X_Cli is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

X_Cli @x_cli@infosec.exchange

That moment when you cannot use your TOTP because the network time of your cell operator drifts...

X_Cli boosted

Ok, OpenBSD experts: I'm seeing this when I plug in (what I assume is a serial device) to an OpenBSD 6.3 box:

ugen2 at uhub3 port 2 "Prolific Technology Inc. USB-Serial Controller" rev 1.10/3.10 addr 4

Shouldn't I be seeing an additional line in dmesg telling me which ucom device it is? I'm stabbing around with `cu -s 9600 -l /dev/cuaU3' but keep getting

cu: open("/dev/cuaU3"): Device not configured

(cuaU0 -- U2 respond from a built-in modem)

How do I solve this?

X_Cli boosted
Encrypting hard drives means you don't have to physically destroy them if you throw them out. Just securely wipe the header area of the disk (usually the first few sectors), which destroys the encryption keys and you're good.

Possibly better for not unnecessarily destroying precious computer parts?

Single Point of Failure Detection using Transitive Availability Dependency Analysis

sstic.org/media/SSTIC2018/SSTI

Recommendation: use glued delegations or diversify your delegations and check your dependencies with github.com/X-Cli/transdep

X_Cli boosted

Demonstration of #Tempest attack (at 10 meters) using TempestSDR by @ANSSI_FR during #SSTIC. It works well for textual content (not so much for pictures). t.co/gnVHk5f3Gx

X_Cli boosted

@h @bob

the gitea alternative is literally less that 2 minutes away to working on your box just the way it is.

docs.gitea.io/en-us/install-fr

wget -O gitea dl.gitea.io/gitea/1.4.2/gitea-
chmod +x gitea

./gitea web

OR

github.com/go-gitea/gitea

X_Cli boosted

WAIT A SECOND

Microsoft acquiring GitHub means they are acquiring Electron, too.

We are all triple fucked.

X_Cli boosted

The person who wrote Debian's apache2 postinst script is a criminal. The enable_default_module function is the offense.

We take security seriously. Proof? I forgot to lock my screen friday, for 5 minutes. Result: 52 vegan muffins.

infosec.exchange/media/A32RWjj

Reminder: domain-validated (DV) certificates are the proof that someone you don't know nor explicitely trust may have observed, some day in the last X years, from an unspecified vantage point, data that is not required to be cryptographically verifiable.

X_Cli boosted
X_Cli boosted
X_Cli boosted

I came across this and think it's an interesting thought game:

twitter.com/chrissanders88/sta

Assume you've been hired as the 1st CISO of a 1000 employee org that has no dedicated sec team.

You can hire 5 people your first year. What roles do you fill?

Choose wisely, because you don't know if/when you'll ever get to hire anyone else.

Reader choice on org type.

Yesterday, I played the Photosynthesis . It is excellent. You might feel, looking at the box that this is a game for the whole family, but it is not. It is a game for game specialists, with a very small rulebook but a lot of strategies and depth.

X_Cli boosted

I need a hug :(

Let’s play a game: what is the deadly bug here?

This short php code contains a critical vulnerability. In this video I will explain in detail what I think while analysing it. Original source of challenge: ...

youtu.be/MpeaSNERwQA

mamot.fr/media/Wjudj0a-Tv9nJo3

X_Cli boosted

hot linux security take Show more

X_Cli boosted

CNIL, the data protection regulator in France, released a guide for protecting data (just in time for GDPR, I guess) and it's pretty good... Kind of neophyte-level stuff, but the basics are important. cnil.fr/sites/default/files/at