23 Followers
117 Following
67 Posts
Infosec Dad | Breaker of Technology | Babylon5 Fan ( don't judge me ! )
If you insist that people learn to code in order to use technology, I'm going to insist that you grow your own flax, do the retting, spin it, weave it, and sew it before you're allowed to wear pants.

When I worked at #ICANN years ago there were these great pictures of early networking and Internet typologies on the wall at the main office.

You could no longer get them from the publisher, so I took pictures! [1/2]:

I received this MSI PDT II yesterday, but it has no EPROM so it refuses to start. It is in otherwise excellent condition.
I want to figure out how it works. Does ANYONE on fedi have any idea? Please boost.
Windows Server 2003 turns 20 this year and will celebrate by continuing to operate in critical national infrastructure and manufacturing facilities for another 20 years

Tiny Mastodon Newbie Tip 🐘✨:

If you find not many people Boost (repost) your toots (posts) with photos or memes, it could be because you did not use Alt-text 👁‍🗨

Adding Alt-text to your images will not only make them more accessible, it will also increase the chances that others Boost your toots!  

HOW TO ❓

Here’s how: https://infosec.exchange/@Em0nM4stodon/109323425237412179

#TinyMastodonTip

Em :official_verified: (@[email protected])

Tiny Mastodon Tip for Newcomers 🐘✨: I’ve had many people asking me recently about Alt-text, so here what it is and how to use this feature: Alt-text is used to add a text description to an image you upload so that people who use a screen reader can know what your image is. HOW TO❓ 1. On desktop, when writing a toot (post), you can add an image by clicking on the paperclip icon on the bottom menu on the left. 2. Once your image is uploaded, click on “! No description added” over you image. 3. You will then see a popup allowing you to add a text description of your image. Try to be as clear as possible in your description. It’s okay if it’s short. 4. Click “Apply” and that’s it! You can then publish your toot normally. 5. You can follow @[email protected] to remind you to add alt-text in case you forget 👍✨ #TinyMastodonTip

Infosec Exchange

Notified Experian on Dec. 23 that their site was allowing anyone to see the credit report for, well, basically anyone, completely bypassing their lame 4-5 multiple guess questions and other security.

Or even in cases (like mine) where trying to get your credit report generates an error saying you have 3 other options for getting your free report from them (calling, mailing, or chat w/ rep). The site said Experian didn't have enough info to validate my identity, but when I changed the url slightly, it showed me my entire report. Glad I checked, too, because the info in there is so completely wrong I don't even know where to start.

So it's Dec. 27, and I still haven't heard anything from Experian. All you needed was the person's name, address, SSN and DOB. This info has been exposed on pretty much most Americans for many years now.

BTW, I checked this with several friends who volunteered to check their own reports, and they were able to fully replicate what I did.

It's bad enough that we can't stop companies like Experian from making $2B a quarter collecting and selling our info, but there has to be some real accountability. And as we saw with the Equifax settlement, class-actions and more laughable "credit monitoring" services aren't going to cut it.

Experian has shown this year especially that it gives exactly zero fscks about securing access to the data that drives its entire business.

https://krebsonsecurity.com/2022/08/class-action-targets-experian-over-account-security/

https://krebsonsecurity.com/2022/07/experian-you-have-some-explaining-to-do/

https://krebsonsecurity.com/2021/04/experian-api-exposed-credit-scores-of-most-americans/

Class Action Targets Experian Over Account Security – Krebs on Security

He talked about electric cars. I don't know anything about cars, so when people said he was a genius I figured he must be a genius.

Then he talked about rockets. I don't know anything about rockets, so when people said he was a genius I figured he must be a genius.

Now he talks about software. I happen to know a lot about software & Elon Musk is saying the stupidest shit I've ever heard anyone say, so when people say he's a genius I figure I should stay the hell away from his cars and rockets.

@dangoodin @gdbassett @boblord having written more incident response statements than most CISOs at this point in my career, I find a common pitfall is expecting a single statement to address the concerns of all stakeholders. What works for infosec doesn’t work for everyone.
Good IR comms is an orchestrated symphony of tailored comms that answer different questions for each audience. These various communications align, but they’re not identical.
Online Casinos DraftKings and BetMGM Hacked; Data of Millions at Risk

Follow us on Twitter @HackRead - Facebook @ /HackRead

HackRead | Latest Cyber Crime - InfoSec- Tech - Hacking News

If you are following me,
you might have noticed that I Boost quite a lot of toots.

This is because you are
all saying beautiful things!
And very funny things!
And very useful things!
And very interesting things!

Thank you all!  ​💚