Royce Williams

@tychotithonus@infosec.exchange
3.2K Followers
3.8K Following
11.8K Posts

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = probably stole you from follows of someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers with the heat of 400B suns

❤️:⚛👨‍👩‍👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!

Stuffhttps://www.techsolvency.com/roycewilliams/mastodon
Keybasehttps://keybase.io/royce
GitHubhttps://github.com/roycewilliams
LinkedInhttps://www.linkedin.com/in/roycewilliams
Gravatarhttps://gravatar.com/tychotithonus
Not "dehashed"!https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/

After having gone missing in my papers for 30 years, the original ad has been found!

The bottom half (shown here) features what we called the Computer "Toad" (actually a tree frog), and it still features prominently on my ancient ISP-provided tilde page. The photo was a mascot around the office for quite a while.

No idea what the ad was for, but ... enjoy!

#Frogs #TreeFrogs #RetroAds

There's "financial institutions that still break the back button", and then there's "financial institutions that still break the back button, and then denylist my client IP for an hour because use of the back button looks suspicious to their lowest-bidder WAF". 😡

Adobe is now processing all your PDFs in the cloud, by default. The setting to “Enable generative AI features in Acrobat” was on, and I didn’t know it until I opened a document and Adobe asked me if I wanted a document summary. It’s annoying to have to click “No,” so I opened settings to disable the prompt.

THE PROBLEM
I sign Non-Disclosure Agreements for many of my clients. Adobe is a potential leak of protected information. I don’t know what Adobe does with this information. I don’t know what they store, or for how long. I don’t know what country (or countries) the data is stored in. I don’t know what LLMs are trained with this data. And I don’t need to know. What I need to know is that they won’t use default opt-in as a legal excuse to wiretap my information.

I recommend that you check your Adobe settings on all devices, for all Adobe accounts.

#CallMeIfYouNeedMe #FIFONetworks

#cybersecurity

Nothing like a well-commented crontab.

> ‘In this article we propose “local-first software”: a set of principles for software that enables both collaboration and ownership for users. Local-first ideals include the ability to work offline and collaborate across multiple devices, while also improving the security, privacy, long-term preservation, and user control of data.’

— Martin Kleppmann et al, Onward!, 2019

https://www.inkandswitch.com/essay/local-first/

#localfirst #cloud #privacy

Local-first software: You own your data, in spite of the cloud

A new generation of collaborative software that allows users to retain ownership of their data.

Things that could/should be fixed that come to mind re: Texas flood disasters

1. All official messaging from officials about WX conditions in Texas went out to Facebook and X only. (This I cannot fix).

2. Those messages did not make it to local media (that said... so little "local media" anymore). (Again, I can't fix that either)

3. I need to go through and make sure very bot I have here pushing out warnings and graphics for every NWS office is back online. There are a lot of them, and it's a bunch of juggling. (This, I can fix)

#DisasterPreparedness

We ditched CGI in the late 1990s because of the overhead of starting, executing and stopping a process for every incoming request... turns out modern servers (plus languages like Go or Rust with a fast startup time) mean CGI isn't such a bad idea any more! https://simonwillison.net/2025/Jul/5/cgi-bin-performance/
Serving 200 million requests per day with a cgi-bin

Jake Gold tests how well 90s-era CGI works today, using a Go + SQLIte CGI program running on a 16-thread AMD 3700X. Using CGI on modest hardware, it’s possible to …

Simon Willison’s Weblog
I created a Chrome extension called “Tab Extract-n” basically it groups tabs based on a search term. Just type “ex git” in the url bar and it will group all @github and @gitlab and tabs.
(Made after original tab extract stopped being supported) https://chromewebstore.google.com/detail/tab-extract-n/hlbbaplcopkikfjblgkbockaeijighln
Tab Extract-n - Chrome Web Store

Search for tabs and group them in a new window.

Robustness work is about enlarging the system's competence envelope, resilience work is about improving the system's future behavior when it inevitably breaches its competence envelope.
There have been claims that NOAA/NWS did not foresee catastrophic TX floods--but that's simply not true. This was undoubtedly an extreme event, but messaging rapidly escalated beginning ~12 hrs prior. Flood Watch mid PM, "heads up" outlook late PM, flash flood warnings ~1am.

RE: https://bsky.app/profile/did:plc:teckhxpypg6v46gj7iysmmqt/post/3lt6heyboa22l
×

Dinner and a walk through a park festival at day 0 of #confconf in #Sofia, #Bulgaria

Just in those photos you see people who made #FOSDEM, #DENOG, #DebConf, #PromCon, #GrafanaCon, #CCC / #38c3, #WHY2025, #IndiaFOSS, #COSCUP, #FOSSASIA, and others happen. And more people will come tomorrow.

We're looking to have a packed agenda over this coming weekend, and I will try and do my best to update this thread with tidbits and information.

Opening talk of #confconf !

Two more structured talks: about the #FOSDEM video box and what #eventinfra is. Then, unconference!

@RichiH I'd have loved to join you. Unfortunately, this whole 'raising a child' thing takes precedence - it's the first weekend of summer holiday and the start of scouting summer camp, so not a good time for me to be away for a long weekend...

@RichiH Enjoy!

Somehow this did not work out to go there! Hope you have a good time and looking forward to all the feedback.

@RichiH enjoy and greetings to all 🤘🏻
@RichiH have fun. Sofia is a great city.