Toots for ceresbzns@infosec.exchange account

Written by serious business :donor: :heart_cyber: on 2025-01-20 at 20:05

Yes, we could be living in a post-scarcity society where everyone's needs are provided for with dignity and people can live truly free lives pursuing their passions.

But... we don't.

So how do I profit from the President of the United States launching back to back shitcoins to grift addled rubes?

[#]cryptocurrency #uspol #economics #finance #ds9 #startrek

=> View attached media

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-15 at 18:05

Oh look! Payment processors are once again unilaterally stifling legitimate forms of expression and economic activity!

But let's not have meaningful discussions about permissionless and censorship-resistant monetary systems because THAT shit is for grifters and techbros, obviously

https://www.eff.org/deeplinks/2025/01/platforms-systematically-removed-user-because-he-made-most-wanted-ceo-playing

#paypal #shopify #banking #eff #bitcoin #ethereum #monero #economics #luigimangione #cryptocurrency

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-14 at 12:21

In a much lower stakes context, I now wonder (belatedly, in my early 40s) if the reason I seem to piss people off in corporate settings is that I try (naively?) to focus on the content of a discussion or situation (e.g., how do we solve for this technical or organizational problem in an economically efficient way), rather than trying to focus on playing to the status fulfillment of the various players in the scene (e.g., how do I make the highest ranking people feel good about themselves and attribute those positive feelings to me).

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-14 at 12:12

For a long time, I was caught off guard by these themes in sci-fi stories like Transmetropolitan and Banks' Player of Games.

Later, after Epstein and having spent more time in corporate America, I started to understand that this is a prevailing mode in a society like ours dominated by hierarchies and often predatory status seeking (two things that seem deeply intertwined.)

Transmet and other stories were trying to teach me a valuable, fundamental lesson - which is that people who are driven by seeking status through currencies of power (e.g., corporate executives, politicians, police) are exactly the same sort of people who will abuse women and children because it gives them the same feelings.

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-14 at 12:02

What always strikes me as particularly nasty about rich fucks abusing people is that it would be trivial for the abusers to use their wealth and fame to get the experiences they ostensibly want with consenting adults.

Instead, they prey on vulnerable people, which suggests that transgression and power over others is the actual underlying feeling they're seeking and the sex or whatever is a secondary concern.

So given a choice between using privilege to seek novel experiences and using privilege to insulate themselves from the consequences of predatory experiences, many choose the latter.

Is this a particularly harmful instantiation of status games? It seems like largely the same dynamics at work.

This is a toot about Neil Gaiman, but also some very significant portion of the ruling classes more broadly. To wit, Epstein et al.

[#]neilgaiman #politics #uspol #psychology #economics

CC @bhalpin

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-12 at 03:36

Quick update to this story:

It sounds like security updates are backported (thanks all for the feedback), so I'm just gonna leave the server running the way it is now

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2025-01-01 at 23:12

@joshbressers I got a meshtastic device. I've set it up. I've chatted with some folks on the local mesh.

...

n-now what?

[#]meshtastic

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-30 at 14:32

Bureaucratic controls will NEVER be sufficient. We must work to make the surveillance technically impossible or so expensive it's infeasible.

[#]infosec #cybersecurity #surveillance #uspol #law

=> View attached media

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-26 at 23:19

@ciaranmak what do you think?

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-26 at 23:19

Here's an interesting use case for the bullshit machine. You tell the LLM that it's some kind of service and then it talks to would-be scanners. I'm not sold it'd be worth the compute vs just running portspoof or some kind of recursive honeypot or other active defense / cyber deception measures, but there is something darkly funny about a hacker trying to craft payloads against a service when it's really just a bot wearing a hat that says "im a nginx server, i promise"

https://github.com/0x4D31/galah

[#]ai #llm #infosec #cybersecurity #cyberdeception #ActiveDefense

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-18 at 16:07

Two extremely painful stories of cryptocurrency phishing attacks from @briankrebs today: https://krebsonsecurity.com/2024/12/how-to-lose-a-fortune-with-just-one-bad-click/

tldr; one guy uploaded a picture of his keys to google photos, one guy entered his seed phrase into a website

In no way do I mean to victim blame, but these were both very basic errors. I think the problem, fundamentally, is that people treat cryptocurrency with the same level of security practices and thinking that they treat their bank or brokerage accounts, which to say, close to zero.

I think the lesson here is that every layperson cannot and should not be expected to become experts on secure key management.

Therefore, probably, I suspect the reasonable conclusion is that, at least until more secure technologies like multisigs and social recovery become more user-friendly and accessible, most cryptocurrency holders probably shouldn't self-custody.

As an example, in the first case, the dude also had coins on an exchange and they saved a good chunk of his bacon before it could be stolen.

[#]crypto #cryptocurrency #infosec #cybersecurity #bitcoin #trezor #coinbase

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-14 at 12:09

@thegrugq you might find this interesting!

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-14 at 12:08

Actually, I realize now a mitigation - airgapping machines used for signing transactions and machined used for commonplace knowledge work

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-12-05 at 18:24

[#]unitedhealthcare #uspol

=> View attached media

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-27 at 19:07

How do we feel about metasploit these days, cyber fam? Is it worth learning?

No Starch has a sale on the preorder of the 2nd ed of the metasploit book.

[#]metasploit #infosec #cybersecurity #pentesting #redteam

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-22 at 23:32

lol

lmao

Sauce: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-326a

[#]infosec #cybersecurity #redteam #cisa

=> View attached media

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-19 at 01:09

"The end justifies the means. But what if there never is an end? All we have is means."

Ursula K. Le Guin, The Lathe of Heaven

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-10 at 15:05

Channeling my anxiety by stocking up on shelf-stable goods

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-05 at 13:57

Wild ass day in the Tor node operator world. Got an email from my VPS, forwarding a complaint from WatchDog CyberSecurity saying that my box was scanning SSH ports!

Oh no, oh no, I knew I should have set up fail2ban, oh god why was I so lackadaisical!

So I remote in to the machine: no unusual network activity, no unusual processes, users, logins, command history, no sign that anything is doing anything I didn't tell it to do.

So what's up? Turns out there's been a widespread campaign where some actor is spoofing IPs to make it look like systems running Tor are scanning port 22: https://forum.torproject.org/t/tor-relays-tor-relays-source-ips-spoofed-to-mass-scan-port-22/15498/14

Operators from all over are saying they're getting nastygrams from their VPS providers because WatchDog is fingering their source IPs (which are being spoofed and NOT part of a global portscanning botnet).

@delroth did an amazing writeup of the whole thing here: https://delroth.net/posts/spoofed-mass-scan-abuse/

[#]tor #infosec #cybersecurity #threatintel #privacy

=> More informations about this toot | View the thread

Written by serious business :donor: :heart_cyber: on 2024-11-05 at 01:30

Great British Bake Off is clearly a Project of British Unity and for the first dozen years always included at least one person from the non-English regions: N Ireland, Scotland, Wales.

This year, no Irish or Scottish person in the tent. Feels deliberate. A statement? A portent?

[#]gbbo

=> More informations about this toot | View the thread

=> This profile with reblog | Go to ceresbzns@infosec.exchange account

Proxy Information
Original URL
gemini://mastogem.picasoft.net/profile/109673308832658761
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
589.772079 milliseconds
Gemini-to-HTML Time
7.107181 milliseconds

This content has been proxied by September (3851b).