Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

tychotithonus@infosec.exchangeT

tychotithonus@infosec.exchange

@tychotithonus@infosec.exchange
About
Posts
19
Topics
5
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Recently I learned about Cyber-informed Engineering:
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    Recently I learned about Cyber-informed Engineering:

    Just a moment...

    favicon

    (inl.gov)

    How do I turn “what ifs” into “even ifs”?

    💡 🧙 💪

    Uncategorized

  • Whoever designed the schema for the censys offline data.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @darfplatypus I haven't seen it since it was publicly downloadable. Is it still one line per record wrapped JSON? The first thing I did in those days was convert it to per-type TSVs, usually reducing its cumulative size by half.

    Uncategorized

  • Happy Alberti Day, @a1batross.bsky.social !
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    Happy Alberti Day, @a1batross.bsky.social !

    Link Preview Image
    Forbidden : NYC Parks

    favicon

    (www.nycgovparks.org)

    PETER CAESAR ALBERTI
    FIRST ITALIAN SETTLER
    LANDED IN N.Y. JUNE 2, 1635

    Uncategorized

  • Hmm.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @mhoye "Hmm, someone's clock is off"

    But in theory, there's supposed to be like 30s of slush time on either side for exactly such drift.

    But if the app also has a "check a log for recent logins" feature, might be good to make sure someone else didn't use it.

    Uncategorized

  • #Signalapp doesn't actually delete messages when they're deleted (either manually or by automation).
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @harrysintonen To confirm ... only validated affected setup so far is Signal Desktop on macOS?

    Uncategorized signalapp fulldisclosure infosec cybersecurity

  • Are there answers to "what can go wrong" which are not threats (in the sense of possible future problems, "He threatened to beat me up," or "it threatened to rain")
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @adamshostack "Don't threaten me with a good time!" 😉

    Uncategorized

  • they have a solid point, y'know.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @phessler

    Each individual user may not consider a given credential as worth needing MFA, but since most users reuse passwords, it's arguably better move for the ecosystem and site operators to require some kind of MFA. Otherwise, if one site gets popped, a wave of user accounts could be abused in bulk and require operator intervention. Whether or not mass lockout/reset is inconvenient enough for the individual user to think MFA is a good trade-off may vary.

    @munin

    Uncategorized

  • Did you know…?
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @fugueish I ſee what you did there!

    Uncategorized

  • Got an email from Apple: "You have signed the following agreement: Apple Developer Agreement"
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    Got an email from Apple: "You have signed the following agreement: Apple Developer Agreement"

    The fact that this email was a surprise is strong circumstantial evidence of a dark pattern.

    Uncategorized

  • Voice modems (from Computers Are Bad)
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    I'm a big fan of this project, which uses "hard" USB modems with voice features as Caller-ID-aware call filtering. It's the only way my parents could keep their landline.

    Link Preview Image
    GitHub - thess/callattendant: A python-based automated call attendant, call blocker, and voice messaging system running on a Raspberry Pi or equivalent. Screens callers and block robocalls and scams with a low-cost system and modem.

    A python-based automated call attendant, call blocker, and voice messaging system running on a Raspberry Pi or equivalent. Screens callers and block robocalls and scams with a low-cost system and modem. - thess/callattendant

    favicon

    GitHub (github.com)

    Passively listens on another extension in the house, so the first ring will come through, but if you have a modern cordless phone, you can often program it to suppress the first ring.

    I have my own resources for the project here, including how to adopt a "default mostly deny" policy by using publicly available telecom exchange data.

    Link Preview Image
    GitHub - roycewilliams/callattendant-resources: grab-bag of callattendant-related materials

    grab-bag of callattendant-related materials. Contribute to roycewilliams/callattendant-resources development by creating an account on GitHub.

    favicon

    GitHub (github.com)

    Uncategorized

  • Trying to level up a language from "Your $language is so good!" to "Where are you from?" is a grind.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @axx $spouse grew up here (Alaska)

    Uncategorized

  • Trying to level up a language from "Your $language is so good!" to "Where are you from?" is a grind.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @evacide My $spouse, a native speaker of US English, is somewhat regularly asked what country she's from. I would love having a linguist + speech therapist determine root cause for this!

    Uncategorized

  • Aftermath: people, running Debian httpd 2.4.66, started complaining when they’ll get the 2.4.67 update to fix this RCE vulnerability.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @DaveMWilburn Not disagreeing - I think Eissing is using "responsible" here on purpose, rather than "coordinated"

    Uncategorized cve202623918

  • DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @gnomon it's in the blog post. Eissing shows the timeline

    Uncategorized cve202623918

  • DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @Andres4NY Parent post updated, apparently CVE-2026-23918 was fixed much earlier?

    Uncategorized cve202623918

  • Aftermath: people, running Debian httpd 2.4.66, started complaining when they’ll get the 2.4.67 update to fix this RCE vulnerability.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    RE: https://chaos.social/@icing/116526903529846107

    Aftermath: people, running Debian httpd 2.4.66, started complaining when they’ll get the 2.4.67 update to fix this RCE vulnerability. Which they already were protected from, but did not know. Because the CVE was not public at the time the fix was shipped.

    [...]

    Two security researchers found the vulnerability independently. Just scanning the 2.4.66 source code. This means the bad guys can no longer be kept in the dark. Coordinated disclosure no longer works.

    #CVE_2026_23918

    Uncategorized cve202623918

  • DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @Andres4NY Ah, thanks - I was just going to start asking!

    Uncategorized cve202623918

  • does anyone know of any computer programs that are good?
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    @lindsey ddrescue!

    Uncategorized

  • DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.
    tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.

    Me: Thanks! Are your distro repos updated to contain the patched version?

    DO: lol no

    [Edit: to be fair, this is Debian's fault, not DOs (see screenshot). At least DO told me!]

    [Edit 2: that specific vuln was quietly fixed on Debian specifically well before this version?? Would be advisable for them to have said that now?
    https://infosec.exchange/@tychotithonus/116527548611779862 ]

    #CVE_2026_23918

    Uncategorized cve202623918
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups