Lee Brotherston

@synackpse
200 Followers
417 Following
85 Posts
InfoSec, $work at $place, GetOffMyLawn, O'Reilly author (how did that happen?!), unfluencer, ok.... ish... I guess, he/him, 🤟
Bird App@synackpse

Do people watch their local timelines a lot? Or do you all just read toots from people you follow?

Just wondering if using my mastodon.social account as my primary is an oopsie and I should be using my infosec.exchange one instead.

Data from an August breach of LastPass was used to gain access for the November breach? So reading between the lines, credentials that weren't rotated during incident response, or a vulnerability discovered from stolen source code.

Personal guess is on a credential/token that wasn't rotated/revoked during the initial incident response. Super easy to miss, especially with the nest of X credential grants access to Y credential, etc.

https://nakedsecurity.sophos.com/2022/12/02/lastpass-admits-to-customer-data-breach-caused-by-previous-breach/

LastPass admits to customer data breach caused by previous breach

Seems that the developer account that the crooks breached last time gave indirect access to customer data this time round.

Naked Security
ChatGPT vs stack1.c
Just got my hands confused and came close to shoving a biscuit in a 3D printer and eating an SD card. And to think that people put me in charge of things!
About to kickstarter the “McAfee or Musk?!” card game.

OK in terms of scaling #Mastodon server infrastructure, this looks interesting:

"CIRA is proud to announce its official partnership with Mastodon Canada, mstdn.ca, to support its growth and community-building efforts. As thousands of Canadians flock to the platform, this unique partnership reflects CIRA’s mission to support Canadian internet communities built on the open web and powered by a .CA domain."

https://financialpost.com/globe-newswire/cira-teams-up-with-mastodon-canada-to-support-canadian-digital-communities

CIRA teams up with Mastodon Canada to support Canadian digital communities

Landmark partnership to help support Mastodon’s fast-growing following

Financial Post

Making your own mobile phone if your app gets removed from the App Store has the same energy as someone who would overspend by billions on a purchase to avoid the one billion fine for pretending.

I’d be interested to learn how such a someone plans to recruit for this phone company, given how they just got themselves blacklisted as an employer by so many engineers.

Is it just high load, or does the federation model of mastodon cause some delay doing convergence/syncing/something with follows?

I sometimes seem to get followed multiple times by one account, have to follow someone multiple times for it to "stick", etc.

I know it’s to promote a Black Friday sale. But getting a “Happy Thanksgiving” from a Canadian company to a Canadian customer seems….. weird.

Don't get me wrong, I like mastodon..... But....

... this is 🍿 watching people rediscover all the problems with IRC from first principles again.