Publidave
1.2K posts

Publidave
@publidave
0.5X engineer, interested in many things and least bad at infosec
UK Katılım Aralık 2012
25 Takip Edilen150 Takipçiler

I made my phone a dumbphone with this Apple Configurator and my life is immeasurably more enjoyable.
Publidave@publidave
@DakotaInDC @Apple This person is using Apple Configurator to achieve that stopa.io/post/297
English

Very impressive honestly. We urgently need cryptographic guarantees that prove authenticity of images and A/V. I don’t understand how this isn’t a huge topic except that social media platforms probably don’t want to implement his.
OpenAI@OpenAI
Sound on.
English

Please, @Apple. I will pay $1K for a mostly dumb phone. You don’t make money on the attention economy. Help free the people from brain rot.
Dakota Cary@DakotaInDC
At this point I just want a dumb phone made by Apple. Please give me signal, uber, NFC tap to pay, and iOS security and a number pad.
English

@vxunderground @Oddvarmoe Where’s Waldo but with looking for a woman
English

@j0hn__f @jukelennings No, but at some point they need an incentive to crack down on it as they still get paid for malvertising clicks
English

@jukelennings This one is entirely on Google IMO.
Looking at our timelines, we saw this infra born at midnight, the domain itself was purchased a couple of hours earlier from namecheap and, as you highlight, the advertiser is unverified. Let's be blunt, did google need any more red flags?
English

@peterwildeford I’d argue SSI have slightly missed the threat model: faraday stops the phone communicating at that time, typically used to prevent wipe commands arriving. If there is malware on the phone the important bit is leaving it outside the room so it can’t record meeting.
English

@JackRhysider @fir3d0g @HackingDave I made a custom GPT that estimates from a photo the macros and outputs it in a strict json formula, then I long touch and copy it, a triple tap on my iPhone triggers the shortcut to grab json out of clipboard and parse it all into apple health
English

@fir3d0g @HackingDave i'm gonna train a chatgpt agent to just nag me every couple hours "whatcha eatin?" and have it track it for me
English

@UK_Daniel_Card Cracks me up how many students leave hacking/it courses and have never heard of a change request
English

@DaveShapi My dude it is a superpower, when it comes to negotiation just leverage the tism. I told them I only cared about total price, if he can help me pay a lower total price by me taking additions that give him commission I’m in, got a great deal, way lower than sticker
English

Either I'm too autistic for car dealerships and salesmen, or these institutions are just intrinsically not autistic friendly.
Like, do neurotypical people really not understand how fake, manipulative, and exploitative car dealerships are? Clearly an autistic person was not involved in the design of such a pointless, exhausting, artificial experience.
English

@MalwareJake Genuinely saw one phishing test a couple years back where the lure was financial and mental health support for troubles during covid, someone absolutely should have sued
English

@spoofyroot What sort of features stayed useful after the novelty period? Can see having fun for a few days but wasn’t sure I’d keep using them
English

@TracketPacer Can you use hubs to beat 802.1x if you have physical access to cable going into an authenticated device or have I been hanging onto my 20yr old hub for nothin? 😅 not actually tried it. If not you’re welcome to it!
English

@blackroomsec @UK_Daniel_Card I genuinely find Twitter is amazing for surfacing the stuff I need to care about, have managed to curate my follows such that good blogs, write ups etc tend to hit my feed and so I don’t need to worry about keeping on top of raw reports
English

My friend @UK_Daniel_Card mentioned managing threat intel feeds the other day and I would like to apologize to him for flippantly responding in a manner which suggested I had it under control. At the time I sincerely thought I did but having not checked my email in a day and now having 85 pieces of mail (which are AGGREGATED from a multitude of sources, btw), I realize this was a premature comment to make. I'm sorry, fren. I'm a dummy. ❤️
With this in mind, assuming the hacker (read: me and I'll include Dan in this and many of you, too) has tapped into every available feed out there, how is this best managed? Meaning, have any of you found a free way to get all of them in one place without repetition and for the outcome to actually be meaningful? If so, would you mind sharing please?
If nothing I said is making any sense to you, that's OK, what I'm referring to is all the current news du jour about new threats, viruses, breaches, generalized cybersecurity news, generalized tech news etc. I use Mail Brew but as I'm pulling from so many sources there are so many duplicates. I'd like it to be more streamlined.
Thank you for reading.
English

Does the NCA get the $10mill bounty? Seems only fair to me
National Crime Agency (NCA)@NCA_UK
Khoroshev, AKA LockBitSupp, who thrived on anonymity and offered a $10 million reward to anyone who could reveal his identity, will now be subject to a series of asset freezes and travel bans.
English

The blog may be of interest to @NavyLookout @UKDefJournal @EngageStrategy1 @fightingsailor @IBallantyn @SSN14CO @CovertShores @SubBrief @Saturnax1 @USN_Submariner @DaveGOwen @GaskarthJamie @MarkUrban01 @gordoncorera @RoryCormac among others!
English

@__invictus_ What’s sad/amusing is this was the original definition of zero trust by forrester, but now the term means the exact opposite
English

I'm going to take this a step further and say segmentation has the biggest impact on early detection of an attack.
Adversaries are generally lazy in the sense that they will take the path of least resistance.
1/n
Dominic Chell 👻@domchell
The most effective controls I see in my red team engagements are practically cost-free… host based firewalls and tight segmentation give red teams a total headache
English

@Laughing_Mantis Your post makes my mind race on what new r/e and forensic capabilities that’ll probably be required and the new attack surfaces. “Hey, check out this new model I downloaded. Never mind it's called FREE_CANDY. I’m sure it's fine.”
English



















