DaLanShark

I look out for Security, Privacy, & Risk. Adjunct Professor and Professional Trainer on Cybersecurity Topics. Sometimes Parody. Posts are my own, != present, past, or future employer.

2023-04-18

@bertjwregeer @Viss
It's just a partnership, Apple putting their name on the service, but another bank on the back end.
Amex bought Kabbage, and Kabbage used to use Green Dot for their checking product, and nowadays if you look for Kabbage, it's kaput; you're redirected to Amex. We'll see if this deal works out OK for Green Dot, but I don't see Apple taking over the financial world that quickly.

2023-04-18

@horse @paulsanders Jake, you are already fancy, no letters required!

2023-04-18

On a webcast today, I contradicted that there were "two types" of companies, those who have been breached, and those who haven't been breached YET, was wrong.

We have to think about those companies that are being breached, and they don't know it YET.

We really need to think about bad controls, poor detection of control failure, insiders who know how to avoid internal controls... The breach didn't start when the ransom notice appeared on the screen.

2023-04-10

@Korgdisso @hacks4pancakes
I wish I'd bought a Tesla over the Toyota/Subaru fiasco and their lack of range. I respect Toyota more than Tesla, but right now Toyota is lying about their EV's range.

DaLanShark boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2023-04-10

Pals, I don’t know who needs to hear this but one of the most offensive things you can say to somebody who has bought something new - especially a big purchase - and is sharing the news with you is, “here is why you should have bought this alternative instead”, like they’ve fucked up or they should have spent 5x as much on something else. They already gave someone money. They’re invested.

Some people just don’t get this nuance when they want to share knowledge about something they’re really excited about, but I really have to warn you that’s an incredibly hurtful thing to say that folks don’t forget. They probably were working within a budget, or within specific constraints or needs you are not fully aware of.

They probably do know what they’re doing. You are talking down to them and basically implying they’re stupid. You’re not helping and you don’t look smart.

DaLanShark boosted:
2023-04-10

This month is the 30th anniversary of the announcement of the Clipper Chip, the first of many bad ideas for weakening cryptography with "key escrow" backdoors. Clipper is long dead, but its ghost continues to haunt us from time to time.

gizmodo.com/life-and-death-of-

2023-04-10

@horse @paulsanders I've seen clients who were questioning why to hire a firm, and one of their concerns was that a much larger firm had alphabet soup for their consultants, so I keep my CISSP active.
(ISC)2 won't let you test online, but the exam is adaptive, so it's not quite the same marathon exercise that it used to be.

DaLanShark boosted:
2023-04-10

I made a homemade Passover treat of coconut macaroons. The left were dipped in semi-sweet chocolate and the right were dipped in a white & semi-sweet mix. They both have orange essence in them, to give a little citrus enhancement. Most of these are going to neighbors. Most 👀

DaLanShark boosted:
2023-04-03

Join us THURSDAY @ 12:30pm CT for THURSDAY DEFENSIVE! A 30min fireside chat with defensive people around the industry.

This week's guest: @likethecoins talking about threats to watch.

reconis.co/3LBhCR9

#infosec #thursdaydefensive

DaLanShark boosted:
2023-04-03

I really don’t know why you’d store your data in a cloud operated by Western Digital. But if you did, you’re in trouble. bleepingcomputer.com/news/secu

DaLanShark boosted:
2023-03-30

My awesome colleague @JohnHammond worked through the night with fellow @huntress analysts to produce this overview of #3CX #3CXApocalypse attack paths and vendor-neutral defensive guidance. Honestly the best summary and overview of activity since the initial CrowdStrike disclosure. #DFIR #ThreatIntel #CTI
huntress.com/blog/3cx-voip-sof

DaLanShark boosted:
off-by-one apocalypse bringerpixelnull@infosec.exchange
2023-03-30

this is me giving The Mouse it's due for this

however, scares me a little as to what else their legal team is capable of doing

newsweek.com/ron-desantis-disn

DaLanShark boosted:
2023-03-30

Join us TODAY @ 12:30pm CT (in ~2 hrs!) for the THURSDAY DEFENSIVE!

Today's guest: @TimMedin of @RedSiege chatting about how offense prepares defense.

reconis.co/3FE6oaS

#infosec #thursdaydefensive

DaLanShark boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2023-03-30
2023-03-30

@malwarejake I'm surprised that they didn't throw in "Zero Trust" and "AI" in their soup of terms.
youtu.be/4JkIs37a2JE

2023-03-13

@0ddj0bb Yeah, I'm in the same time zone, at least. Looking forward to it...

2023-03-13

@0ddj0bb @bsidesroc
Excellent! I'm still debating which car to drive! 😎​
Fuel Efficiency, or a fun 0-70 acceleration?

2023-03-13

@mattblaze
Another reason to bank with a credit union, insured by the NCUA/NCUSIF?
The $250k limits are published, and now the FDIC is selecting SVB and Signature as worthy of an exception... can I use that logic the next time I don't want to slow down to 55mph on the highway?

2023-03-13

@briankrebs Classic response that basically boils down to "If you would like a copy of your credit report, or anyone else's, please contact us."

2023-03-13

@jimray
Well, I guess that's one way of putting it.
"Joining"... as requested by the FDIC, when the FDIC showed up at our door!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst