GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Charl van der Walt (charlvdwalt@infosec.exchange)

  1. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Tuesday, 13-May-2025 00:41:33 JST Charl van der Walt Charl van der Walt
    in reply to

    Thanks everyone for your comments on this. I like this excerpt from doesmysiteneedhttps.com:

    "this discussion isn't about PKI. It's the best system we've got for right now. Deal with it and secure your site. Use CAA records to restrict which CAs can issue certificates for your site, then cross your fingers and hope transparency and oversight works (it does, so far)".

    Do you all feel that there is enough integrity in browser trusted root certificate stores to still provide robust defence against the content / malware injection threat?

    Also - have these kinds of injection attacks ceased now, and is SSL the reason for this?

    Thanks!

    In conversation about 3 days ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Does my site need HTTPS?
      from @mholt6
      Find out if your site needs HTTPS.
  2. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Tuesday, 13-May-2025 00:38:05 JST Charl van der Walt Charl van der Walt
    in reply to
    • Marcus Hutchins :verified:

    @malwaretech side note (and maybe I gave flu and it’s making me more stupid) but what are the arguments for having SSL on brochureware websites that don’t collect private information?

    In conversation about 3 days ago from infosec.exchange permalink
  3. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Saturday, 26-Apr-2025 21:37:02 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller innovation in cybercrime is always in the “crime”, hardly ever in the “cyber”.

    In conversation about 20 days ago from infosec.exchange permalink
  4. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Tuesday, 21-Jan-2025 23:03:54 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller I generated this set of predictions using an AI we configured for this purpose during the US elections. Interesting to check in on it from time to time…

    https://www.linkedin.com/pulse/modelling-security-elections-future-charl-van-der-walt-kh59f?utm_source=share&utm_medium=member_ios&utm_campaign=share_via

    In conversation about 4 months ago from infosec.exchange permalink
  5. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Thursday, 19-Dec-2024 17:01:41 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller this is how “AI” is “revolutionising” our world. We have tools that write shit and tools that check what shit shit was written. What happened to all the poor African farmers whose lives it was supposed to transform. Or wait, was that blockchain…?

    In conversation about 5 months ago from infosec.exchange permalink
  6. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Wednesday, 14-Aug-2024 16:10:09 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller I wonder if Iran exclusively targeted GOP assets, or if they’re targeting political players generally? If they’d hit a Democrat inbox, would they have kept it to themselves or leaked it also? The Russian playbook seems to be to sow discord generally. Are the Iranians exclusively interested in hurting Trump, or the USA in general ?

    In conversation about 9 months ago from infosec.exchange permalink
  7. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Sunday, 09-Jun-2024 18:56:41 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller does anyone have any evidence, or even anecdotes, of these actors significantly “levelling up” using AI? I’ve seen examples of fake video and voice being used in social engineering , but all other evidence seems to suggest the contrary?

    In conversation about a year ago from infosec.exchange permalink
  8. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Thursday, 04-Apr-2024 03:58:01 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller 😂

    In conversation about a year ago from infosec.exchange permalink
  9. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Wednesday, 03-Apr-2024 20:16:36 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller This is so awesome, but I couldn’t help LOLing at “revolutionary “wind assisted propulsion” concept”…

    In conversation about a year ago from infosec.exchange permalink
  10. Embed this notice
    Charl van der Walt (charlvdwalt@infosec.exchange)'s status on Tuesday, 02-Apr-2024 20:24:01 JST Charl van der Walt Charl van der Walt
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller Can someone fill in the blanks for me: I don’t get the connection between this “botnet” and national critical infrastructure. How are the two connected? How do they know there is a connection? What real benefit would such a botnet have to a state-level actor?

    In conversation about a year ago from infosec.exchange permalink

User actions

    Charl van der Walt

    Charl van der Walt

    Hi I'm Charl. Head of Security Research at Orange Cyberdefense. @charlvdwalt on Twitter. Opinions my 'own'.https://youtu.be/ifKKGtFoB9k

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          242304
          Member since
          13 Feb 2024
          Notices
          10
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.