Publidave

1.2K posts

Publidave banner
Publidave

Publidave

@publidave

0.5X engineer, interested in many things and least bad at infosec

UK Katılım Aralık 2012
25 Takip Edilen150 Takipçiler
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@FuzzySec That’s a great point. We need to be able to sign content don’t we……
English
3
0
3
245
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
Very impressive honestly. We urgently need cryptographic guarantees that prove authenticity of images and A/V. I don’t understand how this isn’t a huge topic except that social media platforms probably don’t want to implement his.
OpenAI@OpenAI

Sound on.

English
6
4
41
7.6K
Oddvar Moe
Oddvar Moe@Oddvarmoe·
A pirate ship full of hackers. What could possibly go wrong?
Oddvar Moe tweet media
English
17
4
205
16.3K
Publidave
Publidave@publidave·
@j0hn__f @jukelennings No, but at some point they need an incentive to crack down on it as they still get paid for malvertising clicks
English
0
0
0
104
john fitzpatrick
john fitzpatrick@j0hn__f·
@jukelennings This one is entirely on Google IMO. Looking at our timelines, we saw this infra born at midnight, the domain itself was purchased a couple of hours earlier from namecheap and, as you highlight, the advertiser is unverified. Let's be blunt, did google need any more red flags?
English
1
0
1
487
Luke Jennings
Luke Jennings@jukelennings·
Someone is using Evilginx to target customers of Onfido, part of Entrust, with a malicious Google advert that comes above the legitimate Onfido advert 🤯 Yes that us[.]com domain is actually an evilginx server - guess which advert is the malicious one
Luke Jennings tweet mediaLuke Jennings tweet mediaLuke Jennings tweet media
English
2
17
26
6.3K
Dino A. Dai Zovi
Dino A. Dai Zovi@dinodaizovi·
🤯*context window of 10M tokens* that you can run locally...
English
2
0
3
815
Publidave
Publidave@publidave·
@peterwildeford I’d argue SSI have slightly missed the threat model: faraday stops the phone communicating at that time, typically used to prevent wipe commands arriving. If there is malware on the phone the important bit is leaving it outside the room so it can’t record meeting.
English
1
0
1
35
Peter Wildeford🇺🇸🚀
Peter Wildeford🇺🇸🚀@peterwildeford·
"Candidates who secure an in-person interview are instructed to leave their phone in a Faraday cage before entering SSI’s offices" wow
Peter Wildeford🇺🇸🚀 tweet media
English
15
9
450
53.1K
Publidave
Publidave@publidave·
@JackRhysider @fir3d0g @HackingDave I made a custom GPT that estimates from a photo the macros and outputs it in a strict json formula, then I long touch and copy it, a triple tap on my iPhone triggers the shortcut to grab json out of clipboard and parse it all into apple health
English
0
0
0
30
Dave Kennedy
Dave Kennedy@HackingDave·
Still got 500 cals remaining. This cut is easy when you’ve gained so much muscle mass 😂. 2800 calories a day, dropping 3lbs a week.
Dave Kennedy tweet media
English
9
0
23
7.4K
Publidave
Publidave@publidave·
@UK_Daniel_Card Cracks me up how many students leave hacking/it courses and have never heard of a change request
English
0
0
0
9
mRr3b00t
mRr3b00t@UK_Daniel_Card·
I honestly think people need to understand more about how 'business systems' work....
mRr3b00t tweet media
English
3
4
33
3.7K
Publidave
Publidave@publidave·
@DaveShapi My dude it is a superpower, when it comes to negotiation just leverage the tism. I told them I only cared about total price, if he can help me pay a lower total price by me taking additions that give him commission I’m in, got a great deal, way lower than sticker
English
0
0
0
13
David Shapiro (L/0)
David Shapiro (L/0)@DaveShapi·
Either I'm too autistic for car dealerships and salesmen, or these institutions are just intrinsically not autistic friendly. Like, do neurotypical people really not understand how fake, manipulative, and exploitative car dealerships are? Clearly an autistic person was not involved in the design of such a pointless, exhausting, artificial experience.
English
83
5
258
16.5K
Publidave
Publidave@publidave·
@MalwareJake Genuinely saw one phishing test a couple years back where the lure was financial and mental health support for troubles during covid, someone absolutely should have sued
English
0
0
0
23
Jake Williams
Jake Williams@MalwareJake·
PSA: nobody is checking your phish-testing lures for built-in biases, etc. If you're punishing/shaming/etc. employees failing these tests, then you're setting yourself up for employment lawsuits - and honestly, they're suits you'll probably lose.
English
8
7
64
7.9K
Publidave
Publidave@publidave·
@spoofyroot What sort of features stayed useful after the novelty period? Can see having fun for a few days but wasn’t sure I’d keep using them
English
0
0
0
21
Johnathan Norman
Johnathan Norman@spoofyroot·
A friend at Meta gave me some of the Ray-Ban Meta glasses. I've used them for a bit now and I have to say I'm quite impressed. There are some genuinely useful AI features which (sadly) is rare to see these days.
English
1
0
7
1.2K
Publidave
Publidave@publidave·
@TracketPacer Can you use hubs to beat 802.1x if you have physical access to cable going into an authenticated device or have I been hanging onto my 20yr old hub for nothin? 😅 not actually tried it. If not you’re welcome to it!
English
0
0
0
16
Halvar Flake
Halvar Flake@halvarflake·
... Or 700g of skirt steak a day, and I haven't found any real food that has more than 25-30g of protein per 100g. How do people get to these numbers? It seems insane. I can comfortably do half that, but ...
English
9
0
8
5.5K
Thomas Godden
Thomas Godden@GoddenThomas·
Today I learned that SIM cards have a decently powerful MCU on them and run Java.
English
115
325
7.8K
1.2M
Publidave
Publidave@publidave·
@blackroomsec @UK_Daniel_Card I genuinely find Twitter is amazing for surfacing the stuff I need to care about, have managed to curate my follows such that good blogs, write ups etc tend to hit my feed and so I don’t need to worry about keeping on top of raw reports
English
0
0
0
19
BlackRoomSec
BlackRoomSec@blackroomsec·
My friend @UK_Daniel_Card mentioned managing threat intel feeds the other day and I would like to apologize to him for flippantly responding in a manner which suggested I had it under control. At the time I sincerely thought I did but having not checked my email in a day and now having 85 pieces of mail (which are AGGREGATED from a multitude of sources, btw), I realize this was a premature comment to make. I'm sorry, fren. I'm a dummy. ❤️ With this in mind, assuming the hacker (read: me and I'll include Dan in this and many of you, too) has tapped into every available feed out there, how is this best managed? Meaning, have any of you found a free way to get all of them in one place without repetition and for the outcome to actually be meaningful? If so, would you mind sharing please? If nothing I said is making any sense to you, that's OK, what I'm referring to is all the current news du jour about new threats, viruses, breaches, generalized cybersecurity news, generalized tech news etc. I use Mail Brew but as I'm pulling from so many sources there are so many duplicates. I'd like it to be more streamlined. Thank you for reading.
English
8
3
44
5.9K
Sir Humphrey
Sir Humphrey@pinstripedline·
Between 1980 and 1994 the Royal Navy submarine service conducted over 130 highly classified missions to gather intelligence or covert operations. Even though the files are closed, it is still possible to draw some significant conclusions from the archives. /1
Sir Humphrey tweet media
English
29
167
1.5K
538.3K
Publidave
Publidave@publidave·
@__invictus_ What’s sad/amusing is this was the original definition of zero trust by forrester, but now the term means the exact opposite
English
0
0
0
57
Allen Jones
Allen Jones@ajMSFT·
@Laughing_Mantis Your post makes my mind race on what new r/e and forensic capabilities that’ll probably be required and the new attack surfaces. “Hey, check out this new model I downloaded. Never mind it's called FREE_CANDY. I’m sure it's fine.”
English
1
0
0
124
Greg Linares (Laughing Mantis)
Greg Linares (Laughing Mantis)@Laughing_Mantis·
I have spent the last few weeks looking over AI startups and their historical hiring pages and what I discovered was sadly not too surprising: Out of the 42 AI startups I went thru - only 6 had ever publicly posted open direct infosec roles ever. It's gonna be a bloodbath
English
17
42
205
27.8K