🏞 Remember Little Bobby Tables? I think he has a sibling

“Little Billy Ignore Instructions” by Philippe Schrettenbrunner (LinkedIn) Remember Little Bobby Tables? I think he has a sibling. Just some iPad doodles. Stay safe, sanitize all inputs. (Original xkcd comic: Exploits of a Mom) [aka “Little Bobby Tables”] School: Hi, this is your son’s school. We’re having some computer trouble. Parent: Oh dear - did he break something? ...

4 June 2024 Â· 1 min Â· 122 words

🔗 Risk Based Prioritization

Risk Based Prioritization This guide serves as a crucial companion for cybersecurity professionals, offering an in-depth understanding of how to effectively prioritize vulnerabilities in the digital landscape.

22 March 2024 Â· 1 min Â· 27 words

🏞 Share Google Files Securely: The Why and How

Increasing levels of sharing access for files in Google Drive (source) Always remember these three guiding principles when choosing your share settings: Share with the fewest people and lowest level of access and permission as the work allows. Be aware of searchable settings that may unintentionally share the file with others. If no longer needed, reduce sharing permissions or delete files. Combining these principles with an understanding of Stanford’s risk classifications will help you make the best sharing choices. ...

12 October 2023 Â· 1 min Â· 86 words

🔗 User enumeration: what it is and why it matters

Unable to display PDF file. Download View | Source This talk is about user enumeration, its impacts, and why Microsoft should take it seriously. Everything demonstrated is by design. Microsoft has decided that user enumeration does not qualify as a vulnerability. What is User Enumeration? Enables an attacker to identify VALID accounts, and INVALID accounts based on server response Examples: Verbose login response - “Your username is invalid” Time-based login response INVALID Username response time: 10s VALID Username login response time: 1s Web server response differs (403 vs 404 HTTP Status Code) ...

15 August 2023 Â· 1 min Â· 150 words

🔗 Weak Passwords

http://weakpasswords.net 100~ common passwords based on last 90 days, updated daily

15 August 2023 Â· 1 min Â· 11 words
Father pointing to a slate board with a lock drawn in chalk and his 2 twin sons looking at it, in black and white crayons

💭 Educating security

A real story of how following good security practices is both easier to do than ad-hoc methods, and it spreads quickly to others.

18 March 2019 Â· 3 min Â· 461 words

🔗 #GamerGate [Online] Survival Guide | Jon Jones, smArtist

#GamerGate [Online] Survival Guide | Jon Jones, smArtist Here is a quick, streamlined guide on how to keep yourself safe online and make harassing you and tracking you down much more difficult. Two-factor authentication on everything. Password manager for unique, difficult passwords. Install PrivacyFix. Lock down old Facebook posts and adjust your privacy settings. Domain name whois guard. Delete old accounts. Check the internet for your personal information. Use a VPN. Extreme options… See also: ...

23 November 2014 Â· 1 min Â· 96 words

🏞 (image)

Over the course of a year, I researched and created ZXX , a disruptive typeface which takes its name from the Library of Congress’ listing of three-letter codes denoting which language a book is written in. Code “ZXX” is used when there is: “No linguistic content; Not applicable.” (via Making Democracy Legible: A Defiant Typeface — The Gradient — Walker Art Center )

18 July 2013 Â· 1 min Â· 63 words

📋 TSA: Assault rifles vs Nail clippers

masteradept: FYI – from Sgt. Mad Dog Tracy – As the Chalk Leader for my flight home from Afghanistan, I witnessed the following: When we were on our way back from Afghanistan, we flew out of Baghram Air Field. We went through customs at BAF, full body scanners (no groping), had all of our bags searched, the whole nine yards. Our first stop was Shannon, Ireland to refuel. After that, we had to stop at Indianapolis, Indiana to drop off about 100 folks from the Indiana National Guard. That’s where the stupid started. First, everyone was forced to get off the plane-even though the plane wasn’t refueling again. All 330 people got off that plane, rather than let the 100 people from the ING get off. We were filed from the plane to a holding area. No vending machines, no means of escape. Only a male/female latrine. It’s probably important to mention that we were ALL carrying weapons. Everyone was carrying an M4 Carbine (rifle) and some, like me, were also carrying an M9 pistol. Oh, and our gunners had M-240B machine guns. Of course, the weapons weren’t loaded. And we had been cleared of all ammo well before we even got to customs at Baghram, then AGAIN at customs. The TSA personnel at the airport seriously considered making us unload all of the baggage from the SECURE cargo hold to have it re-inspected. Keep in mind, this cargo had been unpacked, inspected piece by piece by U.S. Customs officials, resealed and had bomb-sniffing dogs give it a one-hour run through. After two hours of sitting in this holding area, the TSA decided not to re-inspect our Cargo-just to inspect us again: Soldiers on the way home from war, who had already been inspected, re-inspected and kept in a SECURE holding area for 2 hours. Ok, whatever. So we lined up to go through security AGAIN. This is probably another good time to remind you all that all of us were carrying actual assault rifles, and some of us were also carrying pistols. So we’re in line, going through one at a time. One of our Soldiers had his Gerber multi-tool. TSA confiscated it. Kind of ridiculous, but it gets better. A few minutes later, a guy empties his pockets and has a pair of nail clippers. Nail clippers. TSA informs the Soldier that they’re going to confiscate his nail clippers. The conversation went something like this: ...

27 March 2012 Â· 3 min Â· 620 words