Seth Hanford 🐔

@ckure@infosec.exchange
462 Followers
982 Following
1.4K Posts

CSIRT primarily, currently doing large-scale detection engineering. I ā¤ļø ISO 8601

Spent a good amount of time in intelligence, ran operations for a vulnerability database, and worked a lot on some industry standards working groups CVSS (v2, v3), CPE (2.3). Did PSIRT a few places, too.

Do a lot with OpenBSD, Python, and Oxford commas. Worked as a manager for some world-class, global teams. Use that experience as a super power now that I’m back as a senior technical IC.

PronounsHe/Him
CommasOxford
TimestampsISO8601
Githubhttps://www.github.com/SethHanford
Websitehttps://trustworth.ee/SethHanford.html
:otter::otter:

> On November 28th, 2012, Randall Munroe published an xkcd comic that was a calendar in which the size of each date was proportional to how often each date is referenced by its ordinal name (…) "In months other than September, the 11th is mentioned substantially less often than any other date. It's been that way since long before 9/11 and I have no idea why." After digging into the raw data, I believe I have figured out why.

https://drhagen.com/blog/the-missing-11th-of-the-month/

The Missing 11th of the Month - David R Hagen

Personal website of David R Hagen, scientific software engineer

Our teammate Leonid had a look on Synology. He discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of organizations that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data such as all Teams channel messages. #synology #disclosure #modzero #infosec

https://modzero.com/en/blog/when-backups-open-backdoors-synology-active-backup-m365/

When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365"

Canadians, pay attention: Bill C-2 is a quiet threat to your privacy and civil liberties.

With so much happening around the world, it’s easy to miss what’s going on in our own backyard. But Bill C-2, now in the House of Commons, deserves your attention.

It lowers the threshold for law enforcement to access your private data—without a warrant. All it takes is "reasonable suspicion."

What kind of data?

* Internet and cellphone metadata

* Your location and activity logs

* Information shared across borders with foreign agencies

All accessed more easily under vague ā€œexigent circumstancesā€

As a person who’s been accosted based on ā€œreasonable suspicionā€ due to…. existing, I’m concerned that this bill expands surveillance powers and erodes due process protections that Canadians have long relied on.

I keep seeing arguments like, ā€œIf you’re not doing anything wrong, you have nothing to worry about.ā€

Let me be clear: that’s not how rights work.

Free societies are built on the principle that the law protects the innocent—not that we must prove we have nothing to hide.

If you're concerned (and you should be), reach out to your Member of Parliament. Let them know you oppose C-2 and support real protections for Canadian privacy and civil rights.

You can read the full bill here:

https://www.parl.ca/DocumentViewer/en/45-1/bill/C-2/first-reading

Let’s not sleepwalk into surveillance. We deserve better.

PS The Citizen Lab has an excellent write up https://citizenlab.ca/2025/06/a-preliminary-analysis-of-bill-c-2/

PPS If you're a Canadian resident, find your Member of Parliament here: https://www.ourcommons.ca/members/en

#PrivacyMatters #BillC2 #Canada

Government Bill (House of Commons) C-2 (45-1) - First Reading - Strong Borders Act - Parliament of Canada

Government Bill (House of Commons) C-2 (45-1) - First Reading - Strong Borders Act - Parliament of Canada

Loved reading @_elena's "This is what resistance to the digital coup looks like"

https://news.elenarossini.com/this-is-what-resistance-to-the-digital-coup-looks-like/

"The mere act of posting on the Fediverse sends a clear message: another way is possible"

This is also one of the reasons why I bring Romanian-centric news to my Fediverse profile. If this is to be a nurturing garden for diversity, I want to contribute to a diversity of politics, grounded in lived experience and grassroots activism.

This is what resistance to the digital coup looks like

Technological platforms are not neutral. If we truly want to resist the digital coup that is currently under way, we need to normalize the use of free, open source solutions.

Elena Rossini
…

Not really sure why, but I've been stuck a bit today reminiscing about standing up a public security advisory program at a former employer. We had an existing PSIRT, but just were not at all interested to speak publicly about vulnerabilities.

They'd had a handful of CVEs published about them about 10 years before and were not really happy with how the process went. I spent several months advocating that "lack of CVEs != lack of vulnerabilities; we should be speaking authoritatively about this so that customers are reassured and we aren't subject to the whims of the Internet's view of our flawsā€. By late 2019, I'd gotten the support from the executives necessary to standup a program and become a CNA.

Starting in 2020, they started to issue CVEs, post about them publicly, etc. It's still going on there to this day, with new CVEs published within the last few months.

I even did a bit of archaeology because the 2010-era CVEs were woefully under-developed entries. I found some internal documentation, some repos, and some long-time employees who helped to get additional details put together to clarify what was actually going on (eg which versions were vulnerable and which were fixed). I'm not entirely sure what happened with those archaeological details, but I fear they're somewhat lost to time.

Still, it was a lot of fun to make it happen and it warms my heart that they've carried on even after I have moved on. Feels good to have left the Internet a little better than when I found it. #vulnerability #cve

This is a 1500 kg meteorite fallen in Campo del Cielo, Chaco, Argentina.
It is about 4.5 billion years old (yes, about as old as our planet).
It is the oldest thing I have ever seen and touched in my life. It is the only thing from space that I have ever touched. It is metallic: iron and nickel.
It is impressive.

I'm collecting data regarding No Kings protests and sizes, looking to ballpark how many people showed up. Feel free to share this post hither and yon.

https://app.nocodb.com/#/nc/form/a5f54d4c-3ae8-437f-8a2e-75690b5b26e3/survey

https://forms.gle/nJayCqPiQ9CEvB6o8

https://forms.office.com/r/EJJWCsjSwi

Each of the offered surveys should all be more or less identical; you don't need to use all of them, I'm just providing options for people's comfort.

All information I distribute as a result of these surveys will be anonymized.

#NoKings #protest

NocoDB

NocoDB provides an intuitive spreadsheet interface for creating online databases, either from scratch or by connecting to any Postgres/MySQL. Access your data through interactive UIs or via API and SQL. Get started for free.

NocoDB