Posts
Assume your devices are compromised
For decades, we have assumed our local computing devices are a safe place to store digital secrets. Most software, systems and security protocols make this assumption.
Posts
Age File Encryption
Age is modern file encryption software that is small, fast and secure. In this blog post, I’ll go over some common encryption tasks that I have historically done using PGP, except I’ll be using Age instead.
Posts
It's OK to speed
Sometimes I am asked for my opinion on whether or not computer users should be allowed to do risky things such as run old software, use certain cryptographic algorithms, or have root on their workstations.
Posts
All our eggs are in one basket
My grandmother used to say, “Don’t put all your eggs in one basket." As a child, I did not understand what she meant, but as I grew older, I came to understand that she was talking about diversity.
Posts
Replace Google Analytics with a shell script
I started blogging in December 2020. I wanted to collect my old stories, software and notes all in one place. I thought others may like the content and I was curious how popular it may be, so I setup Google Analytics to keep track of things.
Posts
Exfiltrate files using the DNS
Once upon a time, a government auditor insisted to me that keystroke loggers had to run as root, otherwise they would not function properly. So, I wrote a keystroke logger that ran as a normal user and showed it to him.
Posts
Cracking passwords with cheap hardware
There were roughly 30 Street teams that participated in Korelogic’s 2020 Crack Me If You Can password cracking contest at Defcon. I took 4th place.
Posts
Finding a hacked server
It was a cold Wednesday morning, about ten ‘til eight. I had been in the office a few minutes when the phone rang.
Hello. “Yes, hi, the server has been hacked!
Posts
Now they have 2FA problems
There’s an old quip about solutions causing more problems:
Some people, when confronted with a problem, think “I know, I’ll use regular expressions.” Now they have two problems.
Posts
Cavezoom
Zoom is software that facilitates remote meetings and collaboration. Its popularity soared in 2020 due to the COVID-19 pandemic. It has also been the focus of increased privacy and security concerns.