GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by da_667 (da_667@infosec.exchange), page 2

  1. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 04-May-2026 22:08:48 JST da_667 da_667
    in reply to
    • Rich Felker

    @dalias really?

    In conversation about a month ago from infosec.exchange permalink
  2. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 04-May-2026 22:07:15 JST da_667 da_667
    in reply to
    • Rich Felker

    @dalias I absolutely want executives in cuffs for failing to secure data that I have no choice but to trust to them, that is mostly immutable. They get paid ridiculous sums of money for the job, but there are zero consequences for that failure. and if that means an executive gets jail time for failing to patch a box, I would welcome it. At the same time, I would absolutely welcome them getting imprisoned for the collection of PII, especially biometric data.

    When I acquired my credit card in the early 2000s, I never once needed to take a picture of my license, or take a picture of myself for some credit card company to verify my identity. They tell you that the data isn't stored, but if it isn't, then why did they need it in the first place?

    In conversation about a month ago from infosec.exchange permalink
  3. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 04-May-2026 21:54:39 JST da_667 da_667
    in reply to

    nobody is held liable when breaches occur and your PII gets stolen for the fifth time in a single year.

    And then we read the inevitable report that it was a third-party managed system that was 6 months behind in patches that got popped. Or it was a risk assessment result that they said "they would get to that eventually" and never did.

    You start throwing executives in cuffs for failing to do their duty and sure as shit things would start changing.

    In conversation about a month ago from infosec.exchange permalink
  4. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 04-May-2026 21:54:39 JST da_667 da_667
    in reply to

    Is what I said right? am I a fucking loon for having said it? I don't care. I haven't seen any improvements over the past 20 years I've been here and I'm fresh out of fucks to give when so-called professionals telling me that the way we've been doing things for so long, which has produced nothing positive so far as I have seen, should be maintained, stop questioning it.

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/514/313/414/328/178/original/97c0ef04e97f2a96.png
  5. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 04-May-2026 21:53:56 JST da_667 da_667

    I'm going to say something that's been festering in my mind for a while now. In my two decades of practice in information security, I have yet to see responsible disclosure result in measurably better security posture.

    Code quality hasn't improved, patch management hasn't improved, minimum viable product hasn't improved, automated security updates, especially for IoT devices... Jesus Fucking Christ haven't improved. The cost of failure for organizations losing your data due to gross negligence has in no way improved, why should responsibility be the domain of the security researcher when nobody else is willing to share in that responsibility?

    I'm half-tempted to say if you have 0-days you might as well get paid for them than be responsible. Because even with a tilted playing field, nothing has measurably improved since I've been here and I would argue with "vibe coding" and the tech industry's view of "Let the AI handle it" that software quality is the worst it has been since the 90s. I lived through windows millennium edition. I've seen shit you wouldn't believe.

    "Hardware's fucked because we can't buy any, software is fucked because the LLMs trained by reddit and stack overflow are in charge now. You might as well fucking guess at this point."

    In conversation about a month ago from infosec.exchange permalink
  6. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 03-May-2026 04:55:29 JST da_667 da_667
    • Cat 🐈🥗 (D.Burch) :paw:⁠:paw:

    @catsalad

    In conversation about a month ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/506/724/143/223/725/original/1b04c04618b82eab.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/506/726/501/742/212/original/2e68e058c313efd5.jpg
  7. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Sunday, 26-Apr-2026 14:38:26 JST da_667 da_667

    Storyline:

    MC: "I'm a lowborn person who can handle mcguffanite, even though commoners shouldn't be able to."

    Authority: "We need the MC to handle the mcguffanite. Otherwise monsters will come and eat our potatoes."

    Nobles:"Dude, fuck the MC, handle the mcguffanite. Why do they think they are tryna save the world? Fuck that. smacks MC

    MC: "Oh no, I can't handle the mcguffanite because I'm hurt!"

    Monsters: "Lookit dem potatoes! Don't mind if I do!"

    Nobles: surprised pikachu face

    Authority:*The nobles have doomed us all

    Nobles: 🤷

    MC: "If I don't handle the mcguffanite, more people will lose their potatoes!"

    Frens of the MC: "No, you cant!"

    MC: "I just did! blergh :blobdead: "

    Nobles: And we learned zero lessons

    In conversation about 2 months ago from infosec.exchange permalink
  8. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 25-Apr-2026 12:37:03 JST da_667 da_667

    @krishean

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/463/236/249/366/983/original/04453d23dab4685d.png
  9. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 25-Apr-2026 03:18:11 JST da_667 da_667

    as always, they are wrong is going to be my new favorite phrase to drop into my writing.

    In conversation about 2 months ago from infosec.exchange permalink
  10. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 25-Apr-2026 02:51:26 JST da_667 da_667

    remember when we used to be able to do pointless shit on the internet for fun?

    https://leekspin.co/

    In conversation about 2 months ago from infosec.exchange permalink
  11. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 24-Apr-2026 22:54:06 JST da_667 da_667

    feeling extra spicy today.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/459/906/693/658/778/original/0a104ce37069897f.png
  12. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Friday, 24-Apr-2026 04:00:36 JST da_667 da_667

    both of my bassetts are snoring on their dog beds behind me. I'm jelly AF.

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/455/303/751/219/281/original/50028be28c9bfad8.png
  13. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 22-Apr-2026 02:50:28 JST da_667 da_667

    "The maintenance is gonna suck"

    "Who the fuck cares? We all work in tech. Either you're gonna do the maintenance, or its going to scheduled its maintenance window for you."

    In conversation about 2 months ago from infosec.exchange permalink
  14. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Tuesday, 21-Apr-2026 03:51:22 JST da_667 da_667

    "You're an elder millenial with over 10 years experience, and you no longer exist to be a people pleaser" in a nutshell

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/437/111/297/220/888/original/e08f992b37d2bff0.jpg
  15. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 20-Apr-2026 12:30:05 JST da_667 da_667

    "Execs getting pay raises, while every else plays employment russian roulette to make Q4 look good" in a nutshell

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  16. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 18-Apr-2026 17:57:51 JST da_667 da_667

    BORN TO PCAP
    TCP STREAM IS A FUCK
    DROP EM ALL
    I AM SURICATA MAN
    410,376,111,223 ALERTS

    In conversation about 2 months ago from infosec.exchange permalink
  17. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Saturday, 18-Apr-2026 10:33:44 JST da_667 da_667

    6,000 followers.

    Why are you here?

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/421/885/736/600/099/original/891e084b4a7b3360.png
  18. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Thursday, 16-Apr-2026 00:08:45 JST da_667 da_667

    yeah

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/408/715/946/790/608/original/17888077218d3850.png
  19. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Wednesday, 15-Apr-2026 23:07:45 JST da_667 da_667

    dear Sans: it was one course, over 10 years ago, back when the government paid for it for me.

    Please stop asking me if I'd like to buy an 8,000.00+ one-week class.

    In conversation about 2 months ago from infosec.exchange permalink
  20. Embed this notice
    da_667 (da_667@infosec.exchange)'s status on Monday, 13-Apr-2026 02:09:16 JST da_667 da_667

    OH? YOU ARE APPROACHING MY REGISTER? APPROACHING MY WAFFLE HOUSE?

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/392/819/400/884/209/original/bf5091eba9964b96.png
  • After
  • Before

User actions

    da_667

    da_667

    Senior Security Researcher, Proofpoint Emerging Threats. Digital ArcanistI've been doing this cybersecurity thing for the better part of a decade now. Probably longer than that. I'm starting to forget. Time is relative, but it surely isn't kind to my memory.I'd like to think I do cybersecurity well, but blue teamers collectively get told they're doing it wrong constantly. So maybe I just failed forward throughout my career.Oh, I wrote a book. Its a good framework for setting up a virtual machine lab. See my bookmarked toots if you're curious.Finally, I occasionally write about tech/nerd-related things over at https://www.totes-legit-notmalware.site where I expose that I have a short fuse, and no filter.Work-Related hashtags:#Iocs #ThreatIntel #DFIR #Malware #NSM #suricata #snort #BEC #phishing #APT #ThreatDetectionHobbies:#VideoGames #XCOM2 #Minecraft #Synthetik #Fallout #Skyrim #Anime #Manga #Adventure #Fantasy #Isekai #HomeImprovement #WoodWorking #MetalWorkin

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          30576
          Member since
          18 Nov 2022
          Notices
          386
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.