computer security person. former helpdesk.

Cyber, USA
Companies are a human problem and those are very, very, very much not a solved problem...
If you ever have imposter syndrome about applying to an F50, don't. I can promise you that you will be disappointed that you ever had any anxiety about it whatsoever.
1
5
2,032
iCloud Hide My Email just generated "3_genders" as my fake address Hmm
11
2
117
3,826
PPF/Ceramic 3pH decon wash+seal: VDA alkaline touchless caustic-free organics strip, fallout removal, VDA buffered acidic descaler, neutralizing zero-residue coat unclog shampoo, degreasing panel wipe, STEK TPU-compatible elastomeric ceramic spray sealant, sacrificial hydrophobic
3
11
6,750
VERY important: This is partial still ridiculously exhaustive chemical sterilization+sealant procedure for a STEK DynoShield PPF scenario, using specialist products as a HOBBY EXERCISE to teach myself what true extreme looks like when engineered, NOT anything anyone needs to do
2
1
5
2,039
The arc of the shaft is long, but it always bends towards the fluffer
9
2
104
13,590
This was supposed to be a subscriber post
3
17
2,984
Children are inventing C2 by first principles
Some NPR podcasts started getting mysterious comments on Spotify. They made no sense to the staff reading them – until someone from a younger generation cracked the code. Hear the story: link.podtrac.com/phns92ui
8
14
179
18,022
SwiftOnSecurity retweeted
nothing gets me fired up in the afternoon like discussing the usage of AI in a SOC before a SOC even has the key foundational elements in place to be successful w AI
11
20
315
18,130
SwiftOnSecurity retweeted
If I had a nickel for every time a Canadian civil aircraft ran out of fuel halfway through its journey and the pilots heroically made an improbable safe glider landing at a random military airstrip, I’d have two nickels. Which isn’t a lot but it’s weird that it happened twice
9
9
274
9,514
SwiftOnSecurity retweeted
I love your planesona
1
2
12
3,433
Little does Rob know, your HR employee (who works for North Korea) is asking your developer job applicants (who are from North Korea) about their hometown (to make sure they are North Korean).
We're screening for North Korean IT workers in the wrong place. Most of the advice on North Korean IT workers is about catching them in the interview. I think that's the wrong place to put most of our effort. The joint advisory four governments just put out is a good example. The hiring advice is almost entirely human: check the applicant's IP against where they say they live, call their phone number, drill the resume live, and ask about their hometown and hobbies. (Apparently "tell me about your hometown" is a security control now.) I'm not knocking any of it. Talking to a real person is still one of the better fraud checks we have. But it only works on applicants, and a laptop farm exists to beat the IP check anyway. None of it helps with the one who already passed, got the laptop, and built a normal work record. And I'd assume one already has. At @OneRSAC last year, @Mandiant's Charles Carmakal said nearly every Fortune 500 CISO he'd talked to about this problem admitted hiring at least one North Korean IT worker. I wouldn't bet on smaller shops doing better. (I'd love to be wrong on that.) The advisory does mention least privilege, in one line, next to revoking accounts once you suspect someone. Revoking only helps once somebody notices. I'd put least privilege at the center for new remote hires. Access should grow with tenure instead of arriving on day one, and you should have a tested answer for how fast you can pull it back. Pick your newest remote engineer. What could they reach, exfiltrate, administer, deploy, or monetize before anyone had a reason to wonder? I built the brand new FOR500: SANS Windows Forensic Analysis case with @HeatherMahalik Barnhart and @ovie Carroll around exactly that hire. Operation Crimson Ledger puts you on the Windows 11 laptop of a remote engineer who cleared the interview and looked normal for months: two remote-access tools, a consumer VPN, an AI coding agent with more screen time than Office, company files staged to a personal Google Drive, a mailbox exported through a second copy of Office, and a wiper run seven times in the two minutes around the upload. (Least privilege wouldn't have stopped all of it, but it would have made the trail a lot shorter.) Advisory: ic3.gov/CSA/2026/260918.pdf SecurityWeek: securityweek.com/japan-disma…
5
11
237
25,108
SwiftOnSecurity retweeted
More on the history of Infosec from someone there, from one perspective, from one of the beginnings. Maybe @johnmccumber could publish the entire PDF or preface somewhere. I found it a very enlightening little treasure.
2
3
16
4,565
SwiftOnSecurity retweeted
Replying to @anton_chuvakin
One of my most favorite, beautiful passages. By @johnmccumber "Bob slowly twirled the unfiltered cigarette in his nicotine-stained fingers and stared at the smoke rising from the end. We were both aware a line had been crossed and the world we inhabited had changed."
3
6
21
3,942
TOMMY TUBERVILLE WARNS THAT “MANY” PILOTS, FLIGHT ATTENDANTS AND AIR TRAFFIC CONTROLLERS ARE FURRIES: “Lord help us. It’s terrifying when you think about this.” Tuberville claimed on the Senate floor that airline workers being part of the furry community poses a danger to passengers, saying a pilot “could have a deranged fetish of dressing up like an animal.”
15
135
2,639
46,255
Anything interesting I could do with these, any preservation needed?
20
3
89
13,196