Royce Williams

@tychotithonus@infosec.exchange
3.2K Followers
3.7K Following
11.1K Posts

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = probably stole you from follows of someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers with the heat of 400B suns

❤️:⚛👨‍👩‍👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!

Stuffhttps://www.techsolvency.com/roycewilliams/mastodon
Keybasehttps://keybase.io/royce
GitHubhttps://github.com/roycewilliams
LinkedInhttps://www.linkedin.com/in/roycewilliams
Gravatarhttps://gravatar.com/tychotithonus
Not "dehashed"!https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/
@grafana Thank you for the forthright and timely post --- a model for how this should be done.

On Saturday, April 26, 2025, an unauthorized user leveraged a vulnerability in a Github workflow within a public Grafana Labs repository, resulting in the exposure of a small number of secrets.

Our detections immediately triggered alerts.

The Grafana team responded, mitigated the vulnerability, rotated keys and verified there was no access to production systems or data.

We'll follow up with more information on our blog in the next few days.

If Backblaze is your poison of choice for your backups, this text might be frightening/interesting for you:

"Backblaze: A Loss-Making Data Storage Business Mired in Lawsuits, Sham Accounting, and Brazen Insider Dumping" https://www.morpheus-research.com/backblaze/

Backblaze: A Loss-Making Data Storage Business Mired in Lawsuits, Sham Accounting, and Brazen Insider Dumping

Summary * Backblaze (NASDAQ:BLZE) is a $250 million cloud storage and backup solution provider based in California that operates through two business segments: B2 Cloud Storage allowing “customers to store data” and “developers to build applications,” and Computer Backup that “automatically backs up data” from devices for “virtually unlimited” storage.

Morpheus Research
@j0hnnyxm4s Aren't they still around?

After *heavy* consideration, I have moved from Fosstodon to Hachyderm.

Short version:
Given public sentiment I think it will be easier for me (personally) in the long run to be here. I have mixed feelings about this.

Long version: https://coreysnipes.com/thoughts-on-fosstodon.html

Thoughts on Fosstodon

I'm moving to hachyderm.io. Here's the background... When I left Twitter for Mastodon in late 2022, I chose fosstodon.org as my home. I appreciated the open source focus and it seemed like a well-run instance that would be around for a while. I also signed up as a monthly patron, to support the admin team and help keep the instance sustainable. In recent days, there has been a minor furor across the fediverse related to one of the moderators at…

coreysnipes.com
If you ever get the chance to see Kids in the Hall live, and you're at all a fan ... don't pass it up. Whatever the opposite of "phoning it in" is, they were doing it. The crowd work and fan service were top notch.
@kjhealy Huge fan -- underrated superpower, and so well designed!
@0xabad1dea This may have changed in the years since, but the email invite used to only be the first step. Once you expressed interest, they sent you a physical postcard with a verification code on it.

I need to be very clear, that the push towards "vibe coding" - that is, deliberately deskilling people - is because AI code assistants are an (increasingly expensive) subscription service.

If you know how to code, you can just write Python, C, Java, R, PHP, whatever for free and make things. You may not own the tools of production, but at least you're not renting them.

If you have been deskilled so you only know how to vibe code, you will be paying for that privilege forever.

This also goes, by the way, for researchers who are starting to be convinced they don't need to learn how to be scientists anymore, because "the AI" can just do the science for them. Nope.