I cracked a tough project today. It was the culmination of 2 months of work. It was only possible because a sloppy contractor left an unsecured private key in a place he thought I'd never look.
Two lessons:
1. Don't use the same key everywhere. I got the keys to the kingdom in one singular moment.
2. Obscurity is a valid security layer. People can't hit what they can't see. But defence in depth is what works. Obscurity can't be your only layer.
#infosec #cybersecurity #fuckyeah
検索
The thing about working at the level of tech I'm at is that you need full big brain every day. There's no instruction manual for what I do. There's no safety net. There's nobody else that knows more about the subject matter. It's very stressful and sick days are actually the right thing to do when I'm not fully on because the stakes are too high for fuck ups.
#Infosec #Cybersec #Burnout
We've certainly reached a #TechDystopia milestone when you need to update the firmware on your bicycle shifters to keep them from getting hacked.
https://www.wired.com/story/shimano-wireless-bicycle-shifter-jamming-replay-attacks/
#InfoSec #biking #bike
Well, this is awful. PII data was apparently collected en masse and without consent by National Public Data, who was then breached, and now 2.9 billion people have SSN, name, and address, going back as far as 30 years, exposed on the dark web.
https://www.tomsguide.com/computing/online-security/29-billion-hit-in-one-of-largest-data-breaches-ever-full-names-addresses-and-ssns-exposed
#InfoSec #Privacy #NationalPublicData
If you are in #infosec and want to contribute to important digital infra, at STF we have added 5 new bug bounty programs for #opensource projects in our BRP program (for a total of 7) 👨💻
More info in the blogpost 👇
https://www.sovereigntechfund.de/news/calling-all-security-researchers/
#CrowdStrike hosting their stuff on Wordpress reminds me of that LifeLock identity protection service guy who posted his SSN in public ads.
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
#InfoSec
Found by two UC students!
The Verge: Two students find security bug that could let millions do laundry for free
https://www.theverge.com/2024/5/19/24160383/students-security-bug-laundry-machines-csc-serviceworks
#InfoSec #UniversityofCalifornia #UCSC
Another updated #introduction post
Hi my name is Rynn! I'm a 30 years old #furry #trans woman located in the eastern United States.Here are some fast facts about me:
#polyamorous - wielding dual partners
#asexual - grey, my horny cannot be quelled by mortals
#autistic / #adhd - Therapist was way more helpful than the Neuropyschologist
I've been doing IT for over a decade - currently a Network Administrator on a contract for multiple large projects.
I regularly post about #linux #plex #cloud #infosec and other tech screaming. I also draw, make pokemon sprites from perler beads, and futz with #homeimprovement projects in my ~120 year old house.


