@0xtero@ohai.social cover

Glorified network janitor. Perpetual blueteam botherer. Pretengineer. Friendly neighborhood cyberman. Constantly regressing toward the mean. Slowly regarding silent things.

This profile is from a federated server and may be incomplete. View on remote instance

@Daojoan@mastodon.social avatar Daojoan , to random

Nobody on LinkedIn has ever had a bad day. Every setback is a "growth opportunity." Every firing is a "new chapter." Every complete professional disaster is framed as "excited to announce." These people would describe the Titanic as "a bold pivot to submarine operations."

0xtero ,
@0xtero@ohai.social avatar

@Daojoan And that's not even the worst part about LinkedIn.

There's a whole professional category of people who think a platform that drives its user-base to this type of insanity is ACTUALLY VALUABLE recruitment tool.

That's the truly depressing part.

@evacide@hachyderm.io avatar evacide , to random

Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning.

https://www.therage.co/persona-age-verification/

0xtero ,
@0xtero@ohai.social avatar

@evacide surely Discord's third age-verification partner will be completely TRUSTED and DEPENDABLE and not at all part of the Torment Nexus being built around these services.

@Viss@mastodon.social avatar Viss , to random

it will never stop being weird that you can get MOST of what good humor makes, the brand that makes cornetto, in the states, EXCEPT cornetto.

you can even get them in canada and mexico.
just not inbetween

0xtero ,
@0xtero@ohai.social avatar

@Viss Making a note that next time you're around here, I need to introduce you to this

0xtero ,
@0xtero@ohai.social avatar

@Viss It's open! ALL OF THE LLMs. Please.

https://cfp.securityfest.com/2026/

@taylorlorenz@mastodon.social avatar taylorlorenz , to random

I’ve been asked on TV hits and interviews lately to explain why decentralized social media is better, especially re: Mastodon.

How would you explain the benefits of a platform like Mastodon and the fediverse to someone in just a few sentences? How would you make the argument that platforms like Mastodon allow for more free expression than big tech controlled apps?

Would love to hear people’s thoughts! Trying to make my arguments most effective

0xtero ,
@0xtero@ohai.social avatar

@taylorlorenz You have a global reach and audience through federation, but you're still moderated by your local, familiar community - which you yourself have a complete freedom to choose on your own, not some faceless machine algorithm or billionaire whims.

@nixCraft@mastodon.social avatar nixCraft , to random

What was the first programming language you ever learned & what did you build with it? 🤔

0xtero ,
@0xtero@ohai.social avatar

@nixCraft BASIC on ZX Spectrum. I guess it might have been an endless loop of printing something on the screen.

@briankrebs@infosec.exchange avatar briankrebs , (edited ) to random

How to waste a day debunking someone else's scoop:

Someone forwarded me this recent story from Straight Arrow News (a publication I didn't previously know existed) which rather breathlessly claimed millions of cars were at risk from new custom firmware sold by a Russian hacker that would enable Flipper Zero users to unlock the doors and trunks of countless makes and models of different cars for a few hundred bucks. Basically, turn the Flipper into a sub-Ghz repeater that can intercept and replay the radio signal sent out when someone presses their car key fob.

https://san.com/cc/millions-of-cars-at-risk-from-flipper-zero-key-fob-hack-experts-warn/

I was skeptical of this story because I recalled reading a blog post from Flipper last year after the Canadian government said it was going to ban flippers. In response, Flipper Devices wrote:

"We are not aware of any officially confirmed cases of theft using a Flipper Zero. This is because the device has limited functionality and can't be used as a repeater to attack keyless entry systems. Flipper Zero is equipped with only one sub-1 GHz radio module, while keyless repeaters have 4 radio modules: one for communication with the car, another one for communication with the key fob, and two for communication between the repeaters."

https://blog.flipper.net/response-to-canadian-government/

It took several hours of questioning the Russian guy on Telegram for him to admit that using his firmware successfully requires additional radio units and other stuff not pictured in most of his sales videos.

https://www.youtube.com/@DjonixTV/videos

I asked him whether he was at all concerned that the Russian authorities might be interested in him, and he curtly replied that this was his concern, not mine. Later he asked why I'd asked this question.

It turns out, in one of his videos he replied to a comment by posting a Google Docs link to a spec and pricing sheet. Clicking "details" on the Google Docs file showed a username and author: [email protected]. Searching on this address in breach tracking services finds it is associated with multiple Russian government records saying the email belongs to a guy from Moscow named Danil Viktorovich Doragu who uses the phone number 79267824950. That phone number is tied to a Telegram account for user "r3df0xx," and a search on this username in Intel 471 finds Daniel has been selling custom firmware for Flipper devices for several years. Oh, and his LinkedIn profile includes a link to the GitHub account "DarkFlippers."

https://www.linkedin.com/in/daniil-dogaru-a58199208/

0xtero ,
@0xtero@ohai.social avatar
@nixCraft@mastodon.social avatar nixCraft , to random

If any random app asks for government issued IDs with a selfie, it's a major red flag. 🚩 Do not provide them. Please share this warning with all your friends/family. You should only provide government issued ID when it's for something critical, such as:

  • Getting a passport
  • Obtaining a citizenship card
  • Acquiring a driving license
  • Opening bank accounts
    Any other request for your ID by any app will likely lead to it being leaked or sold, putting everyone at risk. It's a sad reality
0xtero ,
@0xtero@ohai.social avatar

@nixCraft over here pretty much all services use your digital ID though. Sending in photos/scans of your real ID seems just weird.

@stux@mstdn.social avatar stux , to random

Haha beta’s are so much fun :blobcatgiggle: Can’t get my icons back but it’s more of a challenge

ALT
0xtero ,
@0xtero@ohai.social avatar

@stux perfection

@0xtero@ohai.social avatar 0xtero , to random

@dansup we might need couple of evolutionary cycles and a glacial period to get rid of the faulty homo sapiens line before we can get there, took us quite a while to wipe out the other human spices after all and now that we’ve killed everything else, we’re killing each others and our habitat , because there’s nothing else left. But one day…

@JessTheUnstill@infosec.exchange avatar JessTheUnstill , to random

[Thread, post or comment was deleted by the author]

  • Loading...
  • 0xtero ,
    @0xtero@ohai.social avatar

    @JessTheUnstill you can’t graduate to seniority unless you’ve messed up at least one business critical system during your career.
    It’s a rite of passage and the stories should be told around every camp fire.

    @jerry@infosec.exchange avatar jerry , to random

    I need advice. There are hundreds of people that think my Gmail address is theirs, and over the years it’s been quite annoying. Someone recently engaged a realtor using my email address. When I went to unsubscribe to the “house finder” service, it has that person’s phone number.

    Now I know what the right thing to do it. But I’m not sure that’s what I’m doing to do. What would you do?

    0xtero ,
    @0xtero@ohai.social avatar

    @jerry I inherited someones old phone number years ago. I get notifications about all his his flights (along his name and other personal info). I've contacted him and asked him to change it. It continues.

    So now I just move him to the back och the plane, center seat and unbook his rental car.

    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    Another interview with Bluesky CEO Jay Graber, but this one features maybe her best articulation yet of Bluesky's vision and appeal. "Nobody is fully grasping that this is potentially the last social identity you have to create." It's a "digital passport that moves with you." https://www.wired.com/story/big-interview-jay-graber-bluesky/

    0xtero ,
    @0xtero@ohai.social avatar

    @kevinrothrock They say that, yet the verified identity is local to the Bluesky PDS. It doesn't federate. Some other instance, in the future, might implement completely different verification scheme. So yes, it moves with you, as long as you keep your data on the official BlueSky instance.

    Also. There are no other instances.

    They went from having great promise into yet another Twitter clone.

    @evacide@hachyderm.io avatar evacide , to random

    So much of cybersecurity is "We must secure the Orphan Crushing Machine so that unauthorized people do not crush the orphans," and not "Why the fuck are you building an Orphan Crushing Machine in the first place?"

    0xtero ,
    @0xtero@ohai.social avatar

    @evacide @mattblaze easy now or someone will offshore the Orphan Crushing Machine and then we’ll have Orphan Crushing Supply-Chain security to worry about as well!

    @coffeegeek@flipboard.social avatar coffeegeek , to random

    Linkin Park's first album in 8 (?) years dropped today. From Zero. Find it on your favourite music service, it''s awesome. The new front woman Emily Armstrong sounds excellent; has a Chester vibe with her own style.

    https://music.apple.com/us/album/from-zero/1766137049

    0xtero ,
    @0xtero@ohai.social avatar

    @coffeegeek three songs under 3 minutes made me wish they'd released a double album! It felt too short! 😀

    @dansup@mastodon.social avatar dansup , to random

    [Thread, post or comment was deleted by the author]

  • Loading...
  • 0xtero ,
    @0xtero@ohai.social avatar

    @dansup Only in northern parts I think. The Nordics are pretty introverted.