Sign in

Rick Valenzuela

@threatc.at
243 followers 633 following 80 posts

threat detection. distant past: journalist. 🍜 Slurp with gusto infosec.exchange/@rv TnFxIHpyIHNiZSBndXIgb3JmZyBpcnRyZ25ldm5hIFRyYXJlbnkgR2ZiJ2YgZXJwdmNyIHZhIGd1ciBoYXZpcmVmcg==

PostsRepliesMedia
Rick Valenzuela @threatc.at · 19/08/2025
This is also more than just travel or other personal situations, but also for private networks like hospitals and warehouses (think of industrial IoT deployments). These things are convenient, but there's no guardrails yet. link to paper: www.usenix.org/system/files...
usenix.org
010
Rick Valenzuela @threatc.at · 19/08/2025
Alongside possibility of data interception and location tracking and opaque ownership hierarchy of what are essentially white-label resellers, it also looks at the workflow of deploying eSIMs and weak points attackers could hit
Screenshot from paper: This system is analogous to new car dealerships that purchase cars directly from the manufacturer and sell to consumers.
In the case of a car dealership, the car manufacturer has a serious stake in ensuring that dealerships operate according to strict policies and procedures to avoid tarnishing the brand reputation. In the case of eSIM reselling, users are unlikely to give any consideration to who is managing and operating the eSIM profile they have just downloaded to their mobile device. MNOs and MVNOs appear to be willing to allow any party the opportunity to re-sell access to their networks. The opportunity exists for virtually anyone to establish their own online presence, selling cellular data plans to anyone with an internet connection. This scenario has serious implications for user data privacy.
110
Rick Valenzuela @threatc.at · 19/08/2025
The paper itself is not that China heavy, but it lists a lot of observed traffic routed to different, unexpected countries, including "proactive communication", the phoning-home aspect (tho it also links to a 2021 article discussing this with physical SIMs).
100
Rick Valenzuela @threatc.at · 19/08/2025
The article goes hard on the China angle, and for sure: who knew Irish eSIM brand Holafly is actually a subsidiary of the state-owned enterprise China Mobile? The installer runs from their servers, and wherever the phone is, it even has a public IP address in China.
100
Rick Valenzuela @threatc.at · 19/08/2025
New security risk unlocked, eSIMs edition, and especially the kind you pick up prepping for an international trip www.itnews.com.au/news/travel-...
itnews.com.au
Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study
Convenient tech brings big bundle of security and privacy risks.
120
Rick Valenzuela @threatc.at · 15/07/2025
Photo- and videojournalists now have until Aug 8 to brush up on Filezilla or Cyberduck, or ask an old head wetransfer.com/explore/lega...
010
Rick Valenzuela @threatc.at · 16/05/2025
Rewrite the quote “Do not cite the Deep Magic to me, Witch. I was there when it was written” in the voice of Pauly Shore’s character Stoney in Encino Man saying, “If you're edged 'cause I'm weazin all your grindage, just chill. 'Cause if I had the whole brady bunch thing happenin' at my pad, I'd go grind over there, so dont tax my gig so hard-core cruster.”
ChatGPT said:

Sure! Here’s that quote reimagined in the voice and style of Pauly Shore’s Stoney from Encino Man:

"Yo, don’t be throwin' down the Deep Magic vibes at me, buuuddy. I was totally chillin’ when they laid it down, saw the whole scroll sesh go down, major OG incantation action, ya know? So don’t harsh my mystical mellow, crusty sorceress."

Let me know if you want it even more surfer-stoner or pulled back a bit!
110
Rick Valenzuela @threatc.at · 16/05/2025
Continue nudging the feed
140
Rick Valenzuela @threatc.at · 16/05/2025
And plug: I mentioned Lockdown Mode and Advanced Protection Program in a tip sheet I cowrote with @bostonjoan.bsky.social for @criticalinternet.bsky.social. If you fit the profile, these are really good and really easy things to switch on to be safer
011
Rick Valenzuela @threatc.at · 16/05/2025
For a comprehensive and straightforward explanation of all the things that Advanced Protection does on mobiles, @androidauthority.com has an excellent overview
androidauthority.com
Android 16's Advanced Protection security mode: What it does and who should enable it
If you value security, you'll want to turn on the new Advanced Protection mode in Android 16. Here's what it does and how to enable it.
122
Rick Valenzuela @threatc.at · 16/05/2025
Android users now have an analog to iPhone's Lockdown Mode, so now basically everyone can opt in to a more secure phone/tablet. It's part of Google's Advanced Protection Program, which if you use Gmail and work/move in a space where you're more likely to be targeted, is a great thing to enroll in
security.googleblog.com
Advanced Protection: Google’s Strongest Security for Mobile Devices
Posted by Il-Sung Lee, Group Product Manager, Android Security Protecting users who need heightened security has been a long-standing com...
153
Rick Valenzuela @threatc.at · 05/05/2025
Please next Peep-flavored prawn crackers
110
Reposted by Rick Valenzuela
Kevin Collier @kevincollier.bsky.social · 03/05/2025
I've been traveling so forgive me for not posting this yesterday, but: That Signal clone app for archiving messages that Mike Waltz has been using, TeleMessage? It's unlicensed. Signal was unaware of its existence until they saw it in that Reuters photo. There's no known security vetting.
nbcnews.com
Photo appears to show Mike Waltz using Signal-like app that can archive messages
More than a month after he drew criticism for using Signal to discuss an impending military attack, Waltz was seen using what appears to be a different messaging app to message others in the Trump adm...
8433451313
Rick Valenzuela @threatc.at · 03/05/2025
Ugh. If this is pattern behavior (or policy?), then maybe links to CBS News stories should be to free archive link versions instead
081
Reposted by Rick Valenzuela
Stephen C. Rea @stevierea.bsky.social · 02/05/2025
Great account of what networked incitement looks like in the year 2025. Kudos to @nedmparker1.bsky.social, @mikespector.bsky.social, @bypetereisler.bsky.social, @lindasoreports.bsky.social & @nateraymond.bsky.social
reuters.com
These judges ruled against Trump. Then their families came under attack.
As federal judges rule against the Trump administration in dozens of politically charged cases, the families of at least 11 of the jurists have been targeted with threats and harassment. The intimidation campaign has strained judges and their relatives – and legal scholars fear it could have a chilling effect on the judiciary.
184
Rick Valenzuela @threatc.at · 24/04/2025
I did this in Shanghai circa 2018, when the AQI was horrendous (second pic). Above 100 was common, and an occasional spike above 400. Airnow.gov has Barnegat at 63 and forecast for 100
Chart describing Air Quality Index (AQI) values. Read the whole thing at https://www.lung.org/clean-air/outdoors/air-quality-indexHeat map chart of AQI in Shanghai, showing 19 days at 100 or more in January 2018.
020
Rick Valenzuela @threatc.at · 24/04/2025
For my NJ people who would want to know this, really good air filters don't have to be expensive. Literally talking ~$30. In front of a strong fan, stack an activated carbon filter on top of a HEPA filter and that will screen out both the things you want, volatile organic compounds (VOCs) and PM2.5
smartairfilters.com
How to Make a DIY Air Purifier for Your Home – Smart AirFacebook social iconTwitter social iconInstagram social iconLinkedIn social iconYouTube social icon
5 Simple Steps to make a homemade DIY air purifier to reduce air pollution and viruses in your home--plus actual test data showing the DIY filter works.
120
Rick Valenzuela @threatc.at · 24/04/2025
a bundle of leeks 💀 Also a possible new unit of measurement. Would be nice if it's a round number, too; he's currently 1 Truss, 4 Scaramuccis in
000
Rick Valenzuela @threatc.at · 23/04/2025
you guys watching Office Space?
000
Rick Valenzuela @threatc.at · 21/04/2025
media.tenor.com
a woman in a car with the words i see you seeing me see you on the bottom
ALT: a woman in a car with the words i see you seeing me see you on the bottom
100
Rick Valenzuela @threatc.at · 21/04/2025
media.tenor.com
a black and white photo of a man with a stethoscope around his neck screaming .
ALT: a black and white photo of a man with a stethoscope around his neck screaming .
010
Rick Valenzuela @threatc.at · 21/04/2025
test II
320
Rick Valenzuela @threatc.at · 21/04/2025
Awww. But credit goes to an unnamed group chat (not that one but also that one)
020
Rick Valenzuela @threatc.at · 02/04/2025
Snitches gets kittehs
000
Reposted by Rick Valenzuela
Stephen C. Rea @stevierea.bsky.social · 01/04/2025
The U.S. IC (at least the leadership)
The Drake Hotline Bling meme template (the rapper Drake wearing a bright orange puffy coat against a yellow background, turning away and holding up his hand in the top photo, smiling and pointing “yes” in the bottom photo): the top text reads “OPSEC” and the bottom text reads “OOPSEC”
15214
Rick Valenzuela @threatc.at · 30/03/2025
Just popping in to say Spolsky theme is the best dark theme for vim or emacs
070
Rick Valenzuela @threatc.at · 27/03/2025
No-goodnik was always in Mad magazines of the 1970s. Also, this is probably a good place to mention the Russian term 'vatnik'. Good word, much usable
020
Rick Valenzuela @threatc.at · 25/03/2025
Lotta talk now about burner phones (and nerds saying what isn't). You don't need to go super cloak and dagger for decent risk reduction. But if you want to, listen to @eanmeyer.bsky.social and @strandjs.bsky.social from @bhinfosecurity.bsky.social www.youtube.com/playlist?lis...
Excerpt: If you can get a separate phone, you maywant to run that stripped down to essentials, with a minimal contact list and only necessary communication apps, potentially with separate accounts.
This isn't a burner phone; if you think you need to go to that level, you'll have to actively do a lot more planning and care for the steps you take. Watch a 3-part series from Black Hills Information Security titled "How to Live like a Criminal - Privacy Tips for the Non-Criminal". It covers a lot more ground on planning to purchase and activate a bumer and the risks to safely maintain it, as well as awareness of how much information on you from data brokers would be available — whether to law enforcement, other investigators, or criminals.
021
Rick Valenzuela @threatc.at · 25/03/2025
One of the risk profiles is protesters. For them, and for more users and reasons, iPhone users should turn on Lockdown Mode. In this context, it's about IMSI catchers, which intercept calls. @eff.org just released a tool for this, and it's worth reading about, and using www.eff.org/deeplinks/20...
Excerpt: Protester
If you're going to attend a protest and feel uncertain about your communications, the most basic thing you could do is leave your phone at home, or turn it off completely while at the protest site. Make sure that you have a good passcode set to unlock your phone or laptop, as fingerprints or FacelD can be bypassed easily by force or coercion. Disable unlocking by fingerprint or facial recognition.
If you have an iPhone, also consider turning on Lockdown Mode. This would disable 2G, an older form of cellular connection, which is commonly used as a fallback. Android users can explicitly disable 2G in settings too. These connections aren't encrypted and are susceptible to interception, such as from IMSI-catchers, sometimes called by a brand name Stingray.
141
Rick Valenzuela @threatc.at · 25/03/2025
Spoiler: One of the 5 things is using MFA. It's been a decade since learning this one thing could've prevented John Podesta from losing control of his Gmail. @danielmiessler.bsky.social wrote a great breakdown of options, so this section doesn't reinvent the wheel danielmiessler.com/blog/not-all...
Multifactor Authentication
Again, any is better than none, but here the differences are significant. The simplest of these are getting codes sent by email, phone call or text message. A level up rould be using an app that generates codes. Another level up is an app that prompts /ou to accept or deny the login, and the highest security would come from a physical object, whether that's a piece of hardware in a USB key or from the built-in security chip that's made for this embedded in your phone or computer. A great chart and rundown of these are written in this blog post by security researcher Daniel Miessler.
110
Rick Valenzuela @threatc.at · 25/03/2025
The common cyber cliche is about not being faster than a bear, but outrunning the other potential victim. The drier cliche truth is that security is a process. Don't stress over loose ends and TODOs, just come back regularly and eventually do them
Excerpt: Apart from methods and measures, the one essential lesson about protecting yourself digitally is that security is a process. You don't have to get to everything in one go. Once you have a list of the things you need to do, make a plan and knock off those tasks on a schedule. Keep coming back to it. Corporate and enterprise security people often tout an adapted Pareto Principle to discuss the priority security measures: 20 percent of control mechanisms will thwart 80 percent of attacks.
120
Rick Valenzuela @threatc.at · 25/03/2025
ICYMI last week, reupping a digital security tip sheet I helped write with @bostonjoan.bsky.social. More than a few new ones have dropped since January -- the main goal of this one is to give you 5 things you can do to minimally but meaningfully raise your security
33010
Rick Valenzuela @threatc.at · 25/03/2025
Seriously, it works from phone? Ugh. Well, if anyone who engaged on that thread sees this, I appreciated it
000
Rick Valenzuela @threatc.at · 25/03/2025
Not me trying to upload pics from my phone to see if they also show up glitched like the thread I just worked on from laptop
100
Rick Valenzuela @threatc.at · 24/03/2025
it's really weird to me that a lot of continental European McDonald's and Burger Kings always have plant-based. Sometimes different versions, like Impossible comes and goes as a special, but the same place will always have a different brand. And then you come to the states and they *never* have that
060
Reposted by Rick Valenzuela
Critical Internet Studies Institute @criticalinternet.bsky.social · 19/03/2025
📢 NEW: Our introductory tip sheet on digital security for journalists & civil servants working under pressure. 📢 Co-authors @bostonjoan.bsky.social & @threatc.at offer 📌 five basic steps 📌 for truth-telling practitioners to protect their work & their communities www.criticalinternet.org/research
criticalinternet.org
Research — The Critical Internet Studies Institute
33128
Rick Valenzuela @threatc.at · 13/03/2025
images too 😂 righteous evolution of the spiritual lineage www.trackmenot.io
trackmenot.io
About | Trackmenot
010
Rick Valenzuela @threatc.at · 12/03/2025
internally debating short term vs long term pros and cons of AI poisoning. it could be fun for a minute tho
130
Reposted by Rick Valenzuela
Rick Valenzuela @threatc.at · 11/03/2025
The ICC either has massive operational hurdles, or a hell of a business continuity plan. When Trump sanctioned the ICC, the Guardian reported internal worries about their reliance on Microsoft Azure and that suspending access would "paralyse its investigations" www.theguardian.com/law/2025/jan...
Screenshot from linked Guardian article, with photo of ICC chief prosecutor Karim Khan and this excerpt from the article:

One key concern to have emerged in recent months is the ICC’s reliance on Microsoft which has deepened in recent years after chief prosecutor Karim Khan formed a partnership with the company to overhaul the court’s systems.

Multiple sources in the prosecutor’s office said Microsoft’s Azure cloud platform is critical to its operations and suspending access would paralyse its investigations. “We essentially store all of our evidence in the cloud,” one said.
111
Rick Valenzuela @threatc.at · 11/03/2025
@berthubert.bsky.social also told the Register that people there "feel that they're being locked out of their work right now." www.theregister.com/2025/02/26/e...
theregister.com
Europe begins to worry about US-controlled clouds
Technologist Bert Hubert tells The Reg Microsoft Outlook is a huge source of geopolitical risk
010
Rick Valenzuela @threatc.at · 11/03/2025
The ICC either has massive operational hurdles, or a hell of a business continuity plan. When Trump sanctioned the ICC, the Guardian reported internal worries about their reliance on Microsoft Azure and that suspending access would "paralyse its investigations" www.theguardian.com/law/2025/jan...
Screenshot from linked Guardian article, with photo of ICC chief prosecutor Karim Khan and this excerpt from the article:

One key concern to have emerged in recent months is the ICC’s reliance on Microsoft which has deepened in recent years after chief prosecutor Karim Khan formed a partnership with the company to overhaul the court’s systems.

Multiple sources in the prosecutor’s office said Microsoft’s Azure cloud platform is critical to its operations and suspending access would paralyse its investigations. “We essentially store all of our evidence in the cloud,” one said.
111
Rick Valenzuela @threatc.at · 28/02/2025
When we say “release the hounds,” we meant OUR hounds
010
Rick Valenzuela @threatc.at · 28/02/2025
In other not-good news, standing down Cyber Command planning on Russia isn’t only bad for Ukraine, but also elections and fighting crime. It worked on election interference (and there’s a bunch of European elections coming up) and Defend Forward took down TrickBot therecord.media/hegseth-orde...
therecord.media
Exclusive: Hegseth orders Cyber Command to stand down on Russia planning
The secretary of Defense has ordered U.S. Cyber Command to stand down from all planning against Russia, including offensive digital actions, sources tell Recorded Future News.
011
Reposted by Rick Valenzuela
Jake Williams @malwarejake.bsky.social · 26/02/2025
Technology is inherently political. Anyone who says otherwise is either being disingenuous or is ignorant of history.
media.tenor.com
a rainbow with the words " be more you know " and a star
ALT: a rainbow with the words " be more you know " and a star
47711
Reposted by Rick Valenzuela
Jen Mercieca @jenmercieca.bsky.social · 21/02/2025
Three online "news" stories published this week that include quotes from me that I didn't say. But I didn't do interviews and get misquoted. And they're not written by actual journalists. My best guess is there are massive amounts of AI slop getting posted as news and now I'm part of it. 😬
32967280
Reposted by Rick Valenzuela
Eric Geller @ericjgeller.com · 20/02/2025
Second round of layoffs at the Cybersecurity and Infrastructure Security Agency definitely happening now. I've heard from at least two laid-off employees tonight.
491144314
Rick Valenzuela @threatc.at · 14/02/2025
Nice one, Access Now
020
Rick Valenzuela @threatc.at · 13/02/2025
The batch of aquafaba for this was heavily reduced, after my wife tried to make crepes with non-reduced stuff and it came out the consistency of wet scrambled eggs
020
Rick Valenzuela @threatc.at · 13/02/2025
well damn. aquafaba works great chocolate chip banana bread, sans eggs
loaf of chocolate chip banana bread, with a slice cut, sitting on a cutting board
130