Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Notices by Tinker ☀️ (tinker@infosec.exchange)

  1. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 18-Sep-2023 19:04:56 EDT Tinker ☀️ Tinker ☀️

    Reminder to go to your local library and volunteer to speak on their behalf. Let them know that if folks try to come and ban books that you'll speak publicly against them.

    We found out folks were going to be commenting at our library calling for banning books.

    So.

    We all went and spoke out against them.

    Only one person got up and called for a ban. She went first. Everyone after her started calling out her behavior and telling the library staff to keep the books.

    The first woman and a couple others soon left before the end of comments.

    Drive them out. Protect our libraries.

    In conversation Monday, 18-Sep-2023 19:04:56 EDT from infosec.exchange permalink
  2. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 02-Oct-2019 17:31:58 EDT Tinker ☀️ Tinker ☀️

    Satire is dead.

    In conversation Wednesday, 02-Oct-2019 17:31:58 EDT from infosec.exchange permalink
  3. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 14-Feb-2019 20:20:02 EST Tinker ☀️ Tinker ☀️

    ~=8 Character Passwords Are Dead=~

    New benchmark from the Hashcat Team shows a 2080Ti GPU passing 100 Billion password guesses per second (NTLM hash).

    This means that the entire keyspace, or every possible combination of:
    - Upper
    - Lower
    - Number
    - Symbol

    ...of an 8 character password can be guessed in:

    ~2.5 hours

    (8x 2080Ti GPUs against NTLM Windows hash)

    #Hacking #Infosec

    In conversation Thursday, 14-Feb-2019 20:20:02 EST from infosec.exchange permalink
  4. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 04-Jan-2019 11:35:37 EST Tinker ☀️ Tinker ☀️

    This has become a passion project of mine.

    Open sourced, general purpose computing hardware.
    Open sourced, cell phone tailored operating systems to run on that hardware.

    Ideally anyone should be able to grab Off the Shelf (OTS) equipment, load an open sourced OS on it, and go.

    And with that.... That's all I've got. If you're working on similar, reach out to me.

    I'm ignorant in so many aspects of this, but I'm learning. I've got some work done, but there's still more.

    In conversation Friday, 04-Jan-2019 11:35:37 EST from infosec.exchange permalink
  5. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 01-Jan-2019 17:17:43 EST Tinker ☀️ Tinker ☀️

    Writeup on Installing KDE Plasma Mobile onto a Raspberry Pi, part of my TinkPhone project.

    Cheers to all that helped and offered encouragement and support!

    #TinkPhone #Phone #FOSS #RaspberryPi #KDE

    https://www.tinker.sh/kde-plamo-rpi/

    In conversation Tuesday, 01-Jan-2019 17:17:43 EST from infosec.exchange permalink
  6. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 17-Dec-2018 17:26:35 EST Tinker ☀️ Tinker ☀️

    Wanna see an Internet Easter Egg?

    Run a traceroute on the hostname: "bad.horse"

    Linux: ~/$ traceroute -m 100 bad.horse
    Windows: C:\> tracert -h 100 bad.horse

    In conversation Monday, 17-Dec-2018 17:26:35 EST from infosec.exchange permalink
  7. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 05-Dec-2018 09:06:29 EST Tinker ☀️ Tinker ☀️
    • Dallas Hackers Association

    Popular Mechanics wrote an article about us!

    @dallas_hackers #hacking

    “Want to Be A Hacker? Go to Dallas.”

    https://www.popularmechanics.com/technology/a24676415/dallas-hackers/

    In conversation Wednesday, 05-Dec-2018 09:06:29 EST from infosec.exchange permalink
  8. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 30-Nov-2018 14:37:03 EST Tinker ☀️ Tinker ☀️

    Dear $marriottMember,

    In light of the recent breach, please sign into your Marriott profile and change your password.

    hxxp://www.marriott.mal/passwdReset

    Signed,
    Marriott (We swear!)

    In conversation Friday, 30-Nov-2018 14:37:03 EST from infosec.exchange permalink
  9. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 28-Nov-2018 12:12:01 EST Tinker ☀️ Tinker ☀️

    Grandpa? Tell me about the cyberwars!

    So there I was... Hunkered down behind the firewall trenches under a barrage of TCP scans!

    All I remember seeing was an onslaught of SYN, SYN, SYN!!! We met them with RST after RST after RST!

    #MicroFiction #SmallStories #TootFic

    In conversation Wednesday, 28-Nov-2018 12:12:01 EST from infosec.exchange permalink
  10. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 13-Oct-2018 12:01:47 EDT Tinker ☀️ Tinker ☀️

    Identity Thieves that *copy* data from Surveillance companies are doing this same thing as those companies - using data of our lives against us without our input or control.

    We should have control over our data.

    This is a political issue.

    Technology has only and will only continue to allow this surveillance at massive scale.

    Vote, run for office, conduct civil disobedience (if you’re willing to face the consequences), call your representatives and hold them accountable.

    #Privacy

    In conversation Saturday, 13-Oct-2018 12:01:47 EDT from infosec.exchange permalink
  11. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 13-Oct-2018 12:00:40 EDT Tinker ☀️ Tinker ☀️

    Note: when a breach claims “stolen data” nothing is stolen.

    Stolen implies that the original content is no longer available.

    Data is copied.

    This is why breaches at Equifax, Experian, Transunion (TLO), etc. have little impact on those corporations.

    They can still do business.

    #Privacy #Hacking #Infosec

    In conversation Saturday, 13-Oct-2018 12:00:40 EDT from infosec.exchange permalink
  12. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 19-Aug-2018 12:32:48 EDT Tinker ☀️ Tinker ☀️

    Mastodon: Your DMs can be read by the admin(s) on your specific instance.

    Twitter: Your DMs can be read by the entire Twitter Corporation.

    In conversation Sunday, 19-Aug-2018 12:32:48 EDT from infosec.exchange permalink
  13. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 19-Aug-2018 10:12:21 EDT Tinker ☀️ Tinker ☀️

    This wired article ( https://www.wired.com/story/join-mastodon-twitter-alternative/ ) about Mastodon is mostly good. It covers the basic features and talks about a shift from Twitter to Mastodon.

    It confuses one key issue though, and that’s the “culture” of Mastodon.

    What we’re seeing now across the Fediverse are the first adopters. The fringe. The queer. The hackers. The staunch individualists. The communal care takers.

    As Mastodon becomes more mainstream, the “culture” will shift.

    If you’re here for the culture, be wary... 1/2

    In conversation Sunday, 19-Aug-2018 10:12:21 EDT from infosec.exchange permalink

    Attachments

    1. Tired of Twitter? Join Me on Mastodon
      from WIRED
      It's like Twitter, but without all the bad people.
  14. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 29-Jun-2018 20:52:58 EDT Tinker ☀️ Tinker ☀️

    Now this is Social Engineering.

    Stuttering John live records his vishing (voice phishing / conning over the phone) of the White House.

    He actually gets in touch with President Trump on Airforce One.

    #SocEng #SocialEngineering #InfoSec #Phishing #Vishing

    http://stutteringjohnpodcast.libsyn.com/the-stuttering-john-podcast-4

    In conversation Friday, 29-Jun-2018 20:52:58 EDT from infosec.exchange permalink
  15. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 29-Jun-2018 16:55:15 EDT Tinker ☀️ Tinker ☀️

    There goes my hope for #KaiOS (a fork of FirefoxOS).

    “Google Leads Series A Investment Round in KaiOS to Connect Next Billion Users”

    #Google #FOSS #FuckOffGoogle

    https://www.kaiostech.com/google-leads-seriesa-investment-round-kaios-connect-next-billion-users/

    In conversation Friday, 29-Jun-2018 16:55:15 EDT from infosec.exchange permalink
  16. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 01-Jun-2018 09:43:07 EDT Tinker ☀️ Tinker ☀️

    We've prepped and have a list of targets.

    Let's hack their email servers and send an email from their CFO to their Accounts Payable staff. Wire some money to an offshore account.

    #hacking #phishing #infosec

    https://www.tinker.sh/phishing-using-an-email-server-against-itself/

    In conversation Friday, 01-Jun-2018 09:43:07 EDT from infosec.exchange permalink
  17. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 28-May-2018 11:52:10 EDT Tinker ☀️ Tinker ☀️

    So what I’m understanding is that I need to make it look like I’m coming from the EU and choose EU settings in order to get a semblance of privacy protection from centralized surveillance web sites?

    #GDPR

    In conversation Monday, 28-May-2018 11:52:10 EDT from infosec.exchange permalink
  18. Tinker ☀️ (tinker@infosec.exchange)'s status on Thursday, 17-May-2018 10:47:21 EDT Tinker ☀️ Tinker ☀️

    Your daily dose of dystopia...

    Google's thought experiment of the "Selfish Ledger."

    Understanding the user so completely as to change the behavior of that user, then applying that at scale to change the behavior of entire populations.

    #Google #DeleteGoogle #FuckGoogle #Privacy

    https://www.theverge.com/2018/5/17/17344250/google-x-selfish-ledger-video-data-privacy

    In conversation Thursday, 17-May-2018 10:47:21 EDT from infosec.exchange permalink
  19. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 14-May-2018 14:22:31 EDT Tinker ☀️ Tinker ☀️
    in reply to

    With all this in mind, from a Corporate Standpoint the risk is minimal. There are other more prevalent, less esoteric attacks that will get an attacker access to clear text emails than #efail.

    From a privacy standpoint of folks who may be targeted by systemic attackers, there is an issue. The risk is minimized in that it is still a targeted attack (they have to send an email to *you* with an old encrypted message buried in it).

    In conversation Monday, 14-May-2018 14:22:31 EDT from infosec.exchange permalink
  20. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 14-May-2018 14:20:09 EDT Tinker ☀️ Tinker ☀️

    As such, the real Attack Scenario here is a Nation State attempting to decrypt old emails it sniffed in transit at the systemic level.

    If they were able to get access to an end point of someone in a shared key thread, they probably can decrypt it with the stored private key on the endpoint, etc.

    A nation state actor could feasibly break TLS or sniff traffic at the email provider, etc.

    Their target would be activists, journalists, or military / other nation states.

    #efail

    In conversation Monday, 14-May-2018 14:20:09 EDT from infosec.exchange permalink
  • Before
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.