K. Reid Wightman  ðŸŒ»  

456 Followers
405 Following
5.9K Posts

Tinker, Sailor, Biker, Hi

I do industrial security research for a living, mostly looking for #vulnerabilities in all of the wrong places. I like reverse engineering how PLC logic systems function under the hood, learning how safety instrument protocols work, and figuring out what malicious threat groups are doing and can do with access to such systems. A long time ago, I invented the term 'foreverday' to describe unfixable vulnerabilities.

Occasionally I analyze #industrial #malware, too, and on very rare occasions encounter threat groups that actually write malicious logic to do the vile things that I like to learn about.

I work for a little startup in the space called Dragos. In my spare time I enjoy long distance #bicycling, #sailing, and doting on our #pets.

I used to have an account on , however I haven't used it in a while and you should no longer assume that it's under my control.

Trying not to be one of the 80% that can be moved in either direction.

LocationDes Moines, IA, USA, Planet Earth, second spiral arm around Sagittarius A
Pronounshe/him or they/them
Security LevelCurrently clean on opsec
I’m not saying you’re a bad person for having liked Harry Potter. All I’m saying is that Jim Butcher might or might not have some horrible opinion we don’t know about, but if he does we don’t know it because he doesn’t spend his money trying to exterminate an entire type of person, he keeps his opinions to himself, so read Harry Dresden instead of Harry Potter.

Because this treatment is a crime
The working people fuel the engine
While you yank the chain
We fight the wars and build buildings
For someone else’s gains

https://youtu.be/5BRHuiRyVEE?si=5ylU9Ps1fDqyr3hz

Dropkick Murphys "Who'll Stand With Us?" Music Video

YouTube
Discovered a CVSS10 directory traversal in critical infrastructure today. Send memes.
This fact, once learned, is impossible to unlearn... #kernelfacts #cornfacts
sudo klaatu barada nikto
can't find where I promised the catte-approved shitpost stamp, but here it is:
Can't unsee.
Hearing that Sora is closing its doors permanently.

I make fun of Modbus because it is a network protocol invented by people with limited background in programming let alone protocol design (like indexes start at 1? what?).

I've been writing my own DNP3 stack (native Python stack) and I've gotta say the exact opposite about DNP3. It was written by insane network protocol people who aren't worried at all about making something ridiculously complex. Especially if twenty extra parsing steps might allow someone to save a byte or two on-the-wire. I totally get how Adam and Chris found 18 bjillion parsing bugs in dnp3 systems a few years ago. I'm surprised they didn't find even more bugs.