Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Notices by Tinker ☀️ (tinker@infosec.exchange), page 2

  1. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 14-May-2018 14:14:24 EDT Tinker ☀️ Tinker ☀️

    For an attacker to sniff an encrypted email in transit (a), the attacker can get it either:
    i) In a targeted Man-in-the-Middle attack
    ii) As a systemic attacker (e.g. NSA, GCHQ, Compromised ISP, etc)

    A couple things make this difficult:
    - Many encrypted emails using S/MIME are sent within a corporate enterprise and never leave the perimeter. (You'd have to breach the corporate perimeter)
    - Emails are often protected via TLS in transit. (either need to break TLS or attack the endpoint)

    #efail

    In conversation Monday, 14-May-2018 14:14:24 EDT from infosec.exchange permalink
  2. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 14-May-2018 14:10:53 EDT Tinker ☀️ Tinker ☀️

    So after a couple meetings and going through more of the links, including the GPG response, etc.

    My thoughts on the #efail vuln:

    1) The core requirement is that an attacker needs to get ahold of an encrypted email first. This is axiomatic. This is the thing that they need to decrypt.

    The attacker can do either by:
    a) Sniffing the encrypted email in transit
    b) Stealing the encrypted email at rest.

    In conversation Monday, 14-May-2018 14:10:53 EDT from infosec.exchange permalink
  3. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 06-May-2018 09:49:09 EDT Tinker ☀️ Tinker ☀️
    • UBports

    Much like #UbuntuTouch was picked up by the community under the alias UBPorts, it looks like #FirefoxOS was picked up by the community under the alias B2GOS.

    B2GOS doesn’t appear to be maintained, but the build scripts are there. It also looks like a private company forked the code further and calls it #KaiOS (used on some Nokia smart/feature phones).

    #UBPorts
    - @Ubports
    - https://ubports.com/

    #B2GOS
    - https://wiki.mozilla.org/B2G

    #DIY #Phone #FOSS

    In conversation Sunday, 06-May-2018 09:49:09 EDT from infosec.exchange permalink
  4. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 01-May-2018 13:00:56 EDT Tinker ☀️ Tinker ☀️

    NPR article posted today (May 1st) mentions Mastodon! They link to joinmastodon.org (not mastodon.social) which is great!

    “As Facebook Shows Its Flaws, What Might A Better Social Network Look Like?”

    #Mastodon #News

    https://www.npr.org/sections/thetwo-way/2018/05/01/607361849/as-facebook-shows-its-flaws-what-might-a-better-social-network-look-like

    In conversation Tuesday, 01-May-2018 13:00:56 EDT from infosec.exchange permalink
  5. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 25-Apr-2018 11:28:15 EDT Tinker ☀️ Tinker ☀️
    in reply to

    Seriously. Fuck Microsoft. Fuck the justice system that allowed this.

    The man was actually (and hopefully will continue) making a difference as it relates to ewaste, built-in obsolescence, et al.

    #Ewaste #FOSS #Lundgren

    In conversation Wednesday, 25-Apr-2018 11:28:15 EDT from infosec.exchange permalink
  6. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 25-Apr-2018 11:25:08 EDT Tinker ☀️ Tinker ☀️

    This is why I only use & support Free & Open Source Software in my personal life. This man is going to prison. Prison.

    "A California man who built a sizable business out of recycling electronic waste is headed to federal prison for 15 months after a federal appeals court in Miami rejected his claim that the “restore disks” he made to extend the lives of computers had no financial value, instead ruling that he had infringed Microsoft’s products to the tune of $700,000."

    https://www.washingtonpost.com/amphtml/news/true-crime/wp/2018/04/24/recycling-innovator-eric-lundgren-loses-appeal-on-computer-restore-discs-must-serve-15-month-prison-term/?noredirect=on

    In conversation Wednesday, 25-Apr-2018 11:25:08 EDT from infosec.exchange permalink
  7. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 06-Apr-2018 11:15:12 EDT Tinker ☀️ Tinker ☀️

    Now here's a con! Social Engineer a personal nurse to send vials of blood so that you can forge a DNA signature!

    WHERE'S YOUR BIOMETRIC MFA GOD NOW?!?!?!

    HT to Tails Hon1nbo! #SocEng
    http://www.tmz.com/2018/04/05/stan-lee-stolen-blood-for-sale-black-panther-comic-books

    In conversation Friday, 06-Apr-2018 11:15:12 EDT from infosec.exchange permalink

    Attachments

    1. Stan Lee's Stolen Blood For Sale on 'Black Panther' Comic Books
      from TMZ
      Stan Lee's stolen blood is for sale on 'Black Panther' comic books.
  8. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 04-Apr-2018 10:46:48 EDT Tinker ☀️ Tinker ☀️

    If you’re in #Dallas #Texas tonight, come join me at the Dallas Hackers Association!

    #Hacking #Locksport #CTF #FireTalks

    More info here: https://www.dallashackers.com

    In conversation Wednesday, 04-Apr-2018 10:46:48 EDT from infosec.exchange permalink
  9. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 27-Mar-2018 07:48:39 EDT Tinker ☀️ Tinker ☀️

    The Corporation behind and the Admins of Twitter can see your “Private Messages”

    The Corporation behind and the Admins of Facebook can see your “Private Messages.”

    The Admins of Mastodon can see your Direct Messages. They aren’t private.

    With Mastodon, you can spin up your own instance and be your own Admin.

    Ultimately, don’t use any of these tools for actual private messages. Use Signal, Matrix/Riot or another end to end encrypted messaging tool.

    In conversation Tuesday, 27-Mar-2018 07:48:39 EDT from infosec.exchange permalink
  10. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 18-Mar-2018 18:56:38 EDT Tinker ☀️ Tinker ☀️

    Anyone here at the #SANS #ICSSummit ?

    Need to find food.

    In conversation Sunday, 18-Mar-2018 18:56:38 EDT from infosec.exchange permalink
  11. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 04-Mar-2018 07:39:18 EST Tinker ☀️ Tinker ☀️

    What do you call a hacker that’s past their prime?

    - Obso1337

    #HackerDadJoke #Hacking

    In conversation Sunday, 04-Mar-2018 07:39:18 EST from infosec.exchange permalink
  12. Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 31-Jan-2018 21:00:44 EST Tinker ☀️ Tinker ☀️

    When speaking to folks about leaving Windows and adopting #FOSS OS’s like Linux, the biggest roadblock to leaving is the lack of a viable office suite.

    LibreOffice is at the forefront to providing that.

    In conversation Wednesday, 31-Jan-2018 21:00:44 EST from infosec.exchange permalink
  13. Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 16-Jan-2018 19:47:25 EST Tinker ☀️ Tinker ☀️

    Not gonna lie... this is funny...

    (I still don’t tell prospective users that we call it a ‘toot’... I just call it a post.)

    In conversation Tuesday, 16-Jan-2018 19:47:25 EST from infosec.exchange permalink
  14. Tinker ☀️ (tinker@infosec.exchange)'s status on Saturday, 06-Jan-2018 15:50:17 EST Tinker ☀️ Tinker ☀️

    In Layer 8, the user, a human, dies. As they die, they decompose back into base parts. They become the Physical. They become Layer 1. And, thus, the circle is complete.

    This is the OSI Layer Model.

    #Infosec #Computing #Life #Universe #Everything

    In conversation Saturday, 06-Jan-2018 15:50:17 EST from infosec.exchange permalink
  15. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 17-Dec-2017 11:13:03 EST Tinker ☀️ Tinker ☀️

    I love open sourced phones. I’m working on a (longterm.. when I can get to it) project on a phone using RPi’s. I love seeing other similar projects.

    Here’s one. Says the code will be open source, but I can’t find a repo yet. But, good for watching.

    https://fossbytes.com/pitalk-smartphone-raspberry-pi/amp/

    In conversation Sunday, 17-Dec-2017 11:13:03 EST from infosec.exchange permalink

    Attachments

    1. Open Source "PiTalk" Turns Your Raspberry Pi Minicomputer Into A Modular Smartphone
      from Fossbytes
      Powered by Python, PiTalk modular smartphone is compatible with Raspberry Pi Zero, Pi 2, and Pi 3. For voice and data communication, it's has a 3G module. The basic features performed by PiTalk are calling, SMS, WiFi, modularity, etc.
  16. Tinker ☀️ (tinker@infosec.exchange)'s status on Sunday, 17-Dec-2017 10:43:39 EST Tinker ☀️ Tinker ☀️

    Observed: Working Payphone. Outskirts of Abilene, TX, USA
    #2600

    In conversation Sunday, 17-Dec-2017 10:43:39 EST from infosec.exchange permalink
  17. Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 15-Dec-2017 05:33:16 EST Tinker ☀️ Tinker ☀️

    Oh Eris. Wow. Mudge posted a link to this. This is intense. I can’t download the python script linked in the post yet. If anyone grabs it, let me know:

    #Hacking #InfoSec

    http://archive.is/PQAnU

    In conversation Friday, 15-Dec-2017 05:33:16 EST from infosec.exchange permalink
  18. Tinker ☀️ (tinker@infosec.exchange)'s status on Monday, 20-Nov-2017 13:37:05 EST Tinker ☀️ Tinker ☀️

    For many the tradeoff for Security is Convenience.

    For me the tradeoff for Security is Control.

    iOS takes control of the device away from the user, but has arguably the best phone security.

    Not sure that I like that...

    #InfoSec

    In conversation Monday, 20-Nov-2017 13:37:05 EST from infosec.exchange permalink
  • After
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.