Rob Pomeroy

817 Followers
902 Following
1,062 Posts

TLDR: #infosec #cloud #devops #OpenSource #a11y #JC #MostlyHarmless

πŸ‘‹πŸ»πŸ”’ Friendly British Security/Technology wonk.

πŸ˜‡πŸ™ Good guy wannabe.
βœπŸ»πŸ‘½ Sci-fi author.
πŸ‘¦πŸ»πŸ‘¦πŸ» Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
πŸ¦ΈπŸ»β€β™€οΈ Husband to superhero wife.
βš–οΈ Solicitor (no longer practising law though).
✝️ To everything there is a season.

πŸ”πŸ‘πŸ» Visit my website for secure/private methods of contacting me

Website 🌍https://pomeroy.me/about/
GitHub πŸ‘¨πŸ»β€πŸ’»https://robpomeroy.github.io/mastodon.html
Keybase πŸ”‘https://robpomeroy.keybase.pub/mastodon.html
BrightOS πŸ’‘https://github.com/robpomeroy/BrightOS

This is a great paper on the risks of malicious servers when using password managers: https://zkae.io/. I understood about 2% of it.

You have to dig down in the paper to see that there was pretty good engagement from the password manager developers, once contact was established. That's encouraging, particularly in the light of recent reputational damage suffered by LastPass, and doubts about its future under private equity ownership.

#crypto #passwordmanager #lastpass #dashlane #bitwarden #1password

Boo. πŸ™πŸ‘Ž

"an autistic man ... was told he had to stop stacking shelves at a Waitrose store where he had worked as a volunteer for years"

"his placement was stopped when the firm's head office was asked about the possibility of paid work"

https://www.bbc.co.uk/news/articles/c205le1e27zo

Hooray! πŸ™‚πŸ‘

"Asda have offered him two five-hour paid shifts a week"

https://www.bbc.co.uk/news/articles/c98n53dpzx6o

Asda wins this particular PR skirmish. πŸ€”

#autism #diversity #inclusion #PR #Waitrose #Asda

It's always sad to see a well-functioning venture killed by friendly fire. I joined the UK's CISP (Cybersecurity Information Sharing Partnership) circa 2017. At that time, CISP had been running for four years.

At its heart, it was an active forum, peopled by information security professionals from diverse public and private sectors in the UK. Was it perfect? No. But professionally, it was an invaluable resource. I found it particularly helpful when investigating issues specific to the legal and maritime sectors, while I managed cybersecurity at international law firm Hill Dickinson. Importantly, much of the information I received and shared on CISP was not available anywhere else, not least information covered by amber/red TLP ratings.

In late 2023, NCSC replaced the forum software with an all-new site based on Microsoft SharePoint. Like many CISP members I was more than willing to attempt to use the new platform. But it quickly became apparent that it was impossible to communicate with the ease we'd previously enjoyed. SharePoint is not forum software.

Active use of CISP evaporated. And today, NCSC has given notice that CISP will be mothballed.

Sad as I am to have lost such a valuable resource (in 2023), I would like to thank all the wonderful people at NCSC that made it happen, and who successfully evangelised its merits. I know your resources are stretched thinly and there's no blame here. If you are ever tasked with recreating the original CISP magic though, count me in.

#CISP #NCSC #eulogy

This is super-super niche, but I just made a little launcher for Visual Studio Code workspaces. Very helpful for quickly opening workspaces based on Windows and/or WSL.

Free & open source: https://github.com/robpomeroy/vscode-launcher

#VSCode #WSL #Windows #Development

What could possibly go wrong?

Teen on Musk’s DOGE Team Graduated from [cybercriminal social network] β€˜The Com’
https://krebsonsecurity.com/2025/02/teen-on-musks-doge-team-graduated-from-the-com/

I seem to be using this emoji a lot these days: 😬

#government #America #Musk #cybercrime

Teen on Musk’s DOGE Team Graduated from β€˜The Com’ – Krebs on Security

Beware #AirBnb scams like this one - injected into legitimate conversations on the AirBnb platform (hacked host account).

The domain shown in the message was registered today (among many other red flags).

#scam #scams

Re: Attacking UNIX Systems via CUPS

Read this: https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/

Then you should probably go and rip out CUPS. Everywhere. Or at the very least TAKE YOUR SERVERS OFF THE FLAMING INTERNET.

Exploit code is available on the public internet. No I will not post a link.

#cups #evilsocket

Attacking UNIX Systems via CUPS, Part I

Hello friends, this is the first of two, possibly three (if and when I have time to finish the Windows research) writeups. We will start with targeting GNU/Linux systems with an RCE. As someone who’s

evilsocket

Sneaky HMRC VAT return scam that really looks plausible (except for the non-UK spelling "apologize").

The link does NOT go to HRMC.

VirusTotal results: https://www.virustotal.com/gui/url/e3f698e2de9b417bca6e875c6b621d401839a362de0e62ba7646c018fb668fc4

URLscan results: https://urlscan.io/result/1abd488d-d402-4812-bb5a-5a32058d773f/

#phishing #scam #hmrc #vat #fraud

VirusTotal

VirusTotal

Days like these are hard work. Sympathy, my dudes.

Spare a thought for the engineering/security (?) teams at @mail_gun who are probably not having A Good Day.

#Mailgun #Outage