Josh Summitt

2 Followers
68 Following
59 Posts
CTO, hacker, builder of modular synths, drinker of all things bourbon. Founder of Faction Security and co-founder of Otto-JS Security:
https://www.factionsecurity.com
https://www.otto-js.com
GitHubhttps://www.github.com/summitt
Otto JavaScript Securityhttps://www.otto-js.com
Faction Securityhttps://factionsecurity.com
Don't miss day 1 of our State of the Onion on Wednesday, 29 Nov. Check out the full program here: 🗓️https://blog.torproject.org/state-of-the-onion-2023/
Join us for the State of the Onion 2023 | Tor Project

We will be hosting our annual State of the Onion livestream, a virtual two-day event featuring the Tor Project's different teams presenting highlights of their work from 2023 and what we are excited about in the upcoming year, on November 29th and December 6th from 17:00 - 18:00 UTC.

I'm really excited to announce that I've just open-sourced FACTION, a Security Assessment Collaboration project that I've been working on in the background for many years.

It's mostly geared around #appsec #pentesting and provides many features to make your life easier like:

1. Report Automation and Templating
2. Vulnerability Remediation Tracking
3. APIs and Integrations with other tools
4. Assessment Scheduling
5. Vulnerability Templates

You can check out at the link below!

https://github.com/factionsecurity/faction

GitHub - factionsecurity/faction: Pen Test Report Generation and Assessment Collaboration

Pen Test Report Generation and Assessment Collaboration - factionsecurity/faction

GitHub

Reminder about Mastodon "private" messages. Aside from not being end-end-encrypted (and so visible to instance administrators), they CC anyone @-mentioned ANYWHERE in the body of the message (not just those listed at the start).

They are now called "private mentions" rather than "private messages", but if you don't fully understand the semantics, this behavior may be unexpected and/or cause unpleasant side effects.

So, funny story. Every cop's body cam is basically an AirTag. I did a talk at DEFCON explaining how you can detect and ID police body cams with your phone.

https://blog.dataparty.xyz/blog/snoop-unto-them/

#BlackMastodon #TrackThePolice #ACAB

DEFCON 31 - Snoop unto them, as they snoop unto us

The official videos from DEFCON 31 have been posted! Below you can watch our talk “Snoop unto them as they snoop unto you”. The talk, slides, files

This week we're at the Chaos Communication Camp 2023! 🚀

Join us for an OONI hack session to help improve tools for measuring and analyzing internet censorship 🐙

• When: 18th August @ 18:00
• Where: BornHack at #cccamp23
• Info: https://events.ccc.de/camp/2023/hub/camp23/de/event/internet-measurement-data-analysis-hack-session/

#ooni #hackathon

Chaos Communication Camp 2023 - Event OONI Hack Session: Measuring Internet Censorship (@BornHack)

We might be about to see a whole lot of employees leave X. https://www.platformer.news/p/is-x-bracing-for-exodus
Is X bracing for exodus?

As the company's illegal sign topples from Market Street, a fresh set of employees may also be looking to make the leap

Platformer

Join us for our closing keynote this DEF CON 31!

Our village page has been updated, check out our speakers, CTF & theme!

Link: blacksincyberconf.com/village

#BlacksInCyber #BIC_Village #BIC_CTF #BlacksInCybersecurity #DEFCON31 #DEFCON

'Disruptor' is a Red Flag for me, now.
@mav I used https://www.canva.com/ to get stickers for defcon this year. they were inexpensive took about 5 days to get to my mailbox. Not too late if you have not already found an alternative.
Amazingly Simple Graphic Design Software – Canva

Create beautiful designs with your team. Use Canva's drag-and-drop feature and layouts to design, share and print business cards, logos, presentations and more.

getting fired up about #defcon y'all. was working on my set last night. it's gonna be rowdy - 20230811 21:00 SYN

#defcon31 #music #party #modular #kosmoModular #syn #synthesizers