GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Royce Williams (tychotithonus@infosec.exchange)

  1. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Thursday, 04-Dec-2025 03:02:43 JST Royce Williams Royce Williams
    in reply to
    • Ryan Castellucci :nonbinary_flag:

    @ryanc Make uptime in scope.

    In conversation about 18 hours ago from infosec.exchange permalink
  2. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Thursday, 04-Dec-2025 03:02:02 JST Royce Williams Royce Williams
    in reply to
    • Ryan Castellucci :nonbinary_flag:

    @ryanc Now you just need a poll with three options. 😉

    In conversation about 18 hours ago from infosec.exchange permalink
  3. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Tuesday, 02-Dec-2025 01:29:34 JST Royce Williams Royce Williams
    in reply to
    • Infoseepage

    @Infoseepage I've had some luck with physical analogy: "do you only have one house key?"

    In conversation about 3 days ago from infosec.exchange permalink
  4. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Monday, 01-Dec-2025 15:29:12 JST Royce Williams Royce Williams
    in reply to
    • Infoseepage

    @Infoseepage 100% same - /r/yubikey has made fun of me a couple of times for having 10 (If you count cross-registering with a spouse, etc).

    In conversation about 3 days ago from infosec.exchange permalink
  5. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Monday, 01-Dec-2025 15:22:56 JST Royce Williams Royce Williams

    I am appalled at how many passkey implementations don't understand that someone might want more than one.

    In conversation about 3 days ago from infosec.exchange permalink
  6. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Sunday, 16-Nov-2025 06:36:25 JST Royce Williams Royce Williams

    I don't know why this is how I found out.

    https://www.nytimes.com/2025/11/13/us/politics/alaska-phone-voting-anchorage.html

    Anchorage is going to try voting by phone.

    No one who understands the problem space thinks this is a good idea.

    In conversation about 19 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: phone.No
      Domain Default page powered by phone.no
      from bestwebdesign
      Domain Default page - bestwebdesign
  7. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Sunday, 09-Nov-2025 03:08:46 JST Royce Williams Royce Williams

    Develop habits that will work well in old age.

    Start them now.

    You will not be able to switch to them later.

    In conversation about a month ago from infosec.exchange permalink
  8. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Friday, 07-Nov-2025 05:26:12 JST Royce Williams Royce Williams
    in reply to
    • feld

    @feld Came here to say this; left satisfied

    In conversation about a month ago from gnusocial.jp permalink
  9. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 05-Nov-2025 06:41:51 JST Royce Williams Royce Williams
    in reply to
    • feld

    @feld Oof. Does the mechanism provide a way for the defederating server to say why it happened? Or is it just totally opaque?

    In conversation about a month ago from infosec.exchange permalink
  10. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 05-Nov-2025 06:41:50 JST Royce Williams Royce Williams
    in reply to
    • feld

    @feld 😐

    In conversation about a month ago from gnusocial.jp permalink
  11. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 15-Oct-2025 00:36:05 JST Royce Williams Royce Williams
    • Thomas 🔭🕹️

    @thomasfuchs Yeah, by itself "source?" can be perceived or intended as aggressive ("your post is clearly false"). Additional context is needed if your intent is constructive ("Where did you get this? I want to share it with others")

    In conversation about 2 months ago from infosec.exchange permalink
  12. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Thursday, 09-Oct-2025 13:38:09 JST Royce Williams Royce Williams
    in reply to
    • feld

    @feld Interesting - I've never done that kind of lateral shift. Is it tricky?

    In conversation about 2 months ago from infosec.exchange permalink
  13. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 24-Sep-2025 05:25:57 JST Royce Williams Royce Williams
    • Kevin Beaumont

    @GossiTheDog

    Updated to include:

    https://www.yubico.com/press-releases/yubico-and-t-mobile-deployment-of-200000-phishing-resistant-yubikeys-enhances-un-carriers-work-systems-security/

    In conversation about 2 months ago from gnusocial.jp permalink
  14. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 24-Sep-2025 05:22:29 JST Royce Williams Royce Williams
    • Kevin Beaumont

    @GossiTheDog

    I should have been collecting the receipts on a rolling basis; chatter at the time for multiple of these was "deploying fast now for highest risk, doing the rest in a more controlled fashion after".

    Thinking of:

    • npm ("encouraging FIDO2", anyway)

    • T-Mobile - https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation

    • Twitter - https://blog.x.com/engineering/en_us/topics/insights/2021/how-we-rolled-out-security-keys-at-twitter

    And probably:

    • Uber ("further strengthening our MFA", reading between the lines for 2022 breach and 2023 deployment) - https://www.uber.com/newsroom/security-update/

    • Discord (again, reading between the lines - 2023 breach, 2025 deployment)

    • eBay (public evidence is thinner here, but I got a couple of confidential reports)

    And a couple "we could see the writing on the wall" (they get points for that):

    • Google (2017) - https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/

    • Cloudflare - https://blog.cloudflare.com/how-cloudflare-implemented-fido2-and-zero-trust/

    In conversation about 2 months ago from gnusocial.jp permalink

    Attachments



    1. Domain not in remote thumbnail source whitelist: ubernewsroomapi.10upcdn.com
      US Archives
      Official Uber Newsroom for the latest company announcements in US.
    2. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      cloudflare
    3. Domain not in remote thumbnail source whitelist: cf-assets.www.cloudflare.com
      How Cloudflare implemented hardware keys with FIDO2 and Zero Trust to prevent phishing
      Adopting a phishing resistant second factor, like a YubiKey with FIDO2, is the number one way to prevent phishing attacks. Cloudflare has used phishing resistant second factors only since February 2021, and these were the steps we took to accomplish that.
  15. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 24-Sep-2025 04:59:47 JST Royce Williams Royce Williams

    How many stories of "get popped, then do an emergency FIDO2 deployment" does your leadership need to read before you decide to deploy FIDO2 proactively?

    In conversation about 2 months ago from infosec.exchange permalink
  16. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Tuesday, 16-Sep-2025 04:13:45 JST Royce Williams Royce Williams
    • Poul-Henning Kamp

    Varnish Cache project to change its name to Vinyl Cache with after the next release (after today's 8.0.0, in March), per @bsdphk:

    We have tried to negotiate with Varnish Software for many months about this issue, but their IP-Lawyers still insist that Varnish Software owns the Varnish Cache name, and at most we have being offered a strictly limited, subject to their veto, permission for the FOSS project to use the “Varnish Cache” name.

    We cannot live with that: We are independent FOSS project with our own name.

    So we will change the name of the project.

    The new association and the new project will be named “The Vinyl Cache Project”, and this release 8.0.0, will be the last under the “Varnish Cache” name. The next release, in March will be under the new name, and will include compatibility scripts, to make the transition as smooth as possible for everybody.

    https://fosstodon.org/@bsdphk/115208900512511929

    #VarnishCache #VinylCache

    In conversation about 3 months ago from infosec.exchange permalink
  17. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Wednesday, 10-Sep-2025 05:10:51 JST Royce Williams Royce Williams
    in reply to
    • mhoye
    • Rich Felker

    @dalias

    No disagreement, though we might need to call it 1.5FA. I think it's hard to overstate the insecurity that comes when users have absolutely zero second factor whatsoever -- it turns the entire world into those random store clerks!

    But it's also hard to get companies to treat SMS MFA as they should: as an emergency stopgap to cover them while they make better options available, and to allow users to opt into those stronger factors as quickly, and as early, as possible.

    @mhoye

    In conversation about 3 months ago from infosec.exchange permalink
  18. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Saturday, 06-Sep-2025 03:38:26 JST Royce Williams Royce Williams
    in reply to
    • Michael Richardson
    • Ryan Castellucci :nonbinary_flag:

    @ryanc

    The level of arsing required is lower than you might think, especially with projects like (apologies if you're already familiar):

    https://github.com/trailofbits/algo

    https://zeltser.com/deploy-algo-vpn-digital-ocean/ (just for references; I don't think DO has an IRL presence)

    @mcr314

    In conversation about 3 months ago from infosec.exchange permalink
  19. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Saturday, 30-Aug-2025 21:46:46 JST Royce Williams Royce Williams
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller Et tu, El Reg? 😭

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/117/765/987/355/082/original/22358f8d50f7a9fb.png
  20. Embed this notice
    Royce Williams (tychotithonus@infosec.exchange)'s status on Monday, 18-Aug-2025 23:41:52 JST Royce Williams Royce Williams
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller Another buried lede:

    https://infosec.exchange/@tychotithonus/115046442946529467

    In conversation about 4 months ago from infosec.exchange permalink
  • Before

User actions

    Royce Williams

    Royce Williams

    Just doing my undue diligence.ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.Day job: Enterprise Security Architect for an Alaskan ISP.Obsessed with security keys:techsolvency.com/mfa/security-keysMy 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":youtube.com/watch?v=-uiMQGICeQY&t=20260sFollowed you out of the blue = stole you from someone I respect.Blocked inadvertently? Ask!Am I following a dirtbag? Tell me!Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.Boosts not about security ... usually are.Banner: 5 rows of security keys in a wall case.#NonAIContent#hashcat #Alaska #YubiKeys #LicensePlatesP.S. I hate advance-fee scammers with the heat of 400B suns❤️:⚛👨👩👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          92920
          Member since
          29 Jan 2023
          Notices
          139
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.