Carl Johnstone

6.7K posts

Carl Johnstone

Carl Johnstone

@carljohnstone

Manchester, UK Katılım Mayıs 2009
188 Takip Edilen164 Takipçiler
Sabitlenmiş Tweet
Carl Johnstone
Carl Johnstone@carljohnstone·
Registered on Bluesky, if I know you and you're posting over there give me a follow and I'll follow you back again.
English
0
0
0
48
Carl Johnstone
Carl Johnstone@carljohnstone·
@Akely Same in our house today, well not the fish bit.
English
1
0
1
30
Björn Jansson
Björn Jansson@Akely·
Getting the Xmas ham ready while prepping the fish for today’s dinner.
Björn Jansson tweet mediaBjörn Jansson tweet media
English
2
0
4
119
Carl Johnstone retweetledi
Mykl Ü
Mykl Ü@MyklTheYankee·
@OrwellNGoode We I.T. folks have manual door locks, no appliances on the WIFI, no ring cameras, no Alexa or Google Home to listen in all the time. We use VPN's, nothing with windoze on it, and custom firmware on the router. If we, the experts, do this; ask yourself why that is.
English
4
4
36
7.6K
Jonathan Pie
Jonathan Pie@JonathanPieNews·
This is the fun bit.
Jonathan Pie tweet media
English
45
22
456
81K
Carl Johnstone
Carl Johnstone@carljohnstone·
@WigglePig @synx508 @devnetsecops @alexbloor Those policies are designed to appeal to specific voters, who believe that education was better back in the good old days, when it was all exams. They're not based on any evidence of what works better from an educational point of view.
English
0
0
0
17
Bloor (Mastodon: @bloor@bloor.tw)
I mean this is undesirable but hardly new. A Minister for Education who has never been a teacher and reports to a a Prime Minister who has never been a teacher and is advised by civil servants who have never been teachers - is about to advise teachers how to teach.
Alan Smith@AlanJLSmith

A chancellor who has never run a business and reports to a prime minister who has never run a business and is advised by civil servants who have never run a business - is about to advise business owners how to run a business.

English
1
0
2
521
Carl Johnstone
Carl Johnstone@carljohnstone·
@PBulteel @_chrisdunne @Scott_Helme Yes waiting for the software to be updated to incorporate an Acme client is the fix. The post I replied too suggested you could magically fix it by moving your software to the cloud.
English
1
0
0
38
Patrick Bulteel
Patrick Bulteel@PBulteel·
@carljohnstone @_chrisdunne @Scott_Helme By asking the vendor to implement an Acme client. I have started to see this on some enterprise applications. My hope is they don't "lock it down" to only public CAs like let's encrypt, but allow you to use Acme with your internal CA (like step-ca or hashicorp vault.)
English
1
0
0
60
Scott Helme
Scott Helme@Scott_Helme·
After stalling out on our progress in recent years, we finally have the first signs of movement to continue the reduction in certificate lifetime! scotthelme.co.uk/are-shorter-ce…
English
3
6
16
3.2K
Carl Johnstone
Carl Johnstone@carljohnstone·
@Scott_Helme @_chrisdunne @PBulteel I'm not saying that any of this is bad, will personally be really happy when we are at 45 days and it's all fully automated. Just pointing out that the change here will impact orgs with lots of Enterprise IT solutions faster than the software will adapt.
English
0
0
0
22
Carl Johnstone
Carl Johnstone@carljohnstone·
@Scott_Helme @_chrisdunne @PBulteel It's not really a public web site problem, that stuff is easily automated. However most Enterprise IT is web based these days, and because of the changes in the browser UX, you have to use TLS for everything internally these days to avoid the warnings etc.
English
1
0
0
21
Carl Johnstone
Carl Johnstone@carljohnstone·
@Scott_Helme @_chrisdunne @PBulteel These are certs so that business users can access the non-admin functions of the software via a browser. It's basically a web app, but comes as a packaged piece of software. I've seen products that don't provide a key, just generate a CSR for you to take to your CA.
English
0
0
0
21
Scott Helme
Scott Helme@Scott_Helme·
@carljohnstone @_chrisdunne @PBulteel But if the certificate is in there, then the private key is in there too, right? Are these your own keys and certs you’re installing for some TLS function, or provided by the vendor?
English
1
0
0
22
Carl Johnstone
Carl Johnstone@carljohnstone·
@PBulteel @_chrisdunne @Scott_Helme My concern is the software that's been designed in a way that makes it near impossible to automate cert rotation. Given typical software release/upgrade cycles, IT teams are going to be stuck picking up the burden with those systems in the short term.
English
1
0
0
35
Patrick Bulteel
Patrick Bulteel@PBulteel·
@_chrisdunne @Scott_Helme I'm not. It means companies have to figure out how to automate (even if we already have tons of clients that do it) and those that sell certs will have to change their pricing because who's going to pay £100 for a cert every 45 days (or less since they should renew before then)
English
2
0
0
42
Nick
Nick@Geddonz·
So proud of my little girl. She was chosen as captain for her cheerleading team!!
Nick tweet media
English
1
0
2
67
Nick
Nick@Geddonz·
Today I found out cows can’t see the colour red, and chickens can’t see blue…… how did people find that out?!?!
English
1
0
0
42
Carl Johnstone retweetledi
Channel 4 News
Channel 4 News@Channel4News·
Dyson abandons libel claim against Channel 4 News report
English
67
702
2.4K
417.2K
Carl Johnstone retweetledi
Ian Carroll
Ian Carroll@iangcarroll·
In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found. Here is our writeup: ian.sh/tsa
English
51
625
2.2K
188.3K
Troy Hunt
Troy Hunt@troyhunt·
Credit cards are easy. They're ubiquitous, work in-person, online, from your phone or your wrist and instantly assure the receiving party will be paid and can thus exchange a product. SO WHY IS THIS SO DAMN HARD?! On procurement, resellers and Stripe: troyhunt.com/the-trouble-wi…
English
7
10
42
16.6K
Carl Johnstone
Carl Johnstone@carljohnstone·
@Scott_Helme @stebets @troyhunt @reporturi You're both talking to somebody who has to live with it, rather than someone who writes the policy. Amusingly, the parallels with IT security are massive. Having to request permission before being able to gain privs, because there's a risk, so somebody wrote a policy.
English
1
0
0
89