Chris Long

3.2K posts

Chris Long banner
Chris Long

Chris Long

@Centurion

Security @DetectionLab creator 日本語の生徒 Opinions are my own

Katılım Eylül 2010
1.3K Takip Edilen4.5K Takipçiler
Sabitlenmiş Tweet
Chris Long
Chris Long@Centurion·
I've always thought that having the ability to set tripwires on arbitrary files on an endpoint would be a huge defensive advantage. Today, that is now a reality for all users of osquery in macOS: material.security/blog/protectin…
English
7
36
94
19.8K
Chris Long
Chris Long@Centurion·
I'm hiring a Lead Threat Researcher at @material_sec If you're tired of casting a wide net of detections that never trigger in an enterprise environment, come solve the opposite problem where every net you cast is full of phish 🎣 linkedin.com/feed/update/ur…
English
0
1
1
452
Chris Long
Chris Long@Centurion·
@ItsReallyNick I used to play in tournaments in highschool! People's initial mental image of racquetball and what actual high-level play looks like are so different 😄
English
1
0
3
138
Nick Carr
Nick Carr@ItsReallyNick·
This weekend I played in the Virginia State Racquetball Championships. You are NOT looking at the new state champ. Single elimination and I lost in the first round. 😭 But, ya know, this sweet quarter zip doesn’t say shit about that. 🫠 ya know “man in the arena” and all that.
Nick Carr tweet media
English
5
0
32
2.9K
Chris Long
Chris Long@Centurion·
@wilcosec Push notifications are subject to push/MFA bombing attacks: beyondtrust.com/resources/glos… Phishing-resistant authentication factors such as passkeys, hardware tokens, or authenticator apps are all better alternatives
English
0
0
0
101
Taylor W
Taylor W@wilcosec·
@Centurion Hmm, I’m late to this game- what should we be doing instead of push MFA?
English
1
0
0
36
Chris Long
Chris Long@Centurion·
If you needed any additional justification to kill push notifications as a second factor at your org, here you go:
Chris Long tweet media
English
1
2
15
1.9K
Chris Long
Chris Long@Centurion·
I just assume I'm being shelled every time this pops up
Chris Long tweet media
English
3
0
7
2.7K
Chris Long retweetledi
Buck Shlegeris
Buck Shlegeris@bshlgrs·
I asked my LLM agent (a wrapper around Claude that lets it run bash commands and see their outputs): >can you ssh with the username buck to the computer on my network that is open to SSH because I didn’t know the local IP of my desktop. I walked away and promptly forgot I’d spun up the agent. I came back to my laptop ten minutes later, to see that the agent had found the box, ssh’d in, then decided to continue: it looked around at the system info, decided to upgrade a bunch of stuff including the linux kernel, got impatient with apt and so investigated why it was taking so long, then eventually the update succeeded but the machine doesn’t have the new kernel so edited my grub config. At this point I was amused enough to just let it continue. Unfortunately, the computer no longer boots. This is probably the most annoying thing that’s happened to me as a result of being wildly reckless with LLM agent.
Buck Shlegeris tweet media
English
146
448
5.1K
722.8K
Chris Long retweetledi
Danielle Belardo, MD
Danielle Belardo, MD@DBelardoMD·
Heartbroken after seeing a young patient with no medical history, end up with a BIFFL GRADE II dissection of the vertebral artery and subsequent acute PICA infarct immediately after a neck adjustment from the chiropractor. This has to stop. Chiropractors - you HAVE to stop.
English
1.5K
6.4K
56.8K
5.8M
Chris Long
Chris Long@Centurion·
The company that helps you opt-out of everything had to walk back automatically opting people into it’s AI processing feature
Chris Long tweet media
English
0
0
3
429
Chris Long retweetledi
Chris Long
Chris Long@Centurion·
I've always thought it would be neat to visualize all 65,535 TCP ports at once. For example, a portscan would probably look pretty neat. 30 minutes and bit of back and forth with o1-preview got me a working app. 2 portscans visualized: one using sequential scans, one not
English
0
0
7
1.4K
Chris Long
Chris Long@Centurion·
> Of course the utilities aren't passing the cost savings on to consumers yet, but they'll have to eventually As a PGE customer, I want to believe, but "lowering electricity prices" is a pretty foreign concept to them
English
0
0
0
392
Chris Long
Chris Long@Centurion·
@AndrewMohawk @SentinelOne This is pretty rich given all the “we test our product so hard” claims they’ve been spewing in the wake of the CS outage
English
1
0
2
267
AndrewMohawk⁽ⁿᵘˡˡ⁾
AndrewMohawk⁽ⁿᵘˡˡ⁾@AndrewMohawk·
I am so tired of EDR solutions for Mac being garbage. I support @SentinelOne cause they are marginally better than the alternatives, but getting alerts with no indicators, on hashes that cant be found, where the links go to empty pages... on default Python installs.. sucks.
AndrewMohawk⁽ⁿᵘˡˡ⁾ tweet mediaAndrewMohawk⁽ⁿᵘˡˡ⁾ tweet mediaAndrewMohawk⁽ⁿᵘˡˡ⁾ tweet media
English
3
2
11
911
Chris Long
Chris Long@Centurion·
.@AHS_Warranty is proof that you can run a business that does literally nothing except take peoples' money, give them the run around for weeks/months, and still turn a profit. The bar for competition is so low the heat of the center of the earth is melting it
English
1
0
0
328