I had a business in Indiana and it got a phishing email with proper dkim/dmarc stuff. The business email address was unique/serves as a breach canary, so I was trying to figure out if Indiana got popped or if govdelivery[.]com was misconfigured/got popped...
@ryanc A few years back I bought a bunch of these. Super duper helpful. We find all sorts of crazy pinouts on industrial products. My favorite to date is a GE thing that output +24v on pin 5 (usually a ground pin on db9), meant for powering a handheld programmer device.
Ah, US healthcare: where determining whether insurance covers a doctor visit takes longer than the doctor visit itself. And the answer they give is: "it depends..."
I enjoy that we call these insurance people who look up the coverage "advocates". Advocates for whom, I wonder.
And, pretty much everything all of the well-known infosec people have been saying is correct: physical access required (or, high privileges and high attack complexity; the score is kinda 'wrong' in some sense because it is combining two exploitation vectors but I think it gets across the point: this is not wormable and is not exploitable via wireless, at least not on its own. and if your threat model allows for physical access but still treats this as a big deal somehow, go home, your threat model is drunk).
Tinker, Sailor, Biker, HiI do industrial security research for a living, mostly looking for #vulnerabilities in all of the wrong places. I like reverse engineering how PLC logic systems function under the hood, learning how safety instrument protocols work, and figuring out what malicious threat groups are doing and can do with access to such systems. A long time ago, I invented the term 'foreverday' to describe unfixable vulnerabilities.Occasionally I analyze #industrial #malware, too, and on very rare occasions encounter threat groups that actually write malicious logic to do the vile things that I like to learn about. I work for a little startup in the space called Dragos. In my spare time I enjoy long distance #bicycling, #sailing, and doting on our #pets.I used to have an account on :birdsite:, however I haven't used it in a while and you should no longer assume that it's under my control.Trying not to be one of the 80% that can be moved in either direction.