965 Followers
844 Following
140 Posts
@InGuardians CEO,
#Kubernetes: Bustakube, Peirates, Black Hat Trainer
#Neurodiverse, talk to me about ADHD and Autism
1st @CISecurity Linux lead, BastilleLinux
he/him
@jaybeale on birdsite
http://pronoun.is/he
First Contact Day falls on a Sunday this year. We did not plan that. What we did plan is the second post in our Star Trek series. Picard. Worf. Troi. Data. It turns out the Enterprise senior staff has a lot to teach security engineers about diplomacy, risk communication, empathy, and the quiet power of consistency.
Join us back at https://shostack.org/blog on Sunday!
Shostack + Friends Blog

Security, privacy, economics & unrelated topics, since 2005.

Close enough.

Don’t let other people stomp on your happiness. If it’s not hurting anybody, do the things that make you happy, even when others belittle them or say they’re uncool.

Being true to yourself is cool. Having a passion is cool. Finding joy is cool.

John Morales Warns Of NOAA & NWS Cuts: VIDEO

Telling it like it is.

Comic Sands
1. Trump has publicly and privately fantasized about deploying the military on US soil against protesters for years.

In LA, with little justification, he has made those dreams a reality, violating longstanding democratic norms.

He has manufactured a crisis.

Let's review the history.

🧵
"Trump declares intention to openly break Congressionally-enacted valid law in order to honor white supremacy." Sums it all up. www.nytimes.com/2025/06/10/u...

Trump Says Army Bases Will Rev...
Trump Says Army Bases Will Revert to Confederate Names

The move would reverse a yearslong effort to remove names and symbols honoring the Confederacy from the military.

The New York Times

I did some reversing/exploring on a widely used IoT product for fun this week, and here’s what I found:

- embedded Linux on an SD card
- SD card not encrypted
- developed by a third party on behalf of the end customer who makes the actual device this thing is connected too
- runs the code in docker containers from a private container repo
- docker credentials for private repo stored locally
- can use docker credentials to access containers for all of third parties customers, not just the one who makes the device
- GitHub creds in bash history
- can access source code for all customer projects using said creds

So things are going well over there.

Psychological Safety: Why Security is Digging a Hole

Looking forward to giving a brand new talk at BSides Basingstoke today on Psychological Safety: Why Security is Digging a Hole. Because it is. Security professionals frequently fail to make 'security' something that isn't scary and out to yell at you or blame you or call you nasty words. No one wants to connect or work with an area like that.

http://infobex.co.uk/2024/07/19/psychological-safety-why-security-is-digging-a-hole/

Psychological Safety: Why Security is Digging a Hole

Looking forward to giving a brand new talk at BSides Basingstoke today on Psychological Safety: Why Security is Digging a Hole. Because it is. Security professionals frequently fail to make ‘…

InfoBex
ICYMI: based on a public record request of GPS data from the Seattle #Police Department, I found that SPD officers regularly drive at excessive and dangerous speeds--often for no reason at all: https://publicola.com/2024/10/25/data-shows-seattle-police-speed-constantly-even-when-they-arent-responding-to-calls/ #PoliceAccountability #VisionZero
Data Shows Seattle Police Speed Constantly, Even When They Aren't Responding to Calls - PubliCola

By Andrew Engelson Seattle Police Department officers frequently drive at excessive and dangerous speeds, PubliCola has learned using GPS data…

PubliCola
I keep thinking, “it’s the hope that kills you.”