ghostbuster

linux security person

ghostbuster boosted:
Matthew McPherrinmattm@infosec.exchange
2024-02-09

The Canadian government's plan to combat auto theft is to ban the Flipper Zero: canada.ca/en/public-safety-can
Seriously, WTF?

2024-01-29

so because my keyboard has no arrow keys I often use ctrl+p/ctrl+n to access my bash history, but this never seems to work correctly in docker containers...

I just learned that docker uses ctrl+p,ctrl+q as an escape code to exit the session. Disabling this and I can browse history again!

`docker attach --detach-keys 'ctrl-q,q'`

ghostbuster boosted:
Mandu πŸ₯Ÿyurnidiot@mstdn.social
2024-01-24

the struggle was real

tweet: We memorized phone numbers. We memorized driving directions. No one knew what we looked like. No one could reach us. We were gods.
ghostbuster boosted:
Tim (Wadhwa-)Brown :donor:timb_machine@infosec.exchange
2024-01-10

Lest anyone tell you otherwise, we're decades behind the bad guys as far as detection on Linux.

Cado Security reanalysed a CrowdStrike report in 2022 and found a 20-year old piece of malware.

Why am I mentioning this? Because I just randomly clicked my way to the Cado link whilst going through some of their more recent reporting on Qubitstrike.

This isn't the first time that *old* malware has reappeared e.g. Luckscan as used by UNC1945/LightBasin and it won't be be the last.

Interestingly (for me at least), it's another example of malware poisoning argv[0], something we've been looking to add to ATT&CK recently and collecting evidence for.

ghostbuster boosted:
2023-12-24

I have interviewed 100s of candidates for software engineering positions.

I’ve done take-home tests, in person challenges, pair programming with the candidates.

I've had folks punch the whiteboard in frustration, refuse to do the task because it was beneath them, confidently produce an incorrect solution and then argue with me about it being wrong, and demonstrate they knew nothing about a language they claim to be an expert in. I've also had folks, largely from anxiety, freeze up entirely, make silly mistakes, and go down a wrong path and get stuck.

These types of interviews are far from perfect. I personally dislike them as I also experience crippling anxiety in those situations. They can provide useful information but only if you focus on how the person worked through the problem, not whether they got a right answer. Most of the time, I would tell the candidate that I did not expect them to finish and that I was looking at their approach, not the solution. Not only did this put them at ease early on, it let them focus on showing the skills that I was evaluating them on.

In other words, a significant part of why everyone hates these interview questions is that the recruiter and interviewer failed to set expectations. There's a vast array of books on how to do better as an interviewee but few on being a better interviewer. Even if there were, few companies put any incentives in place to be a better interviewer. Most of the time, there is an implicit disincentive of getting more interviews.

2023-09-02

@thelinuxcast red nubs ok?

ghostbuster boosted:
Digital Mark Ξ» β˜•οΈ πŸ”ͺ πŸ™„mdhughes@appdot.net
2023-07-03

A new version of the AWK book is coming out! In 2023!
awk.dev

#unix #awk

ghostbuster boosted:
2023-07-01
A humorous chart called How to Measure Things Like a Canadian
ghostbuster boosted:
Ned Yeungned@mstdn.ca
2023-07-01

Americans: I use miles and pounds

Europeans: I use kilometres and kilograms

Canadians: [snorting a line of assorted measuring systems] I'm 5'3", I weigh 150Ibs, horses weigh 1000kgs, my house is an hour away and I drive 80 km/h to get there, I need a cup of flour and 1L of milk

Janel Comeau @VeryBadlLlama 

Americans: I use miles and pounds

Europeans: I use kilometres and kilograms

Canadians: [snorting a line of assorted measuring systems] I'm 5'3", I weigh 150Ibs, horses weigh 1000kgs, my house is an hour away and I drive 80 km/h to get there, I need a cup of flour and 1L of milk
ghostbuster boosted:
𝐿𝒢𝓃𝒢 :verifiedtrans:LadyDragonfly@universeodon.com
2023-06-13

I present to you the 90s Band Alignment Chart.

An alignment chart showing various 90s bands plotted on a dual axis chart of Happy-Sad and Angry-Horny. Also includes a Sarcasm Belt - a donut shaped area in the middle.
ghostbuster boosted:
Michael Steebermichaelsteeber
2023-02-02

This is a reminder to use movetodon.org one more time before the watertight doors on the Titanic close

2023-01-25

@alberg Ironically that link to blacklight has a tracker embedded in the URL, and interestingly blacklight seems to discard UTM parameters from URLs

ghostbuster boosted:
Mike Masnick βœ…mmasnick
2023-01-24

Oh hey, I keep forgetting to do music posts here. So here's Hepcat. If you don't know Hepcat, they're an absolutely amazing ska band from LA who have been around in some form or another for over 30 years (I first saw them in 1993). They put on amazing live shows with a ton of energy, so I went for a live clip... youtube.com/watch?v=EdST9suL3gg

2023-01-07

He spends more time at my workbench than I do. The two of us completed a comparable number of #electronics projects last year #caturday #cats #CatsOfMastodon

2023-01-04

@hacks4pancakes great article, lots of food for thought.

I'd love to hear how resume styles have changed compared to eg. 5 years ago

ghostbuster boosted:
Sundae_GurlSundae_Gurl
2023-01-03

Accordion to a recent survey, replacing words with the names of musical instruments often goes unnoticed.

2022-12-30

@fabian_bader If you split work and private then you would need a backup for each, right?

I think I'm going to need a spreadsheet soon to track which keys are enrolled where

2022-12-30

Unscientific #2FA poll:

How many #FIDO #U2F #WebAuthN hardware keys do you have? Do you enroll the same ones in every service that supports them?

ghostbuster boosted:
jwzjwz
2022-12-29

All Your Face.

TSA going hogwild with facial recognition is going about as well as you'd expect, "but you can opt out". YK Hong: Since folks asked what happens whenever I opt out of facial recognition, I documented it for you while going through US...
jwz.org/b/yj8C

Screenshot

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst