Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 1hAh, so the purpose of the Googlebook is to kill off the affordable Chromebook category? 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 5h0 as I pull away from the electronics recycling center after having ogled some fascinating pea hardware in one of the bins, I suspect that if I got a job there, it would kind of like the cat hoarding lady getting a job at the animal shelter. 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 9hThis used to be my homepage, decades ago. www.alaska.net/~royce/pub/roycelink… 010
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 12hIt's like a dog with a cropped tail wagging a little stub, except it's the rear wiper on people's cars that have broken off but the wiper is on but they have no visual feedback to see that it's on, so it just stays on indefinitely, wagging a little stub as they drive through town. 010
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 22hI, for one, do _not_ welcome our new Russian plague overlords. 000
Reposted by Royce WilliamsWill Dormann @wdormann.infosec.exchange.ap.brid.gy · 05/10/2026I only just recently realized that my cheapo (at the time) N95 CPU in my DVR can do hardware video encoding, which was completely unutilized until now. So of course I nerd-sniped myself into writing a script that uses Intel QSV for automatically transcoding my MPEG2 recordings into H.264. 😂 010
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 04/10/2026One of the best uses of an old phone is as a _local_ scratch device, for activity that tends to burn through battery. This: * reduces wear on the battery of your daily driver (likely your highest-value device, that you're probably trying to stretch its lifetime in these times, and * […]infosec.exchangeOriginal post on infosec.exchange 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 04/10/2026Today I learned that Habermas would have been a great hacker. > Their core insight: _most of what we call “normal” was designed by someone, for a reason, and that reason might not be your reason._c.im 000
Reposted by Royce WilliamsAlexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 04/10/2026Threat-Actor explorer v1.1.0 released with many improvements and upgrade to the latest Pivotick library Latest A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster […] [Original post on infosec.exchange] 056
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 04/10/2026Every few years, I randomly remember that Binaca was a thing. 010
Reposted by Royce WilliamsEric Geller @ericjgeller.com · 29/09/2026GAO has a new report about how agencies gave DOGE staffers vast access to sensitive data and largely refused to verify to GAO that proper security controls were in place. The most remarkable part is the agencies' displays of pique & rancor toward GAO for asking questions. www.gao.gov/assets/gao-2... 18039
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 29/09/2026SCADA, or as I like to call it, "involuntary retrocomputing" 227
Reposted by Royce WilliamsDavid Choffnes @proffnes.discuss.systems.ap.brid.gy · 29/09/2026www.theverge.com/transportation/100… Amazing work by Sarah, Nicole, and the rest of the team! And many thanks to Consumer Reports for saying “yes” when I posed the somewhat ridiculous idea of letting a bunch of researchers test over […]discuss.systemsOriginal post on discuss.systems 015
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 27/09/2026Good think I'd already decided to migrate away from 1Password, because now that it has a passkey for a site, it wants to be the sole mediator of _all_ auth to that site, and I can't just say "no I want to use my security key instead" 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 26/09/2026The mixed emotions of being at a talk and asking a dumb question and getting a really good, informative, insightful answer. 200
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 25/09/2026Compiling FreeBSD 2.2.6 ... as one does. #PlansWithinPlans 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 24/09/2026It's 2026 and Bank of America still only lets you use a max of two security keys. 100
Reposted by Royce WilliamsLiam Proven @lproven.social.vivaldi.net.ap.brid.gy · 24/09/2026Pick is a living fossil of computer history <- an interesting, if very unaffectionate, 3-part look at the original database OS P1: csixty4.medium.com/pick-is-a-living… P2 […]social.vivaldi.netOriginal post on social.vivaldi.net 201
Reposted by Royce WilliamsKit Bashir @unixbigot.aus.social.ap.brid.gy · 24/09/2026Uh uh, uh uh “a big computer did it and ran away” is now a valid defence, gotcha 035
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 24/09/2026Chronic cowlicks so severe I'm considering hitting up the knitting forums to ask about best practices for sleeping with a hair net 100
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 24/09/2026That's such a good deal I should probably just pick up all four. 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 23/09/2026Who out there knows if/what commercial products use Shrubbery's `tac_plus` as a base for their TACACS+ services, and would be vulnerable to the RCE? Need help checking products and adding missing ones. See tables at […]infosec.exchangeOriginal post on infosec.exchange 110
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 23/09/2026RE: tech.lgbt/@LilahTovMoon/11731823504… This character is U+26B9 SEXTILE (⚹), aka UTF-8 bytes E2 9A B9, in the "Miscellaneous Symbols" Unicode block.tech.lgbt 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 23/09/2026RCE in tac_plus, common TACACS+ implementation. And perhaps underneath a number of commercial solutions that provide network authentication. Pre-auth vuln. No CVE yet. Goes back 25 years. "Shrubbery fixed it in F4.0.4.32, published on 21 September, and the Facebook fork is archived, so it will […]infosec.exchangeOriginal post on infosec.exchange 030
Reposted by Royce WilliamsWill Dormann @wdormann.infosec.exchange.ap.brid.gy · 22/09/2026Just in case you were wondering if you have Administrator Protection bits activated or not, there's an easy test. If you log in as an admin, and you run an elevated-privilege process, default Windows behavior is to present you with a UAC **Credential** […] [Original post on infosec.exchange] 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 22/09/2026Report URI rolls out Device-Bound Session Credentials -- perhaps the first non-trivial deployment. (Oversimplified summary: they are sort of like unstealable auth cookies) Not yet tested myself, but looks promising. If it pans out in practice, it will eliminate an entire _class_ of […]infosec.exchangeOriginal post on infosec.exchange 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 22/09/2026> CB and TV antennas (16 CFR part 1402) and coal- and wood-burning appliances (16 CFR part 1406): The rule eliminates requirements that manufacturers and importers of these products routinely submit copies of product labels, warnings, and instructions to CPSC. The agency retains its authority to […]infosec.exchangeOriginal post on infosec.exchange 004
Reposted by Royce WilliamsTechnology Connections @techconnectify.bsky.social · 19/09/2026"Are you selling me a solution or a dependency?" is a question I think more people should ask. 4639411077
Reposted by Royce WilliamsMatt Blaze @mattblaze.federate.social.ap.brid.gy · 21/09/2026NY (and Philly) region ILS failures related to a primary system failing and then, when it failed over to a backup, they discovered that the backup's fiber link had previously been severed. A old friend of mine was responsible for a critical public safety system with redundant links. He always […]federate.socialOriginal post on federate.social 2120
Reposted by Royce WilliamsEleanor Saitta @dymaxion.infosec.exchange.ap.brid.gy · 13/09/2026Has anyone in the EU tech policy space considered just making it illegal for services to charge more for MFA, SSO, audit log streaming, and break-glass/split privilege accounts? If y'all are serious about improving SME security, that's an easy win. 0312
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 20/09/2026Friend, as I drop them off at the airport: In theory, TSA should be fine with my mustache scissors -- they're under the blade-length limit. Me: Guess we'll find out -- good luck! [...] Me: How did it go? Friend: They didn't bat an eye. Me: _cuts to a scene where you are forcibly trimming […]infosec.exchangeOriginal post on infosec.exchange 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 20/09/2026The "viral AI actress" is only "viral" because they paid someone to write a piece to call them "viral", and are manufacturing controversial features. It's still bullshit, just like the last time they tried to shop it. 001
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 19/09/2026The mocktail page of this menu is headed "Absence of Proof". 102
Reposted by Royce Williamshrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 17/09/2026We have 28 positions open (most remote, some non-US|CA). Attached are the research & engineering positions open (since I don't think sales or marketing folks follow me here). Links to these and more @ censys.com/careers DM me for a Signal contact #FediHired 015
Reposted by Royce WilliamsErnie Smith @ernie.writing.exchange.ap.brid.gy · 15/09/2026Good news or bad news depending on your POV: Usenet archives are suddenly easy to dig through, thanks to a new service. It’s built by a big data guy, and it’s packed with every awkward thing you ever wrote in a newsgroup in 1997. My deep dive […]writing.exchangeOriginal post on writing.exchange 5341
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 17/09/2026/me drops a 30-year-old hard drive into a 30-year-old computer Ontrack Disk Manager. Now that's a name I haven't heard in a long time. And it turns out ... you can still download it (permission granted by the rights holder!) www.philscomputerlab.com/ontrack-di… 000
Reposted by Royce WilliamsJonathan Kamens 86 47 @jik.federate.social.ap.brid.gy · 15/09/2026An important, timely reminder: 0010
Reposted by Royce WilliamsEric Geller @ericjgeller.com · 16/09/2026CISA wants to hire infrastructure security experts who can work broadly across sectors, rather than people specializing in certain sectors, acting CISA Director Nick Andersen told reporters today at Google's Cyber Defense Summit. My story: www.cybersecuritydive.com/news/cisa-cr...cybersecuritydive.comCISA looks to recruit general infrastructure security experts rather than sector-focused advisers“I need people that can pivot from day to day,” the agency’s acting chief told reporters. 2166
Reposted by Royce WilliamsSpookJ 👻 @snoopj.hachyderm.io.ap.brid.gy · 15/09/2026being continuously exposed to people saying "sentience" when they mean "sapience" is going to be my villain origin story 111
Reposted by Royce WilliamsWill Dormann @wdormann.infosec.exchange.ap.brid.gy · 15/09/2026Did you update to iOS 27? Congratulations! You've now been enrolled in Apple Intelligence, because Apple knows better about what you want than you do. 1. Starting with iOS 27, there is no top-level `Apple Intelligence` setting that you can turn off. 2 […] [Original post on infosec.exchange] 011
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 15/09/2026So the Transcend flash-IDE drives (to replace spinning rust in legacy computers) ... pretend they support SMART, but all the values are zero, so you can't tell actual power-on ours, etc.? 000
Reposted by Royce WilliamsJiří Eischmann @sesivany.social.vivaldi.net.ap.brid.gy · 14/09/2026One perk of working for Red Hat was the ability to use a self-managed OS. However, this is coming to an end due to compliance requirements. I'm not comfortable with having my personal private keys on a managed system, so I moved my SSH key, GPG key, and electronic signature certificate to a […]social.vivaldi.netOriginal post on social.vivaldi.net 001
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 14/09/2026"I replaced the only part of this item critical to establishing provenance" isn't the pro move you're trying to position it as, eBay seller. And you know it isn't. 000
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 13/09/2026I assume there's been a sharp uptick in requests for API access to commercial grade data / frameworks / engines, but for leaving academic nor commercial use, just "I'm writing this thing for me". It's not, it feels like an interesting middle ground in the licensing space. 000
Reposted by Royce WilliamsTheodora Ward @theodoraward.wandering.shop.ap.brid.gy · 12/09/2026if i rig up a random number generator to a bomb, program it to generate a number between 1 and 20 every five minutes, set the bomb to go off if i roll a 20, begin the random number generator, then leave the room, i am liable for when the bomb goes off. the fact that a deeply stupid […]wandering.shopOriginal post on wandering.shop 5760
Reposted by Royce WilliamsBrennan Kenneth Brown 👻 BOO! @brennan.social.lol.ap.brid.gy · 11/09/2026RE: social.jpoesen.com/@jpoesen/1172520… Omarchy-as-Linux-distro is a front for Omarchy-as-political-movement. We are watching in real time as this is being established. Not enough people are aware of what's happening here. Not enough people realize the gravity and weight of […]social.lolOriginal post on social.lol 029
Royce Williams @tychotithonus.infosec.exchange.ap.brid.gy · 12/09/2026See, it's like an Arnold Palmer, but mixing two different kinds of Listerine. 100