HIPAA doesn't say who has to hold the encryption keys.
Notices by darf ๐ (darfplatypus@infosec.exchange)
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Thursday, 05-Jun-2025 05:08:58 JST darf ๐
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Friday, 23-May-2025 09:14:06 JST darf ๐
@legacv @cR0w I can only imagine that sharing notifications was a bolted on capability and their auth flow doesnt account for that properly. So theres no sense of RBAC for the shared with user and when they click it just lets them in like a fully auth'd user.
but thats me spitballing with literally zero research.
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Friday, 23-May-2025 09:14:05 JST darf ๐
@cR0w @legacv Legacv if you ever get super bored and need an AppSec project, start downloading SOHO router firmware, then binwalk the filesystem out of it, then do security review of their web panels. I'm willing to bet within 10 you look at, you'll find something horribly wrong.
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Friday, 23-May-2025 09:14:04 JST darf ๐
@cR0w @legacv friend of mine and I won a contest at DefCon for backdooring a malicious update into a samsung IOT camera. literally just take firmware off the internet, slam a netcat shell in the init system as root, put it on a web share and DNS AITM to feed it a bad update.
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Tuesday, 06-May-2025 11:51:05 JST darf ๐
@cR0w @Viss im currently waiting for the local place I love to open their brick and mortar after closing their ghost kitchen.
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Tuesday, 06-May-2025 11:51:04 JST darf ๐
@cR0w @Viss theyre the only place ive found around here to do birria. and im pretty sure between me and a friend of mine, we're putting one of their kids through college ๐
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Monday, 05-May-2025 04:29:13 JST darf ๐
@Viss Strategically Transport Equipment to Alternative Locations. ๐
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Friday, 02-May-2025 12:56:25 JST darf ๐
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Monday, 25-Nov-2024 08:23:25 JST darf ๐
@kims as someone who likes dogs considerably more than people, i fully support this!
-
Embed this notice
darf ๐ (darfplatypus@infosec.exchange)'s status on Monday, 25-Nov-2024 07:42:54 JST darf ๐
I'm looking for some stickers to throw on a pelican case along the lines of "sensitive electronics" "danger" "fragile contents" etc if anyone has suggestions on what else I should throw on there and where I can buy them 1 at a time rather than the 500x bulk options on amazon.