umeHack social
  • FAQ
  • Login
GNU social-nod för Umeå Hackerspace. Inbjudan krävs, men det är bara att hojta till oss om du vill vara med!
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by Paco Hope (paco@infosec.exchange)

  1. Paco Hope (paco@infosec.exchange)'s status on Sunday, 21-Apr-2019 14:08:52 CEST Paco Hope Paco Hope
    Remote profile options...

    So Marcus Hutchins, of #WannaCry fame and who had been arrested in the US has pleaded guilty to writing banking #trojan software. Over on the birdsite there's lots of strong opinions. I blogged my opinion that it's a big world out there and trying to dismiss him as a criminal or pardon him because he's a hero are fundamentally misguided. https://blog.paco.to/2019/marcus-hutchins-infosec-soul-searching/

    In conversation Sunday, 21-Apr-2019 14:08:52 CEST from infosec.exchange permalink
  2. Paco Hope (paco@infosec.exchange)'s status on Sunday, 03-Feb-2019 12:52:08 CET Paco Hope Paco Hope
    Remote profile options...
    • Paco Hope

    I'm running a pi-hole in the house now to block ads and trackers. It's absurdly easy to setup and very effective. Plus the stats are so interesting to see all the ads blocked. The best thing is that because it works at the DNS level, it affects things like TVs, mobile apps, game consoles, and other embedded devices. https://pi-hole.net/

    In conversation Sunday, 03-Feb-2019 12:52:08 CET from infosec.exchange permalink

    Attachments

  3. Paco Hope (paco@infosec.exchange)'s status on Wednesday, 09-Jan-2019 14:29:25 CET Paco Hope Paco Hope
    Remote profile options...

    Not learning a thing from 3D printing of TSA keys or all the data breaches that have happened in the last decade, a firm has created photos-of-keys-as-a-service. It is a bad idea beyond bad ideas.
    This year's announcement. https://www.bbc.co.uk/news/technology-46795616
    Why that's bad.
    https://www.wired.com/2015/09/lockpickers-3-d-print-tsa-luggage-keys-leaked-photos/

    In conversation Wednesday, 09-Jan-2019 14:29:25 CET from infosec.exchange permalink

    Attachments

    1. Invalid filename.
      Would you store your house key in the cloud?
      from BBC News
      Company shows digital solution for lost keys at the CES technology show in Las Vegas.
    2. Invalid filename.
      Lockpickers 3-D Print TSA Master Luggage Keys From Leaked Photos
      from WIRED
      Another lesson in why you should never show pictures of sensitive keys on the Internet.
  4. Paco Hope (paco@infosec.exchange)'s status on Monday, 07-Jan-2019 16:31:57 CET Paco Hope Paco Hope
    Remote profile options...

    This is not a joke. This was an actual progress bar on a web site I use. Microsoft has nothing on these folks. :)

    In conversation Monday, 07-Jan-2019 16:31:57 CET from infosec.exchange permalink
  5. Paco Hope (paco@infosec.exchange)'s status on Sunday, 06-Jan-2019 17:05:20 CET Paco Hope Paco Hope
    Remote profile options...
    in reply to
    • The_Gibson{BBS88/net93/94}
    • nil

    @redfrog @TheGibson I just wish that the headline said "if, like a reasonable person, you feel that violates your trust" as opposed to "if that freaks you out". We need to normalise people who want privacy, and de-normalise (by using words like "freak") companies that violate privacy as a business model.

    In conversation Sunday, 06-Jan-2019 17:05:20 CET from infosec.exchange permalink
  6. Paco Hope (paco@infosec.exchange)'s status on Thursday, 06-Dec-2018 16:11:42 CET Paco Hope Paco Hope
    Remote profile options...

    Oh, man. The 2000s called and they want their integer overflow bugs back.

    "unprivileged users with UID > INT_MAX can successfully execute any systemctl command"

    https://github.com/systemd/systemd/issues/11026

    In conversation Thursday, 06-Dec-2018 16:11:42 CET from infosec.exchange permalink

    Attachments

    1. unprivileged users with UID > INT_MAX can successfully execute any systemctl command · Issue #11026 · systemd/systemd
      from GitHub
      Unprivileged users with UID > INT_MAX can execute any systemctl command due pkttyagent aborting with an assertion at https://github.com/freedesktop/polkit/blob/8c1bc8a/src/programs/pkttyagent.c#...
  7. Paco Hope (paco@infosec.exchange)'s status on Tuesday, 27-Nov-2018 12:15:10 CET Paco Hope Paco Hope
    Remote profile options...

    When I read a report like this on the deceptive design practices, the constant nagging for location access, etc. I sorta shrug. It's obvious to me. But then I have to ask WHY do we allow this? We, who know better, don't advocate on behalf of those who don't know better. How do we fight this business model? How do we fight and prevent this being the norm? https://www.forbrukerradet.no/side/google-manipulates-users-into-constant-tracking

    In conversation Tuesday, 27-Nov-2018 12:15:10 CET from infosec.exchange permalink

    Attachments

    1. Invalid filename.
      New study: Google manipulates users into constant tracking
      By Øyvind Kaldestad from Forbrukerrådet
      New study: Google manipulates users into constant tracking
  8. Paco Hope (paco@infosec.exchange)'s status on Thursday, 15-Nov-2018 10:03:04 CET Paco Hope Paco Hope
    Remote profile options...

    Japan cyber security minister admits he has never used a computer. More secure than any of us!
    https://www.theguardian.com/world/2018/nov/15/japan-cyber-security-ministernever-used-computer-yoshitaka-sakurada

    In conversation Thursday, 15-Nov-2018 10:03:04 CET from infosec.exchange permalink

    Attachments

    1. c2ad64164decde90892d3231c6d2a0b6e603963f24ad2b0c41c1b00d086fecc6.jpg
  9. Paco Hope (paco@infosec.exchange)'s status on Sunday, 04-Nov-2018 14:01:39 CET Paco Hope Paco Hope
    Remote profile options...

    I've just discovered the hot garbage entitled "Certification Magazine's 2019 Annual Salary Survey". Ugh. So American. Don't survey about #infosec #certification if what you're really interested in is US-based companies and how they compensate their American employees who live and work in America. As a proper Brit would, I wrote a sternly-worded letter.

    In conversation Sunday, 04-Nov-2018 14:01:39 CET from infosec.exchange permalink
  10. Paco Hope (paco@infosec.exchange)'s status on Wednesday, 31-Oct-2018 23:20:56 CET Paco Hope Paco Hope
    Remote profile options...

    “Microsoft adopts systemd for Windows. Rewrites it in JavaScript.” Good luck getting to sleep tonight, punks.
    Scary #halloween stories for tech people

    In conversation Wednesday, 31-Oct-2018 23:20:56 CET from infosec.exchange permalink
  11. Paco Hope (paco@infosec.exchange)'s status on Friday, 05-Oct-2018 19:30:16 CEST Paco Hope Paco Hope
    Remote profile options...

    People with "knowledge of the cyber domain" are also low on my list. What the fuck is #cyber? Can you name me two things? One that everyone would agree is cyber and one that everyone would agree is totally not cyber? I mean, I'm gonna assume a horse isn't cyber. But maybe it is. A chair? A door? Obviously everything that has electricity is cyber. An electric toothbrush, a kettle, an analog wristwatch. I just want to cyberstab myself in the cybereye.

    In conversation Friday, 05-Oct-2018 19:30:16 CEST from infosec.exchange permalink

User actions

    Paco Hope

    Paco Hope

    Cloud Security Consultant at AWS. Based in London. Opinions are my own, etc.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          51359
          Member since
          5 Oct 2018
          Notices
          11
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          umeHack social is a social network, courtesy of Umeå Hackerspace. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All umeHack social content and data are available under the Creative Commons Attribution 3.0 license.