GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Adrian Sanabria (sawaba@infosec.exchange)

  1. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Tuesday, 20-Jan-2026 20:53:59 JST Adrian Sanabria Adrian Sanabria
    • Cory Doctorow
    • iFixit

    The enshittification of computer repair is happening.

    AI has amazingly managed to make repairable computers practically worthless.

    The increase in memory and storage pricing is destroying the second-hand market for computing hardware and this makes me sad. I watched a video from someone that runs a repair shop, and this is what's happening:

    The memory/storage alone is worth more than the rest of the computer, so people are stripping them out to sell separately.

    The second hand market is now flooded with computers that have no memory or storage. Buying new memory or storage to put in these used computers is now more expensive than buying a new computer.

    So we now suddenly have a giant e-waste problem PLUS a giant problem for repair shops that want to stay in business.

    In the video, he was basically saying that they have to pivot to the only computers that folks aren't stripping RAM and storage out of - computers that have those things soldered on. The irony here is that repair shops now have to ignore the most repairable computers and focus on the least repairable computers instead.

    https://www.youtube.com/watch?v=T6eiFyJMWgM

    cc @pluralistic @iFixit

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Buy happening.ai | Spaceship
      Own happening.ai today. Secure checkout and guided transfer support. No hidden fees.

  2. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Monday, 08-Dec-2025 23:54:05 JST Adrian Sanabria Adrian Sanabria
    • Tod Beardsley
    • Kevin Beaumont

    @GossiTheDog @todb It reads like, “hey, there was some detail missing from the first CVE, so here’s a new CVE with extra details”

    In conversation about 3 months ago from infosec.exchange permalink
  3. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 08-Nov-2025 08:36:40 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont
    • Sam Bowne :donor:
    • fuzzyfuzzyfungus

    @sambowne @fuzzyfuzzyfungus @GossiTheDog This would kill entire market segments if true. Bitsight, Security Scorecard, Upguard, Censys, and a few dozen other security vendors would have to cease operations immediately

    In conversation about 4 months ago from infosec.exchange permalink
  4. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Thursday, 06-Nov-2025 09:23:48 JST Adrian Sanabria Adrian Sanabria
    • Kevin Beaumont

    @GossiTheDog I still maintain they'll end up giving it away for free. No one wants to pay for it, the value just isn't there.

    In conversation about 4 months ago from infosec.exchange permalink
  5. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Friday, 17-Oct-2025 22:06:34 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog went through the thread here, but didn't find a clear answer - do we know how attackers got their initial foothold into JLR?

    Sounds like, if no, the obvious guess would be the same way M&S and Co-Op got hit since they were also using TCS?

    In conversation about 5 months ago from infosec.exchange permalink
  6. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Wednesday, 15-Oct-2025 07:14:09 JST Adrian Sanabria Adrian Sanabria

    This Korean data center fire keeps getting more and more tragic. Here’s what I know, to catch you up.

    1. Back in 2017, S.Korea built “G Drive” for government officials to store all their files (no relation to Google drive, the ‘G’ stands for Government)
    2. They were told to store all their stuff in G Drive, not on their local systems.
    3. They were concerned about battery backups causing a fire, so decided to move half the li-ion batteries to the basement.
    4. One of the li-ion batteries exploded as it was being unplugged, setting the building on fire. Several floors of datacenter were affected.
    5. They’ve recovered roughly a third of the data.
    6. none of it was backed up, because 1 petabyte was “too large to back up”
    7. In 2017, one AWS Snowmobile 18-wheeler held 100 petabytes, so “too big to back up” doesn’t make a lot of sense
    8. 125,000 government employees lost all their data

    This is WILD. Go to any failing mall in America and choose a retailer at random. Spencer’s Gifts? They probably do backups. Jamba Juice? Backups. The CBD vape store? Okay, maybe they don’t do backups, but everybody else does.

    One of the most technologically advanced 1st world nations in the world DOESN’T BACK UP government data? I’m still floored by this.

    In conversation about 5 months ago from infosec.exchange permalink
  7. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Tuesday, 09-Sep-2025 02:13:32 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog is this a new attack vector? Typically, I've seen attackers use the NPM install scripts to put malware on systems, and they typically leave the package code itself alone, right?

    In conversation about 6 months ago from infosec.exchange permalink
  8. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Sunday, 22-Jun-2025 00:48:54 JST Adrian Sanabria Adrian Sanabria

    Every cybersecurity firm pitching vendor press releases to me: "Attackers are getting more advanced and sophisticated"

    The news:

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/722/038/407/509/591/original/e31abb0e2bb394c5.png
  9. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Tuesday, 17-Jun-2025 23:25:29 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog overdependence on search engines has similar results for the same reasons

    In conversation about 9 months ago from infosec.exchange permalink
  10. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 14-Jun-2025 01:10:56 JST Adrian Sanabria Adrian Sanabria
    • Kevin Beaumont

    @GossiTheDog it looks like she is saying that it only posts things publicly if you ask it to

    so more of a situation where people don’t understand what the share button does

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/676/924/274/583/138/original/e2f0383f425627d9.jpeg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/676/924/275/747/623/original/d8afb9dea22ced34.jpeg
  11. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 17-May-2025 04:12:40 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog to be fair, IIRC, Coop Sweden went down because their payment provider used Kaseya.

    So, it was ransomware on a fourth party, nothing Coop Sweden had any direct control over

    In conversation about 10 months ago from infosec.exchange permalink
  12. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 26-Apr-2025 07:29:48 JST Adrian Sanabria Adrian Sanabria
    • Kevin Beaumont

    @GossiTheDog if you’re on a box, can’t you just do the equivalent of Recall with malware? It definitely makes the job of an attacker easier and more streamlined, but not sure it adds up to a massive increase in risk.

    Also, anyone that figures out how to eliminate that one hour every day the planet spends trying to find stuff on their computer could maybe add 10% to global GDP. How much risk is that worth?

    (not that Recall is that solution, but it could be, right?)

    In conversation about 11 months ago from infosec.exchange permalink
  13. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 26-Apr-2025 05:58:53 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog people already screenshot stuff constantly, Recall is just drawing extra attention to an existing issue

    In conversation about 11 months ago from infosec.exchange permalink
  14. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 05-Apr-2025 06:09:24 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog please don’t tell me they were converting cash into crypto to pay a ransom

    That’s like, incident turducken

    In conversation about a year ago from infosec.exchange permalink
  15. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 29-Mar-2025 23:35:40 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Kevin Beaumont

    @GossiTheDog tl;dr - not a threat, you’ll update it anyway, probably don’t need special tools since we’ve been updating crypto forever

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/243/958/918/570/454/original/04ed93080380c7fb.jpeg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/243/961/234/517/271/original/16ab0b8b1b907bcf.jpeg
  16. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Saturday, 29-Mar-2025 23:35:40 JST Adrian Sanabria Adrian Sanabria
    • Kevin Beaumont

    @GossiTheDog doing a webinar in a few weeks, working on the slides

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/243/944/143/499/981/original/1f2135b681b429cf.jpeg
  17. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Wednesday, 05-Mar-2025 12:45:10 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller infiltrated?

    In conversation about a year ago from infosec.exchange permalink
  18. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Monday, 06-Jan-2025 10:21:14 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Rich Felker
    • Hal Pomeranz

    @dalias @hal_pomeranz came here to say this. I remember coming in to work one day at a large payment processor (where I got my start in cybersecurity), and suddenly realizing that most of the people that worked there could just stop coming to the office and there would be zero impact.

    Every department had one or two highly competent people that ended up doing 80-100% of the work that had value. It was literally a mirror of doing group projects in HS/Uni

    In conversation about a year ago from infosec.exchange permalink
  19. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Monday, 16-Dec-2024 10:04:52 JST Adrian Sanabria Adrian Sanabria
    • Kevin Beaumont

    @GossiTheDog LOL, I just downloaded that. Haven't dug in yet though, because deliverables

    In conversation about a year ago from infosec.exchange permalink
  20. Embed this notice
    Adrian Sanabria (sawaba@infosec.exchange)'s status on Thursday, 03-Oct-2024 15:29:52 JST Adrian Sanabria Adrian Sanabria
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller This is fine.

    In conversation Thursday, 03-Oct-2024 15:29:52 JST from infosec.exchange permalink
  • Before

User actions

    Adrian Sanabria

    Adrian Sanabria

    🎙️ Enterprise Weekly Podcast🤝 Founder @bsidesknoxville🗣️ Faculty @IANS_Security🕵️ Security Research🍳 Cooking⛰️ Hiking🏎️ F1"I rant with data!"

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          32777
          Member since
          19 Nov 2022
          Notices
          28
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.