Just plain, simple Alex  

112 Followers
72 Following
59 Posts

PNW-based, globally mobile. InfoSec in Big Tech. Not the Cameroonian footballer. Former member of the Obsidian Order. Toots are my own. Send me your kitties. Boosts != endorsement

Moved from @TheRealAlexSong

Twitterhttp://Twitter.com/_AlexanderSong_
LinkedInhttp://LinkedIn.com/in/AlexanderSong
Contact Cardhttp://alexsong.com/contactcard.html

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item from themselves as a gift for you. Bam, they have your address.

In particular, attack does not depend on an existing third party seller having poor PII handling hygiene, like the articles have implied.

Why am I JUST learning the annual Star Trek Convention overlaps with DefCon?

Announcing the opening of the Pros V Joes call for players!
Since we’re going for an extra half day, this year, the PvJ team is going to bring you that much more learning and fun!

Call for Joes: https://forms.gle/pdDTs9ft8PWG2cvQA

Call for Pros: https://forms.gle/9LDubL8mNTBjvRUi6

BSidesLV 2025 PvJ CTF Sign-up for Joes

Calling All Joes! Joe registration for the BSides LV Pros V Joes competition is now open! Pros V Joes website: http://prosversusjoes.net/ (Please note the game is on Monday, August 4 and Tuesday, August 5, with an extended post-game debrief and other activiites on Wednesday, August 6) What is the Pros V Joes CTF? This event is an opportunity for average users (Joes) to try their hand at both the defensive and offensive side of computer security. As a Joe you will learn from seasoned professionals who will lead and mentor you as you develop the skills to protect your network. You’ll also have the opportunity to work with a seasoned penetration tester/hacker who will start you on the path developing those skills. For the Pro's, it's a chance to hone and show off their skills, helping others to learn and better themselves. It's a lot of fun, no matter which side you’re on. Joes are split up into teams, each with a Pro captain and co-captain, then given their own network to defend against the Red Cell. Each team's network comes complete with all of the services, servers, and desktops common to a corporate environment today. Your mission is to secure the systems, maintain business-critical services, find the Red Cell, and expel them while keeping them from getting back in. Of course, there will be more than a few surprises... For two days, players will attack and defend in live networks, breaking into each other's systems to steal flags for fame and glory. For the first day, Joes are completely defensive, and on day two, Joes will both defend and attack the other Joe teams. Each team is provided with their own network that is full of servers and workstations to defend. All of this gear is housed in a dedicated and isolated network that we affectionately call the Gaming Grid. Players need only to connect to the environment over VPN. (Players' personal machines will not be in the line of fire, if you follow the rules... ;-) You can’t join and learn if you don’t send in the form! The environment to host this CTF is currently undergoing active construction and will be laced with various surprises to keep the game interesting. The networks that the Blue Teams must defend will be a mix of Windows and Linux, with the typical Internet services (web, DNS, mail, etc) and maybe more obscure systems and services. At the end, a winning team will be announced. I'd like to ask each Joe applicant to please respond with a bit of information about yourself - your background, your level of experience, and your area of expertise. This information will help us balance the teams to make for a fun and exciting game for all. It will help us and your team if you are brutally honest with your self-estimate, but don’t let imposter syndrome cause you to underestimate your experience and skills, either. Try to be fair to yourself. Don’t feel too intimidated to apply, you can’t join and learn if you don’t send in the form! In the days and weeks ahead, should you be selected to play, you’ll be contacted by your Pro Captain and co-Captain. As we get closer to the event, we'll refine the rules and I'll work with each of you to provision your VPN access to the CTF Network, so that you can become familiar with it. We will not share your responses with anyone besides our Blue captains. Lastly, if anyone has questions, comments, or suggestions, please don't hesitate to contact me on https://infosec.exchange/@dichotomy. We have a whole team building and running this CTF. We’re very open to new ideas, and think a group collaboration can only make this event better. Thanks, ~dichotomy

Google Docs
Locking down your phone, being mindful of what you're wearing, and coming up with plans to communicate with others are all key steps to take before attending a protest. https://ssd.eff.org/module/attending-protest
Attending a Protest

For quick reference, we've created a handy guide designed to be printed, folded, and carried in your pocket (PDF download). Now, more than ever, citizens must be able to hold those in power accountable and inspire others through the act of protest. Protecting your electronic devices and digital assets before, during,...

For only 24 more hours, all Signal groups I am added to will have:

👊🇺🇸🔥
"Did anyone check for journalists in the group?"
Group name contains "top secret war plans"

Sorry, it's the law.

People have been asking for updated Fediverse infosec lists from me, ask and ye shall (eventually) receive https://tisiphone.net/2025/03/18/updated-infosec-mastodon-lists/
Updated InfoSec Mastodon Lists!

I have been asked for these, so here they are! I hope you find these useful in following more Fediverse cybersecurity stuff. Pancakes Short Stack,[email protected] Pancakes Short Stack,spacero…

Lesley Carhart's Cybersecurity Blog
Hi everyone. It’s a new month and here’s a new plea for you to support your fediverse instance if you can and they accept donations. My thanks to all that do, and also my thanks to the many people that make the fediverse tick.

I was invited to keynote at an excellent conference in the US ... but I have turned it down:

"Thank you for contacting me. Prior to the recent political changes in the US, I would have said "yes, absolutely" but I am no longer traveling to the US, particularly to Republican states like XXXXX. "

Sorry, US folks, but without a functioning FAA ✈️ and a rampaging nazi in charge, I'll not traveling to the US any time soon 😢

( I'm available for keynotes outside the US: https://matthewskelton.com/keynotes )

Keynotes — Matthew Skelton

Matthew Skelton
My favorite part of the day is going home and having this purr monster climb all over me #catsofmastodon

If you work in government and are asked to remove content from websites (as a result of executive orders), please use the HTTP status code 451 instead of 404.

451 is the correct status code to use for these cases, and you'll be doing the rest of the country a service by using it.

Addendum: you should also include a Link header with the link relation "blocked-by" that "Identifies the entity that blocks access to a resource following receipt of a legal demand."

https://www.rfc-editor.org/rfc/rfc7725.html

RFC 7725: An HTTP Status Code to Report Legal Obstacles