to a boot volume and attaching it to a new instance.
roguesecurity.dev/blog/custom-...
A quick writeup on a hacky but effective method of bypassing Oracle's restrictions on #Linux distro use in their free tier. I don't trust them, but I'll happily burn some of their compute.
#selfhosting #cloud #OpenSuse
19.11.2025 03:42 β π 1 π 0 π¬ 0 π 0
I have not, but maybe I don't follow. I have only seen QR used for onboarding passkeys, never authenticating with them. Untrusted devices and BLE connections seems equally strange as far as threat modeling goes, to me. Have not found it in the Bitwarden docs either. Enlighten me?
27.10.2025 15:21 β π 0 π 0 π¬ 1 π 0
Love @bitwarden.bsky.social
I'm already a user and a fan! I use it for the few things that have passkeys in my life currently, but I still don't agree with the overarching implementation of passkeys.
23.10.2025 19:27 β π 1 π 0 π¬ 0 π 0
I'm a user and general fan of Bitwarden -- self-hosted. It works great for me, but it still means that to use it on a "guest" device, I need to access my password manager *on that device*. The alternative being accessing my password manager on my trusted device (my phone), and transposing the data.
23.10.2025 19:26 β π 0 π 0 π¬ 1 π 0
Passkeys are all well and good until you need to access a service on another device.
When did we sign up to be chained to a phone or endpoint with access to a service that manages passkeys?
I get the benefit, but it feels like entrapment was engineered into the workflow.
23.10.2025 16:19 β π 0 π 0 π¬ 1 π 0
The fourth monkey has emerged. He sees no one, hears no one and speaks to no one.
22.10.2025 21:15 β π 138 π 32 π¬ 4 π 1
End-to-End Encrypted Chat that YOU Control: Hosting XMPP (Jabber) with Prosody
Start-to-finish guide for setting up a modern XMPP (Jabber) Server to facilitate E2EE chat on your own infrastructure, podman style
After a bit of a break, I've got a new homelab post in the books on #XMPP
Take control of your chat experience with #E2ee and own your data. Maybe relevant for those potentially affected by a future #chatcontrol ruling.
Check it out, let me know what you think!
roguesecurity.dev/blog/xmpp
13.10.2025 20:35 β π 1 π 0 π¬ 0 π 0
It's like planting a tree. The best time to do it was yesterday.
07.10.2025 17:13 β π 1 π 0 π¬ 0 π 0
I know itβs been said again and again, but what does it say about ChatControl that its backers keep explicitly *exempting* law enforcement and national security accounts from content scanning?
17.09.2025 17:10 β π 95 π 41 π¬ 3 π 8
So by proxy, RC4 with Kerberos is bad.
16.09.2025 17:17 β π 2 π 1 π¬ 0 π 0
RC4 used with Kerberos isn't the fundemental flaw we think. Yes, RC4 is deprecated, but the real issue is the key generation for AES v RC4 for cracking (Kerberoasting). With RC4 the key = password hash. With AES it is 4096 rounds of hashing of hash+username+domain. The 4096 rounds matters, a lot!
16.09.2025 17:14 β π 8 π 2 π¬ 1 π 0
Cyd 1.1.21 released | Cyd Docs
We're pleased to announce Cyd 1.1.21 is released. Here's what's new:
Cyd 1.1.21 is out. This is a bug fix release resolving issues importing from X export files and in migrating media to Bluesky:
docs.cyd.social/blog/cyd-1.1...
Thank you to the bug reporters!
24.08.2025 21:52 β π 10 π 4 π¬ 2 π 0
Ah yes, the life of a cybersecurity pro. Here to be hated...
18.08.2025 21:01 β π 0 π 0 π¬ 0 π 0
SystemD Service Hardening
Discover additional security options for systemd units, to include quadlets. These options are everything from system permissions, time manage, BPF, syscall & seccomp filters, etc., all to make your s...
Another #selfhosting blog down, this time some casual notes on #systemd #security. Love it or hate it, systemd is a big player in the bulk of Linux systems out there, and these are a few notes on how to lock down some of the defaults.
roguesecurity.dev/blog/systemd...
11.08.2025 22:14 β π 2 π 0 π¬ 0 π 0
GitHub is no longer independent at Microsoft after CEO resignation
GitHub will be part of Microsoftβs AI engineering team
This is big. GitHub is no longer independent at Microsoft after CEO resignation: GitHub CEO Thomas Dohmke has resigned, and now GitHub will be part of Microsoftβs core AI engineering team. Github is no longer independent company.
www.theverge.com/news/757461/...
11.08.2025 17:12 β π 122 π 79 π¬ 10 π 21
Page logo: SONICWALL
Title: Recommended Mitigation Steps.
Until further notice, we strongly advise all partners and customers using Gen 7 SonicWall firewalls to take the following actions:
**1. Disable SSLVPN Services Where Practical**
Callout box: NOTE: All other steps below should still be followed even if disabling SSLVPN is not viable.
So the official SonicWall mitigation leads with "turn it off" ? ooooof.
04.08.2025 18:40 β π 3 π 5 π¬ 2 π 0
Don't give your government issued Id to YouTube.
31.07.2025 16:13 β π 89 π 24 π¬ 2 π 1
It's easy to bash vulnerabilities with logos but... I couldn't resist, say hello to http1mustdie.com :)
18.07.2025 12:56 β π 13 π 3 π¬ 2 π 0
OPNsense 25.7 released
OPNsense 25.7 released
#OPNsense 25.7 "Visionary Viper" is now available.
23.07.2025 11:10 β π 23 π 5 π¬ 3 π 0
Being in tech and having a single modicum of critical thinking is just screaming "this isn't what LLMs are designed for" over and over as people shove a bunch of word predictors into critical decision making processes because some glorified used car salesmen told them it would fix all their problems
23.07.2025 18:10 β π 3918 π 1352 π¬ 52 π 33
EFF's @tsnvaa.bsky.social will be sharing the history of Flock in the U.S. and the growing risks and concerns with the technology at this teach-in for the Denver community on 7/15 from 6-8pm MT. You can join online at bit.ly/FLOCKteachin.
10.07.2025 20:03 β π 130 π 67 π¬ 3 π 3
@garmin.com what's your take on this? how are you going to guarantee you're keeping customer data safe?
10.07.2025 17:02 β π 0 π 0 π¬ 0 π 0
Monarch Lisa looking a bit disheveled
Good morning! βοΈβοΈβοΈβοΈβοΈ
03.07.2025 13:34 β π 1253 π 153 π¬ 24 π 11
Kennedy guts CDC's vaccine panel of independent experts
The Advisory Committee for Immunization Practices helps the agency make recommendations on who should get certain vaccines.
An outspoken vaccine conspiracy theorist just fired every last member of CDC's vaccine advisory committee.
RFK Jr. is paving the way to reshape vaccine policy based not on decades of science, but on his own unhinged fanaticism.
This is unprecedented, and unthinkably dangerous.
09.06.2025 21:22 β π 1999 π 746 π¬ 143 π 64
Monitor your AREDN Node with Prometheus and Grafana
Utilize the newly added prometheus metrics exporter in the AREDN firmware to add analytics and performance metrics to Grafana. Read about the metrics endpoint and a basic dashboard to monitor performa...
This week I'm combining data enthusiast homelab metrics with @grafana.bsky.social and #arednmesh #hamradio goodness, by setting up @prometheus.io collection of performance metrics of your AREDN node and displaying them in Grafana! Homelabbers and hams unite!
roguesecurity.dev/blog/aredn-m...
09.06.2025 01:41 β π 0 π 0 π¬ 0 π 0
Last night I went to see Mission Impossible: Final Reckoning, where a rogue AI takes over the entire US nuclear arsenal, and all I could think was: this shit wouldnβt have happened if theyβd published ISO 19790:2025 for free.
03.06.2025 16:47 β π 62 π 12 π¬ 1 π 0
Open Thoughts, Electrical Engineering, Computer Programming, Music & Oldskool Technology.
I design audio gear, compose music and build experimental musical instruments.
Full Snack Developer
Once got code to run on the first try
Highly trained in fika breaks βπ§
π οΈ #Dev π§ #Linux
https://github.com/pa-ulander
https://linkedin.com/in/paulander/
πStockholm, Sweden πΈπͺ
Hi, I am rootcat (he/him)| Posts in German/English| Redteamer/Hacker| Team Orca| My Opinions belong to the fey folk| π |
Hacker for hire at @specterops.bsky.social
Blog: https://blog.xpnsec.com
π¬π§ | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel
Vulnerability Researcher | Exploit Developer (speaker 3x at DEF CON)
Enjoy Linux & Unix-like systems, open-source software, and programming/compsci? Into Sysadmin & DevOps? Follow us to make the most of your IT career! Discover new tools and apps daily, plus a dose of humor ‡οΈ
https://www.cyberciti.biz
Offensive security tools developer. Malware developer, hobby music producer, bedroom DJ & ex-MMO game hacker. Creator of Evilginx / Bartender @ BREAKDEV RED.
Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) πΊπΈ A mostly unserious person. @therealc3rul34n.bsky.social is bae π₯°
Live hacking content https://truecyber.world/
Red team training https://mr.un1k0d3r.world/training/
Github https://github.com/Mr-Un1k0d3r
Penetration tester trying to perform novel research. You can find all of my write-ups and research at https://thomas.stacey.se.
By the power of truth, I, while living, have conquered the universe - /OS(C(P|E)|EE)/ -- Red teamer @codewhitesec.bsky.social | @dhn@infosec.exchange | @dhn_ on X
Hermetic Initiate. Exploring conscience and the nature of reality. I also hack things.
Red Teamer || Pentester || CTF Player
The largest collection of malware source code, samples, and papers on the internet.
Password: infected
(unofficial, this is a bot! Maintained by @yjb.bsky.social, the bot can't handle retweets, video, and maybe a few other things)
Threat Hunting - DFIR - Detection Engineering
π https://github.com/mthcht
π¦ https://x.com/mthcht
π° https://mthcht.medium.com
Math and Science Education, Climbing and Mountain Biking, other nerdy things like Ham Radio (VA7FI).
mitmproxy developer, making cloud more secure at Google. TLS, web, networks, and open source.
Mostly active on http://fedi.hi.ls these days, mirroring announcements here.
Sr. Security Researcher at Microsoft
π bridged from https://infosec.exchange/@fr0gger on the fediverse by https://fed.brid.gy/
Discover open source alternatives to popular software. Curated by @kulpinski.dev
Join 8k+ subscribers β openalternative.co