Rick Hunter

11 Followers
59 Following
301 Posts
Got roped into product security by sitting in the wrong cockpit at the wrong time.
Well done to the CEO of Krafton, who asked ChatGPT how to avoid paying $250m in bonuses if Subnautica 2 launched well, executed the ChatGPT plan, got sued by staff, had all the chat logs appear in court, lose, and now have to pay $250m and more and be publicly humiliated by his own employees.
cybersecurity 2025

My new post in the CERIAS blog:
https://www.cerias.purdue.edu/site/blog/post/more-than-the-code

Third in a series on AI hype. If LLMs cannot replace experienced people, what is the right preparation for a computing career? The capacities AI labs now hire philosophers to provide — communication, ethics, social literacy, the capacity to argue and interpret — are cultivated in the humanities and fine arts now being cut. Advice for students choosing electives, and food for thought for the rest of us.

New Myths for Old - CERIAS - Purdue University

The Center for Education and Research in Information Assurance and Security (CERIAS) is currently viewed as one of the world’s leading centers for research and education in areas of information security that are crucial to the protection of critical computing and communication infrastructure.

The Canvas hack is "the biggest student data privacy disaster in history." For years critics have been warning about the centralization of EdTech. Well, millions of students being locked out is what happens when you do exactly that https://www.404media.co/the-biggest-student-data-privacy-disaster-in-history-canvas-hack-shows-the-danger-of-centralized-edtech/
'The Biggest Student Data Privacy Disaster in History': Canvas Hack Shows the Danger of Centralized EdTech

Messages could include "medical circumstances, accessibility accommodations, disputes, sexual assault allegations," and more.

404 Media
Today's #Muppets GIF of the Day is...

NASA astronaut and Artemis II Commander Reid Wiseman took this picture of Earth from the Orion spacecraft’s window after completing the translunar injection burn. There are two auroras and zodiacal light is visible as the Earth eclipses the Sun.

https://bsky.app/profile/alexjamesfitz.com/post/3milw6miovk2q

Astronauts are trained for decades in some of the most physically and mentally grueling environments of any career. They’re some of the smartest people on the planet. And yet, once they get up there, fucking Outlook is borked. https://www.404media.co/artemis-2-astronauts-microsoft-outlook-livestream/
Artemis II Astronauts Have ‘Two Microsoft Outlooks’ and Neither Work

In space, no one can hear you scream at Microsoft’s legacy software.

404 Media
Today's #Muppets GIF of the Day is...

In today's episode of "Can It Run Doom": DNS fucking TXT records.

Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

blog: https://blog.rice.is/post/doom-over-dns/

repo: https://github.com/resumex/doom-over-dns

Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

It was always DNS.

#infosec #dns #doom #itisalwaysdns