Royce Williams

@tychotithonus@infosec.exchange
3.2K Followers
3.8K Following
11.8K Posts

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = probably stole you from follows of someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers with the heat of 400B suns

❀️:βš›πŸ‘¨β€πŸ‘©β€πŸ‘§πŸ›‘πŸ™ŠπŸŒ»πŸ—½πŸ’»βœπŸŽ₯🍦🌢🍫!

Stuffhttps://www.techsolvency.com/roycewilliams/mastodon
Keybasehttps://keybase.io/royce
GitHubhttps://github.com/roycewilliams
LinkedInhttps://www.linkedin.com/in/roycewilliams
Gravatarhttps://gravatar.com/tychotithonus
Not "dehashed"!https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/
I created a Chrome extension called β€œTab Extract-n” basically it groups tabs based on a search term. Just type β€œex git” in the url bar and it will group all @github and @gitlab and tabs.
(Made after original tab extract stopped being supported) https://chromewebstore.google.com/detail/tab-extract-n/hlbbaplcopkikfjblgkbockaeijighln
Tab Extract-n - Chrome Web Store

Search for tabs and group them in a new window.

Robustness work is about enlarging the system's competence envelope, resilience work is about improving the system's future behavior when it inevitably breaches its competence envelope.
There have been claims that NOAA/NWS did not foresee catastrophic TX floods--but that's simply not true. This was undoubtedly an extreme event, but messaging rapidly escalated beginning ~12 hrs prior. Flood Watch mid PM, "heads up" outlook late PM, flash flood warnings ~1am.

RE: https://bsky.app/profile/did:plc:teckhxpypg6v46gj7iysmmqt/post/3lt6heyboa22l

πŸ“‘ The #livestream doesn’t stop when we're off for the holiday or weekend. πŸ‡ΊπŸ‡Έ

When the microfiche scanning team powers down overnight & on weekends, the feed keeps on keeping on, shifting to silent films, home movies & other gems from the #InternetArchive.

Catch the stream ➑️ https://www.youtube.com/live/aPg2V5RVh7U

lofi Archive radio 🎞️ beats to scan/read microfiche to

YouTube

Calling upon #Python developers. Have you implemented #Passkey authentication without using third-party services?

I'm trying to find some good reference material but all seem to include usage of third-party services for managing the authentication...

... but I want full "ownership" of the authentication stack before deciding to ship that to someone else. One of the most critical components is not something I feel entirely comfortable handing off to someone else.

So... anyone got something to share? I have come across this:

https://pypi.org/project/webauthn/

That seems to give me the server/backend stuff. If you have experience building the frontend/UX components using #Reflex then I would be even more excited to hear from you! πŸ™‚

Client Challenge

in the past I've provided expert advice for inclusion in guidelines for domain owners. Often that advice is mangled once published. So I wrote my own guidelines a few yrs ago.
#dns #domains #domainnames

https://kalfeher.com/secure-practices-for-domain-owners/

Secure Practices for Domain Owners

The recommendations contained within this document attempt to provide easy to audit points that any domain owner, regardless of technical capability, can …

Dinner and a walk through a park festival at day 0 of #confconf in #Sofia, #Bulgaria

Just in those photos you see people who made #FOSDEM, #DENOG, #DebConf, #PromCon, #GrafanaCon, #CCC / #38c3, #WHY2025, #IndiaFOSS, #COSCUP, #FOSSASIA, and others happen. And more people will come tomorrow.

We're looking to have a packed agenda over this coming weekend, and I will try and do my best to update this thread with tidbits and information.

Is there a term for the class of "credential storage confusion" #security issues, where the user accidentally saves a password or passkey in a vault they don't actively use (browser, #SSO IdP, #passwordManager, OS)?

One thing that made me think of this is having to go through a separate step (like "use a different device") on Android to avoid enrolling the phone as passkey.

I can see how users spread active credentials across multiple services which seems like a massive #infosec issue to me...

The younglings don't even understand why not being able to turn off autoplay is a bad thing 😭
Γ—
When the wolves were at the door in the past, how did people survive? They accumulated assets as possible, evaluated who was trustworthy, maintained lines of communication, formed community level mutual aid & defense societies, and importantly still sought ways to be happy.
Be very fucking assured, those that wish to poison and destroy my brothers and sisters delight in our anguish and isolation. It is a benchmark, one of many on the way to totalitarian goals.