Keith Hoodlet  

1.7K Followers
300 Following
290 Posts
Director of Security Research @ 1Password; OSCP; OSWA; Vulnerability Whisperer; Blogger; Occasional podcast personality; Top 300 Security Researcher on Bugcrowd 😈
Bloghttps://securing.dev
Instapaperhttps://www.instapaper.com/p/securingdev
SignalKeith.64
PhilosophySecurity is a Feature
AlignmentChaotic Good
I should be trying to sleep but Nissa said I should worship her leggies before I do and maybe you should too. #CatsOfMastodon
There was a time when Dril’s identity was leaked and we all just agreed to ignore that and mind our business as if it hadn’t happened and I think we owe Banksy at least that much.

WE DON'T WANT TO KNOW BANKSY'S IDENTITY

STOP INVESTIGATING BANKSY FFS

INVESTIGATE LITERALLY EVERYTHING ELSE

we finally located nginx HQ in japan. lol. pic credit https://xcancel.com/snmr_s/status/2033834665573048776

Reading Thomas Nagel's classic 1974 paper, "What Is It Like to Be a Billionaire?"

Nagel argues that these bizarre, cursed entities *are* able to experience introspection, but choose to pretend otherwise, lest they be haunted to the end of their days by the memories of their innumerable, unspeakable crimes

Hey internet. I'm hiring for a vuln researcher/exploit dev/hacker type.

US preferred, UK okay.

Reports to me, in the research engineering team at @runZeroInc.

HMU if you're interested, and then fill out the thing. If you use a name different from the one I know you as, please be clear about that so I can tag the (internal) recruiter with that info.

Listing:

https://www.runzero.com/about/careers/apply/?gh_jid=5829740004

Apply

runZero

"Qihoo 360, China's largest cybersecurity company with approximately 460 million users and a valuation of approximately $10 billion, shipped a wildcard SSL private key inside the public installer of its new AI assistant, 360 Security Lobster"

https://blog.barrack.ai/qihoo-360-ssl-key-leak-wotrus-ca-fraud/

Qihoo 360's AI Product Leaked the Platform's SSL Key, Issued by Its Own CA Banned for Fraud | Barrack AI

Qihoo 360 shipped the wildcard SSL private key for *.myclaw.360.cn inside its AI assistant installer. The certificate was issued by WoTrus CA, Qihoo 360's own subsidiary, previously distrusted by Chrome, Firefox, and Safari under its former name WoSign for certificate fraud.

@securingdev His whole spiel breaking down how to hunt paper trails in that scene clicked when I was watching it last night. The lightbulb went on and I just thought: "Oh. He's just describing what we call 'pivoting' through non-digital records."