RIP vmware
Notices by Viss (viss@mastodon.social), page 6
-
Embed this notice
Viss (viss@mastodon.social)'s status on Tuesday, 13-Feb-2024 18:18:44 JST Viss -
Embed this notice
Viss (viss@mastodon.social)'s status on Tuesday, 06-Feb-2024 05:31:17 JST Viss go to the cloud they said.
it'll be fine, they said. -
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 04-Feb-2024 21:09:30 JST Viss -
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 04-Feb-2024 06:18:59 JST Viss @da_667 theres a huge difference between 'keeping something at like 150 degrees in a slowcooker' and 'the same thing but under 12psi in the instant pot'.
shit will turn into liquid way faster than you think in that thing.
ive melted several meals in mine because i thought the same thing :D
-
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 28-Jan-2024 00:40:19 JST Viss @dangoodin one thing their writeup doesnt make clear, is that they were corporate credentials.
thats the only way that you can draw a dotted line from "some test vm somewhere with some kind of creds" to "execs and security team emails".
they refer to it as 'tenant', but there are only two possible explanations for what happened:
1) it was indeed 'customer gear', but staff logged into it for some reason
2) it was corp gear, and they're just calling it 'tenant'.
-
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 28-Jan-2024 00:40:18 JST Viss @dangoodin the first possitiblity is a massive can of worms with regards to implications.
if it is indeed 'customer equipment', then why did someone with corporate creds log into it? does ms routinely log into customer stuff with corp creds and not consider cached creds or logs or anything like that?
or is it the other - where they leave corp creds stashed on some vm they abandoned months or years ago and left to rot?
neither are great. but one is definitely worse.
-
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 28-Jan-2024 00:40:16 JST Viss @haroldgodwinson @dangoodin thats the second scenario. where it was indeed some kind of corp vm or something they setup and used legit corp creds on it, then .. just fucked off? and left it to fester?
-
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 28-Jan-2024 00:40:14 JST Viss @haroldgodwinson @dangoodin a system is only as good as its sysadmin.
you can harden windows boxes, even unpatchable ones.
you can make macs and linux woefully insecure. I have seen it all.
being a sysadmin is a lot of fun and its really rewarding to build cool shit and watch it hum along under pressure.
but its when they get lazy and assume 'the cloud will do stuff for me' - thats where demons and plagues and evil lives.
-
Embed this notice
Viss (viss@mastodon.social)'s status on Friday, 26-Jan-2024 06:08:19 JST Viss remember how last week 23andme said the users were to blame because of their bad password hygiene? this week we find out the attackers were cavediving in their small intestines for 6 months?
this is exactly the sort of scenario these new SEC rules were written for:
-
Embed this notice
Viss (viss@mastodon.social)'s status on Friday, 26-Jan-2024 06:08:19 JST Viss 23andme attacker dwell time: 6 months
-
Embed this notice
Viss (viss@mastodon.social)'s status on Saturday, 13-Jan-2024 09:32:09 JST Viss @horse im pleased you approve :D
-
Embed this notice
Viss (viss@mastodon.social)'s status on Saturday, 13-Jan-2024 09:30:51 JST Viss welp, better get started on my hackcon oslo training slide deck
-
Embed this notice
Viss (viss@mastodon.social)'s status on Thursday, 11-Jan-2024 06:32:29 JST Viss @mmasnick i can say that i appreciate you here way more than on bsky, in that like 90% of my feed content there is politics and the drama surrounding that, and it gets tiresome pretty quickly - there are way broader topics here - if theres something i can do to make you feel welcomed here more than there i'm happy to do it!
-
Embed this notice
Viss (viss@mastodon.social)'s status on Thursday, 11-Jan-2024 03:31:17 JST Viss @mmasnick @dangoodin @briankrebs i tried there. i really did. but there are people who i have gone to some lengths to avoid and bsky does that shitty thing twitter does where it will show you replies from someone you follow, responding to someone you have blocked, and showing you that the previous post in the thread isnt visible to you.
its an incredibly stupid design decision and it makes me crazy, so closed the tab for a couple weeks
-
Embed this notice
Viss (viss@mastodon.social)'s status on Wednesday, 10-Jan-2024 11:24:01 JST Viss @jerry cool they can take all those ssl vpn vulns with em
-
Embed this notice
Viss (viss@mastodon.social)'s status on Monday, 08-Jan-2024 06:08:08 JST Viss spotted on imgur.
something i figured @foone might appreciate -
Embed this notice
Viss (viss@mastodon.social)'s status on Friday, 29-Dec-2023 05:51:08 JST Viss go to the cloud they said
it'll be fine they said -
Embed this notice
Viss (viss@mastodon.social)'s status on Friday, 15-Dec-2023 16:49:34 JST Viss this is the real trolley problem
-
Embed this notice
Viss (viss@mastodon.social)'s status on Tuesday, 28-Nov-2023 16:14:53 JST Viss oof.
-
Embed this notice
Viss (viss@mastodon.social)'s status on Sunday, 19-Nov-2023 09:08:46 JST Viss yup