Royce Williams

3.5K Followers
3.9K Following
14.9K Posts

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = stole you from someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Suggestions welcome!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning by a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers w/heat of 400B suns

❀️:βš›πŸ‘¨β€πŸ‘©β€πŸ‘§πŸ›‘πŸ™ŠπŸŒ»πŸ—½πŸ’»βœπŸŽ₯🍦🌢🍫!

Stuffhttps://www.techsolvency.com/roycewilliams/mastodon
Keybasehttps://keybase.io/royce
GitHubhttps://github.com/roycewilliams
LinkedInhttps://www.linkedin.com/in/roycewilliams
Gravatarhttps://gravatar.com/tychotithonus
Not "dehashed"!https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/
I asked my gemini-sysadminhelper to assess the migration path for me today for a very old FOSS tool I need to swap out to get modern OAUTH2. Instead, it hot-patched the source to handle OAUTH2 because that's easier than migrating. I now wonder whether my tech-debt problem will improve because the agent can autonomously handle step-upgrades and I won't accrue the tech debt, or whether it will worsen because to the agent it's just as easy to refactor and hot-patch as it is to apply updates.

I am going to NYC later this month for an awards ceremony at the Cipriani since the AP package I contributed to won an Overseas Press Club of America award.

I'd like to meet people doing cool or interesting work in the cybersecurity/privacy/human rights/etc. space. Anyone I should connect with?

There was no good way to see what CT logs are actually used by CAs, so I made a dashboard of Censys data on exe.dev.

There are some interesting patterns, but the main one is that Let's Encrypt is the only CA that evenly spreads load. Other CAs are mostly using older logs, or their own logs and Google's.

(Of course, LE is 50% of issuance, and GTS is 25%, so the rest don't matter much.)

https://groups.google.com/a/chromium.org/d/msgid/ct-policy/718571cb-a841-4102-bcfa-3fe3feab63ae%40app.fastmail.com

Just stepped into a Burlington for the first time in 20 years. It's like Target and Goodwill had a baby.

RE: https://fosstodon.org/@ovid/116334866923361500

My earlier thread on 4,000 years of enshittification got some great responses. One question kept coming up: if the extraction pattern is deeper than capitalism, what is the root cause? I think I have the start of an answer, but it means annoying people across the political spectrum.

1/9

There is an entire industry designed to distract enterprises from deploying FIDO authentication. Why solve the problem when you can "manage" it with "risk informed decision frameworks" that require bespoke products and don't really work? πŸ’Έ πŸ”“οΈ

Just one study but we have seen clear decreases in human attention spans, esp since 2012...

"Watching fragmented short videos rather than a single continuous video leads to poorer memory recall and alters how the brain retrieves information. A recent experiment revealed that fast-paced episodic media formats disrupt the neural systems responsible for integrating details and maintaining cognitive control." via PsyPost

https://www.psypost.org/brain-scans-reveal-how-short-videos-impair-memory-and-disrupt-neural-pathways/

#Science #Psychology #SocialMedia

Brain scans shed light on how short videos impair memory and alter neural pathways

A recent brain imaging experiment reveals that watching fragmented short videos leads to measurably worse memory recall compared to viewing continuous content. The fast-paced format reduces brain activity in regions dedicated to focusing attention and processing deep meaning.

PsyPost Psychology News
Inside of you are two Outlooks

My greatest professional accomplishment of the year: I got my exec & manager teammates saying "point positive," a term from whitewater rafting and kayaking.

Meaning: when facing hazards, point people toward where to go/what to do, rather than drawing attention to everything to avoid.

Why did they remove from Ruby the equivalent of Perl's data "taintedness" tracing mechanism?